A commonly used technique among computer crackers, and experienced thieves as well, is to erase their fingerprints from the crime scene. This usually means erasing or modifying the logs stored on the computer that will expose them if carefully examined. Unprotected . . . . A commonly used technique among computer crackers, and experienced thieves as well, is to erase their fingerprints from the crime scene. This usually means erasing or modifying the logs stored on the computer that will expose them if carefully examined. Unprotected logs will make system security checks an impossible task in most cases. When crackers gain complete access to the system, they gain the ability to read, modify or erase any logs. Let us define "Secure Logging" as the ability to record a given amount of information on a given storage media and be able to check the authenticity of that record later. This is part of the CIA triangle: confidentiality, integrity, and availability. This definition says nothing about the security of the storage media where the information is recorded, we must assume that anybody can read, modify or erase it. The link for this article located at daemonnews is no longer available. . Discover the techniques seasoned criminals employ to alter system logs and the significance of robust logging protocols in safeguarding data.. Secure Logging, Log Integrity, Cybersecurity Techniques. . LinuxSecurity.com Team
A few months ago, I challenged myself with a problem. I wanted to implement centralized system logging that would securely store logs in a location that would prevent any tampering or mischief. It was necessary to find a solution that fit . . . . A few months ago, I challenged myself with a problem. I wanted to implement centralized system logging that would securely store logs in a location that would prevent any tampering or mischief. It was necessary to find a solution that fit into my company's tight budget that would also be a) secure, b) affordable and c) easy to run, especially on a Solaris system. While these constraints made it very tough to discover a viable solution, I was nevertheless able to do so. This article will discuss a solution that meets these criteria and will work well in other environments as well. It should be noted that since I implemented the solution I have in place now, I have discovered some other options. The link for this article located at Security Focus is no longer available. . Establish a secure, centralized logging system using SCP to protect logs from tampering. Follow these steps for effective log management and integrity.. Centralized Logging, Secure SCP Implementation, Remote Log Management, Log Security, Linux Administration. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.