[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

logging fork() and exec()



I'm working on a little kernel patch to allow the kernel  to scribble a
note in a logfile every time an exec or a fork happens. I'm thinking of
deploying this  on a packet filtering firewall which doesn't spawn many
processes. It's the obvious reason - I want to know about every process
running. Yes, I know about process accounting, but I don't believe that
will be sufficient for instant notification. As it is, my NFR generates
a fair number of warnings,  so i'm quite prepared to handle a deluge of
messages. I'll probably be implementing this as a sysctl option.

So bottom line: good idea? Care to comment/speculate on the effect this
could have on system performance,  stability or security? Has this been
tried with OpenBSD before?

Be Well,
Chris

-- 
Chris Kuethe: System Administrator - U of A Math Dept

pager: 780.917.6448             office: CAB553, 492.1704   cell: 903.9475
wargames_(_at_)_edmc_(_dot_)_net               ckuethe_(_at_)_ualberta_(_dot_)_ca
ckuethe_(_at_)_math_(_dot_)_ualberta_(_dot_)_ca        ckuethe_(_at_)_gecko_(_dot_)_math_(_dot_)_ualberta_(_dot_)_ca

Opinions expressed herein are solely the responsibility of
the author. And the author wouldn't have it any other way.




Visit your host, monkey.org