M O N I T O R
66
66
66
66
!"
Monitor is a client program of the Daemon process. Therefore, in
order to run Monitor you must also install and customize Daemon.
7.2. Assembling and Configuring
Assembling the FreeBSD kernel anti-virus module and
the anti-virus monitor. Editing the Monitor
configuration file.
7.2.1. Assembling Monitor
The FreeBSD kernel is constructed in such a way that to enable the
monitoring of files to be opened, saved or executed you must first install
and assemble the kernel anti-virus module. The module is supplied
together with the Monitor program and is called
klmon
.
The main feature of the module construction is that the module allows you
to launch and shut down the anti-virus monitor without restarting the
FreeBSD operating system.
#"
The Monitor program performs its functions only in combination with
the
klmon
anti-virus kernel and the Daemon program.
The Figure 9 illustrates the process of anti-virus monitoring within the
FreeBSD filesystem.
Figure 1. The monitoring flowchart
Right before a file within the FreeBSD filesystem is opened, recorded or
executed it is intercepted by the anti-virus module and transferred to