A standard audit trail format
Conference
·
OSTI ID:231354
- Univ. of California, Davis, CA (United States). Dept. of Computer Science
The central role of audit trails, or (more properly) logs, in security monitoring needs little description, for it is too well known for any to doubt it. Auditing, or the analysis of logs, is a central part of security not only in computer system security but also in analyzing financial and other non-technical systems. As part of this process, it is often necessary to reconcile logs from different sources. This speaks of a need for a standard logging format. A standard log format robust enough to meet the needs of heterogeneity, transportability across various network protocols, and flexibility sufficient to meet a variety of needs in very different environments must satisfy two basic properties: extensibility and portability. This report presents the author`s proposed format for a standard log record. In section 3, he shows how and where the translation should be done, and in section 4 he demonstrates how log records from several disparate systems would be put into this format. Section 5 concludes with some observations and suggestions for future work.
- Research Organization:
- Lawrence Livermore National Lab., CA (United States)
- Sponsoring Organization:
- USDOE, Washington, DC (United States)
- DOE Contract Number:
- W-7405-ENG-48
- OSTI ID:
- 231354
- Report Number(s):
- UCRL-JC--119744; CONF-9510360--1; ON: DE96009238
- Country of Publication:
- United States
- Language:
- English
Similar Records
Hassle-free audit trails: Automated audits
VMS (Virtual Memory Systems) ALAP (Audit Log Analysis Package) 1. 0: An automated audit trail analysis tool
Audit trails in an online accountability system
Conference
·
Fri Mar 31 23:00:00 EST 1989
·
OSTI ID:6242100
VMS (Virtual Memory Systems) ALAP (Audit Log Analysis Package) 1. 0: An automated audit trail analysis tool
Conference
·
Sat Dec 31 23:00:00 EST 1988
·
OSTI ID:6187626
Audit trails in an online accountability system
Conference
·
Mon Dec 31 23:00:00 EST 1984
· J. Nucl. Mater. Manage.; (United States)
·
OSTI ID:5414319