
Severity
Severity levels of events are reported from the severity database. The severity
database defines the importance of potential security events and numbers them one
through ten, ten being the most severe security incident. The severity levels are
determined by the threat or importance of different security events, such as certain
resources accessed or services denied.
Mode
The mode is the permission that the profile grants to the program or process to
which it is applied. The options are
r
(read),
w
(write),
l
(link), and
x
(execute).
Detail
A source to which the profile has denied access.This includes capabilities and files.
You can use this field to report the resources to which the profile prevents access.
Access Type
The access type describes what is actually happening with the security event. The
options are
PERMITTING
,
REJECTING
, or
AUDITING
.
Executive Security Summary
A combined report consisting of one or more high-level reports from one or more ma-
chines. This report can provide a single view of security events on multiple machines
if each machine's data is copied to the reports archive directory, which is
/var/log/
apparmor/reports-archived
. This report provides the host machine's IP address,
the start and end dates of the polled events, total number of rejects, total number of
events, average of severity levels reported, and the highest severity level reported. One
line of the ESS report represents a range of SIR reports.
The following screen represents an executive security summary:
Managing Profiled Applications
91
Summary of Contents for APPARMOR 1.2
Page 1: ...Novell AppArmor Powered by Immunix Administration Guide www novell com 1 2 09 29 2005...
Page 4: ......
Page 14: ......
Page 116: ......
Page 128: ......