1 / 5100%
Running Head: AUDIT i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 1
Apply: Signature Assignment: Audit Logs
CYB 205 – Infrastructure Administration
AUDIT i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 2
Describe what information was contained in the logs and what value they might have in
a security investigation.
An individual log offers security against compromise in the application and perimeter
defenses by alerting the user about the issue. The objective is to make sure that suitable
measures are adopted before serious damage occurs. While investigating an assault, a log can
shed light on who did what, when and where. Such data could be used for discovering the
individual responsible for the initiation of the assault (Cobb, 2011).
What are the risks associated with logging too little data or not auditing the correct
events?
Logging is vital as it can help the user to carry out the appropriate kinds of auditing for every
single framework as well as application along with the correct measure of log audit. A
thorough risk evaluation must be conducted to explore what actions need to be logged.
Without such an approach, the assembled data would serve no purpose in case an event arises.
Some of the main data that must be logged in the system so that proper preparedness exist
during an incident include User ID, terminal identity, time and date of log-on as well as log-
off, failed and successful attempts to access system, application or data, networks and files
accessed, changes made to system configuration, the utilization of system utilities, exceptions
such as triggered alarms, activation of intrusion detection system (IDS), etc. i
What are the risks associated with logging too many events?
The risk associated with logging too many events in the log is that the log information would
not provide the requisite knowledge that is needed when the opportunity for investigation and
examination arises.
AUDIT i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 3
When the default configuration is to create audit logs, what impact can this have on
security incident investigations?
The default audit configuration settings help to guarantee that the PC security records have
been put away in proper detail for a fitting period. Conducting frequent and routine log audits
is beneficial as it helps to identify and distinguish security episodes, deceitful and malicious
actions, strategy infringements, as well as operational issues soon after they have occurred.
Security investigations provide insightful data that helps to settle the identified issues.
This was just a single domain with 2 systems on a local LAN. How much more
complicated would auditing and log management be for 100 computers? What about an
enterprise with 10,000 computers in several domains on their LAN/WAN?
A network encompassing only three computers could generate a humongous amount of data
that could be broken down physically. But when there exist more than 100 computers in
LAN/VAN, there is the need to have a solid computerized framework. Log analyzers could
computerize the investigation and auditing of logs. These analyzers could inform the user
about what event has taken place or what event is going on. Thus, it could help to uncover
malicious conduct and/or unapproved actions.
Consider a cloud-hosted Infrastructure as a Service (IaaS) environment with many new,
Internet-accessible systems regularly being built and brought online. What challenges
might there be managing audit policies and logs in such an environment?
The functioning of cloud computing systems is based on a large datacenters as well as a third-
party subcontractor that is responsible for managing it. Since a client has no insight into who
is responsible for handling the data on the system, it is necessary to conduct a cloud security
audit. It can help to expose risks relating to undesirable scenarios. Additionally, the clients
AUDIT i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 4
must ensure that new systems are correctly configured to provide appropriate logging (Cobb,
2011). i
How the tools and processes demonstrated in the labs might be used by an infrastructure
administrator to help secure an environment.
On the basis of the learning from the week’s work, a framework administrator could use
auditing methods for preventing n attack from taking place or at least limiting the severity of
the attack. An infrastructure administrator could make use of the event logs that is created by
the framework to highlight the starting point of an attack and thus identify the culprit. (Cobb,
2011) The event logs could be used for seeing the accessed websites, user credentials,
password failed or successful attempts, etc. Thus, the methods and tools could be used to
safeguard the environment.
AUDIT i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 5
References
Cobb, M. (2011, August 8). Best practices for audit, log review for IT security investigations.
ComputerWeekly.com. https://www.computerweekly.com/tip/Best-practices-for-audit-
log-review-for-IT-security-investigations.
Students also viewed