
Date
The date during which security events occurred.
Program
The name of the executing process.
Profile
The absolute name of the security profile that is applied to the process.
PID
Process ID number is a number that uniquely identifies one specific process or
running program (this number is valid only during the lifetime of that process).
State
This field reveals whether the program listed in the program field is confined. If it
is not confined, you might consider creating a profile for it.
Type
This field reveals the type of confinement the security event represents. It says either
complain or enforce. If the application is not confined (state), no type of confinement
is reported.
Security Incident Report
A report that displays security events of interest to an administrator. The SIR reports
policy violations for locally confined applications during the specified time period. The
SIR reports policy exceptions and policy engine state changes. These two types of se-
curity events are defined as follows:
Policy Exceptions
When an application requests a resource that is not defined within its profile, a se-
curity event is triggered. A report is generated that displays security events of interest
to an administrator. The SIR reports policy violations for locally confined applica-
tions during the specified time period. The SIR reports policy exceptions and policy
engine state changes.
Policy Engine State Changes
Enforces policy for applications and maintains its own state, including when engines
start or stop, when a policy is reloaded, and when global security feature are enabled
or disabled.
Managing Profiled Applications
89
Содержание APPARMOR 1.2
Страница 1: ...Novell AppArmor Powered by Immunix Administration Guide www novell com 1 2 09 29 2005...
Страница 4: ......
Страница 14: ......
Страница 116: ......
Страница 128: ......