IBM 8687 Installation Guide - Page 186

Breakaway OK, moved to the top of the list of execution rules, because the rules are parsed

Page 186 highlights

Specify here how often you want Process Control to check for new processes and apply the process alias rules. Figure 5-45 Process Control scan interval The other configurable entry, Request timeout interval, is used to determine how long the service will wait for commands from a remote server. If the timeout value is exceeded, control will pass back to the local console. Breakaway OK This parameter is to allow a child process to break away from the process group. If this box is not checked, a child process that tries to break away from the group will not be permitted to execute. This will prevent processes from creating other processes that are not managed under the group's rules. This may prevent the spread of Trojan horse viruses that enter a system attached to other processes and then attempt to run as services, or under another user's credentials. Process Control enables a very strict security method. It is possible to grant execution privileges only to specific subdirectories. Make sure these rules are moved to the top of the list of execution rules, because the rules are parsed in top-down order. Then create a rule for subdirectory names that match * and apply a process count of 0. This will prevent all processes that are initiated from any other subdirectories from executing. 172 IBM ^ xSeries 440 Planning and Installation Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202

172
IBM
^
xSeries 440 Planning and Installation Guide
Figure 5-45
Process Control scan interval
The other configurable entry, Request timeout interval, is used to determine
how long the service will wait for commands from a remote server. If the
timeout value is exceeded, control will pass back to the local console.
±
Breakaway OK
This parameter is to allow a child process to break away from the process
group. If this box is not checked, a child process that tries to break away from
the group will not be permitted to execute. This will prevent processes from
creating other processes that are not managed under the group
s rules.
This may prevent the spread of Trojan horse viruses that enter a system
attached to other processes and then attempt to run as services, or under
another user
s credentials.
Process Control enables a very strict security method. It is possible to grant
execution privileges only to specific subdirectories. Make sure these rules are
moved to the top of the list of execution rules, because the rules are parsed in
top-down order. Then create a rule for subdirectory names that match
*
and
apply a process count of 0. This will prevent all processes that are initiated from
any other subdirectories from executing.
Specify here how often
you want Process
Control to check for new
processes and apply the
process alias rules.