Abstract:
As a very important component of secure operation system, audit subsystem plays a key role in monitoring the system, insuring proper implementing of security policy, and building intrusion detection system. The design and realization of an audit subsystem are presented, which is Linux based and copyrighted, and accords with the third level, "Security Label Protection", GB17859 1999. This audit subsystem can collect data all around by mounting audit points in the kernel and applications, make configuration more flexible by configuring audit mask in subjects and objects and enhance the subsystem’s performance by optimizing buffer management.