DocumentCode :
2933817
Title :
Evidence of log integrity in policy-based security monitoring
Author :
Montanari, Mirko ; Huh, Jun Ho ; Dagit, Derek ; Bobba, Rakesh B. ; Campbell, Roy H.
Author_Institution :
Inf. Trust Inst., Univ. of Illinois at Urbana-Champaign, Urbana, IL, USA
fYear :
2012
fDate :
25-28 June 2012
Firstpage :
1
Lastpage :
6
Abstract :
Monitoring systems are commonly used by many organizations to collect information about their system and network operations. Typically, SNMP, IDS, or software agents generate log data and store them in a centralized monitoring system for analysis. However, malicious employees, attackers, or even organizations themselves can modify such data to hide malicious activities or to avoid expensive non-compliance fines. This paper proposes a cloud-based framework for verifying the trustworthiness of the logs based on a small amount of evidence data. A simple Cloud Security Monitoring (CSM) API, made available on the cloud services, allows organizations operating on the cloud to collect additional “evidence” about their systems. Such evidence is used to verify system compliance against the policies set by security managers or regulatory authorities. We present a strategy for randomly auditing and verifying resource compliance, and propose an architecture that allows the organizations to prove compliance to an external auditing agency.
Keywords :
auditing; cloud computing; computer crime; computerised monitoring; data integrity; data loggers; software agents; CSM API; IDS; SNMP; attackers; auditing agency; centralized monitoring system; cloud security monitoring API; cloud services; cloud-based framework; data storage; expensive noncompliance fines; log data generation; log integrity; malicious employees; network operations; policy-based security monitoring; regulatory authorities; resource compliance verification; security managers; software agents; Computer architecture; Credit cards; Monitoring; Organizations; Security; Software; Standards organizations;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Dependable Systems and Networks Workshops (DSN-W), 2012 IEEE/IFIP 42nd International Conference on
Conference_Location :
Boston, MA
Print_ISBN :
978-1-4673-2264-5
Electronic_ISBN :
978-1-4673-2265-2
Type :
conf
DOI :
10.1109/DSNW.2012.6264693
Filename :
6264693
Link To Document :
بازگشت