Updated on 2024-08-14 GMT+08:00

Adding a Privileged Process

If WTP is enabled, the content in the protected directories is read-only. To allow certain processes to modify files in the directories, add them to the privileged process list.

Only the modification made by privileged processes can take effect. Modifications made by other processes will be automatically rolled back.

Exercise caution when adding privileged processes. Do not let untrustworthy processes access your protected directories.

Constraints

  • Only the servers that are protected by the HSS WTP edition support the operations described in this section.
  • Only x86 OSs with kernel 4.18 support this function.
  • The privileged process takes effect only for Agent 3.2.4 or later.
  • A maximum of 10 privileged processes can be added to each server.
  • Only Linux is supported.

Prerequisites

The Protection Status of the server must be Protected. To view the status, choose Prevention > Web Tamper Protection. Click the Servers tab.

Adding a Privileged Process

  1. Log in to the management console.
  2. Click in the upper left corner of the page, select a region, and choose Security > Host Security Service.
  3. Choose Prevention > Web Tamper Protection, click Servers tab page and click Configure Protection in the Operation column.
  4. Click Privileged Process Settings and then Settings.
  5. On the Privileged Process Settings page, click Add Privileged Process.
  6. In the Add Privileged Process dialog box, enter the path of the privileged process.

    The process file path must contain the process name and extension, for example, C:/Path/Software.type. If the process has no extension, ensure the process name is unique.

  7. Click OK.

Follow-Up Procedure

Modifying or deleting existing privileged processes

In the Operation column of a process file path, click Edit to modify the privileged processes or click Delete to delete it if it is unnecessary.

  • After you edit or delete the process file path, the privileged process cannot modify the files in the protected directory. To avoid impact on services, exercise caution when performing these operations.
  • Unnecessary privileged processes should be deleted in a timely manner as they may be exploited by attackers.