Security Audits.



Hello,

I sent the following letter to our Anti-Virus support team; as we are
continentally established enterprise, with only designated contacts permitted
to get direct vendor support. I believe that this condition has two parts to
it, a vendor side and a Microsoft side. I'm merely looking for anyone who may
have seen this, and might save me some time (and red tape) involved in
regular support for this application. Thanks in advance. See the below:

Hello,



I’m curious if there is any precedent or previous case history involving
Windows security event logs becoming clogged and full of Failure audits of
Event 560? This event seems to be logged eight simultaneous times..all with
the same timestamp; with this trend occurring every 60 seconds or so, some
intervals as short as every 20 seconds. It occurs on each and every
Windows(XP, all service packs) workstation and/or Server (2K, Advance 2K,
2003) that runs Symantec Anti Virus Corporate version 10.x and up. The
details of these events are as follows:



Event Type: Failure Audit

Event Source: Security

Event Category: Object Access

Event ID: 560

Date: 4/18/2006

Time: 3:22:27 PM

User: NT AUTHORITY\SYSTEM

Computer: computer_name

Description:

Object Open:

Object Server: Security

Object Type: Key

Object Name: \REGISTRY\USER\.DEFAULT

Handle ID: -

Operation ID: {0,3035375}

Process ID: 1944

Image File Name: C:\WINDOWS\system32\svchost.exe

Primary User Name: computer_name$

Primary Domain: INTERNAL

Primary Logon ID: (0x0,0x3E7)

Client User Name: computer_name$

Client Domain: domain_name

Client Logon ID: (0x0,0x3E7)

Accesses: MAX_ALLOWED



Privileges: -

Restricted Sid Count: 0





For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.



These events stop entirely when the Symantec Anti Virus service ("C:\Program
Files\Symantec AntiVirus\Rtvscan.exe") is stopped. They continue the above
trend when the service is restarted. While not at all a system-down type of
issue, the constantly filling event logs make for more frequent than
necessary log backup/purging routines as well as more processor-intensive
event log queries. Indeed, the bloating of the security logs by Event ID 560
fired by Symantec leaves very little room to manage security logs a manner
more beneficial to our organizations security concerns.



Assuming that the system isn’t ‘broken’, my request is more process-related.
What are the details behind rtvscan and the above event? How do they relate?
If identified, our systems can be configured to not audit this activity,
dramatically reducing event log size without sacrificing audit warning in
general by globally ‘saying no’ to failure audits

--
Jonathan Forbes
.



Relevant Pages

  • FW: {RTCProd#003-520-317}Windows Update Support Request
    ... support policy for Windows NT 4.0 Workstation SP6a. ... The Microsoft Support Lifecycle defines the support policies for all ... This means that after this date, Microsoft would no longer create ... security fixes for this platform, nor automatically post to WU, etc. ...
    (NT-Bugtraq)
  • Re: How to automatic send an e-mail when an event occurs?
    ... CyberCop combines packet analysis with assessment of the event logs, ... environment, including security profiles, account groups, time and subnets. ... KSM is unable to terminate the intrusion or take actions such as logging ... As Windows NT and Windows 2000 are more fully deployed in environments ...
    (microsoft.public.windows.server.general)
  • RE: Vendor wants remote control of our Servers and Workstations
    ... Of course the age-old problem with security is that ... Vendor has significant access to your internal ... this vendor uses the same method to support a number ... customer and makes significant changes ... ...
    (Security-Basics)
  • Re: Both security mode with WSHttpBinding?
    ... I've been scouring the WCF Security Guide. ... and only bindings that support the Microsoft Message Queuing ... establish a binding which will support both transport security via ...
    (microsoft.public.dotnet.framework.webservices)
  • Re: The Register: OpenVMS among most-secure of operating systems
    ... >story with out of support versions of VMS/OpenVMS as well. ... >Take LAND there is no CERT advisory for LAND refering to ... You have claimed that CERT advisory counts is ... not a good measure of the relative security of a system. ...
    (comp.os.vms)