AUDIT SYSTEM REFERENCE
APPENDIX B. AUDIT SYSTEM REFERENCE
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/security_guide/app-Audit_Reference#sec-Audit_Events_Fields
https://elixir.bootlin.com/linux/latest/source/kernel/audit.c
https://elixir.bootlin.com/linux/latest/source/include/uapi/linux/audit.h
/* The netlink messages for the audit system is divided into blocks:
- 1000 - 1099 are for commanding the audit system
- 1100 - 1199 user space trusted application messages
- 1200 - 1299 messages internal to the audit daemon
- 1300 - 1399 audit event messages
- 1400 - 1499 SE Linux use
- 1500 - 1599 kernel LSPP events
- 1600 - 1699 kernel crypto events
- 1700 - 1799 kernel anomaly records
- 1800 - 1899 kernel integrity events
- 1900 - 1999 future kernel use
- 2000 is for otherwise unclassified kernel audit messages (legacy)
- 2001 - 2099 unused (kernel)
- 2100 - 2199 user space anomaly records
- 2200 - 2299 user space actions taken in response to anomalies
- 2300 - 2399 user space generated LSPP events
- 2400 - 2499 user space crypto events
- 2500 - 2999 future user space (maybe integrity labels and related events)
- Messages from 1000-1199 are bi-directional. 1200-1299 & 2100 - 2999 are
- exclusively user space. 1300-2099 is kernel --> user space
- communication.
*/
------------------------------------------
除非特别声明,文章均为原创,版权与博客园共有,转载请保留出处
BUY ME COFFEE


【推荐】国内首个AI IDE,深度理解中文开发场景,立即下载体验Trae
【推荐】编程新体验,更懂你的AI,立即体验豆包MarsCode编程助手
【推荐】抖音旗下AI助手豆包,你的智能百科全书,全免费不限次数
【推荐】轻量又高性能的 SSH 工具 IShell:AI 加持,快人一步
· 如何编写易于单元测试的代码
· 10年+ .NET Coder 心语,封装的思维:从隐藏、稳定开始理解其本质意义
· .NET Core 中如何实现缓存的预热?
· 从 HTTP 原因短语缺失研究 HTTP/2 和 HTTP/3 的设计差异
· AI与.NET技术实操系列:向量存储与相似性搜索在 .NET 中的实现
· 10年+ .NET Coder 心语 ── 封装的思维:从隐藏、稳定开始理解其本质意义
· 地球OL攻略 —— 某应届生求职总结
· 提示词工程——AI应用必不可少的技术
· Open-Sora 2.0 重磅开源!
· 周边上新:园子的第一款马克杯温暖上架