[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Tripwire and /proc



The amount of data that tripwire reports on /proc is a bit overwhelming,
and strikes me as not particularly useful most of the time. After all,
most of the info in the root of /proc is PID info, so while certain
system processes shouldn't change all that often, most of the stuff in
there is pretty dynamic.

Since there doesn't appear to be a way to specify wildcards in
tripwire/stable uptodate 2.3.1.2.0-4, it seems like having 30k+ lines
similar to:

    /proc/32768 -> $(SEC_INVARIANT) (recurse = 0) ;

is the best way to minimize this sort of info, although it slows down
tripwire tremendously. Is there a better way to do it, and is there
actually any value in recursing into PID directories in /proc that I'm
overlooking?

-- 
Re-Interpreting Historic Miracles with SED #141: %s/water/wine/g



Reply to: