Re: Star Trek and Log Integrity
"Tom Le" <[email protected]> Wed, 7 May 2008 11:13:47 -0700
| Newsgroups | gmane.comp.sysutils.loganalysis |
|---|---|
| Message-ID | <[email protected]> |
--===============0712517187== Content-Type: multipart/alternative; boundary="----=_Part_12534_11170418.1210184027672" ------=_Part_12534_11170418.1210184027672 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Content-Disposition: inline I think the correct reference is "Schneier, et al" and you can get the paper here without needing an ACM account: http://www.schneier.com/paper-auditlogs.html Cliff notes for lazy folks: - Use changing hashes for logging authentication key (change after every log event) - Encrypt each log message, using one-way encryption key - Each log entry contains element in hash chain to verify all previous entries (think how token servers work, but in reverse) - Says weakness in sending logs to remote server is the link itself (reliability & subject to DoS attack) and ability to provide selective read access (though most log indexing solutions today provide some level of role-based-access) I just don't see authentication + encryption ever happening in the the logging universe anywhere in the next decade, outside of one-off add-ons to syslog or SNMP. Most of log archiving & indexing functionality available today is "good enough" to provide non-repudiation of log data, with the one exception of spoofed data (which would require server compromise in the Schenier scheme). Also, consider that firewalls and hosts generate just as much logging activity today (order of magnitude) than in 1999, yet log archiving & indexing capabilities are orders of magnitude better: better indexing, better context-driven search capability, faster CPU, more memory, more disk, faster network, etc. Tom On Tue, May 6, 2008 at 1:49 PM, <[email protected]> wrote: > It is so disappointing that even in the 24th century, computer logs are > not tamper-proof. > > At least the logs are tamper-evident. Kelsey, et.al. showed us how in > 1999 > http://portal.acm.org/citation.cfm?id=317089&coll=portal&dl=ACM > > -chris > > -----Original Message----- > From: [email protected] > [mailto:[email protected]] On Behalf Of Tina Bird > Sent: Tuesday, May 06, 2008 1:38 PM > To: [email protected] > Subject: [logs] Star Trek and Log Integrity > > > I can't believe we've been talking about log data on this list for what, > over 6 years now, and no one's ever brought it up. > > The CBS network Web site provides episodes of classic TV shows for > viewing, > at the cost of 90 seconds of advertising breaks per episode: > > http://www.cbs.com/video/?showname=classics/star_trek > > There's no obvious way to link directly to an episode, but if you click > to > page 5, you'll see episode 20, "Court Martial," in which Captain Kirk is > proved innocent of a crew member's death after Spock is able to prove > that > the computer logs have been tampered with. I am *so* going to > incorporate > this into my logging tutorial :-) > > enjoy -- tbird > _______________________________________________ > LogAnalysis mailing list > [email protected] > http://www.loganalysis.org/mailman/listinfo/loganalysis > > _______________________________________________ > LogAnalysis mailing list > [email protected] > http://www.loganalysis.org/mailman/listinfo/loganalysis > ------=_Part_12534_11170418.1210184027672 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Content-Disposition: inline I think the correct reference is "Schneier, et al" and you can get the paper here without needing an ACM account:<br><br><a href="http://www.schneier.com/paper-auditlogs.html">http://www.schneier.com/paper-auditlogs.html</a><br> <br>Cliff notes for lazy folks:<br><br> - Use changing hashes for logging authentication key (change after every log event)<br><br> - Encrypt each log message, using one-way encryption key<br><br> - Each log entry contains element in hash chain to verify all previous entries (think how token servers work, but in reverse)<br> <br> - Says weakness in sending logs to remote server is the link itself (reliability & subject to DoS attack) and ability to provide selective read access (though most log indexing solutions today provide some level of role-based-access)<br> <br>I just don't see authentication + encryption ever happening in the the logging universe anywhere in the next decade, outside of one-off add-ons to syslog or SNMP. Most of log archiving & indexing functionality available today is "good enough" to provide non-repudiation of log data, with the one exception of spoofed data (which would require server compromise in the Schenier scheme).<br> <br>Also, consider that firewalls and hosts generate just as much logging activity today (order of magnitude) than in 1999, yet log archiving & indexing capabilities are orders of magnitude better: better indexing, better context-driven search capability, faster CPU, more memory, more disk, faster network, etc.<br> <br>Tom<br><br><br><div class="gmail_quote">On Tue, May 6, 2008 at 1:49 PM, <<a href="mailto:[email protected]">[email protected]</a>> wrote:<br><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;"> It is so disappointing that even in the 24th century, computer logs are<br> not tamper-proof.<br> <br> At least the logs are tamper-evident. Kelsey, <a href="http://et.al" target="_blank">et.al</a>. showed us how in<br> 1999<br> <a href="http://portal.acm.org/citation.cfm?id=317089&coll=portal&dl=ACM" target="_blank">http://portal.acm.org/citation.cfm?id=317089&coll=portal&dl=ACM</a><br> <br> -chris<br> <div><div></div><div class="Wj3C7c"><br> -----Original Message-----<br> From: <a href="mailto:[email protected]">[email protected]</a><br> [mailto:<a href="mailto:[email protected]">[email protected]</a>] On Behalf Of Tina Bird<br> Sent: Tuesday, May 06, 2008 1:38 PM<br> To: <a href="mailto:[email protected]">[email protected]</a><br> Subject: [logs] Star Trek and Log Integrity<br> <br> <br> I can't believe we've been talking about log data on this list for what,<br> over 6 years now, and no one's ever brought it up.<br> <br> The CBS network Web site provides episodes of classic TV shows for<br> viewing,<br> at the cost of 90 seconds of advertising breaks per episode:<br> <br> <a href="http://www.cbs.com/video/?showname=classics/star_trek" target="_blank">http://www.cbs.com/video/?showname=classics/star_trek</a><br> <br> There's no obvious way to link directly to an episode, but if you click<br> to<br> page 5, you'll see episode 20, "Court Martial," in which Captain Kirk is<br> proved innocent of a crew member's death after Spock is able to prove<br> that<br> the computer logs have been tampered with. I am *so* going to<br> incorporate<br> this into my logging tutorial :-)<br> <br> enjoy -- tbird<br> _______________________________________________<br> LogAnalysis mailing list<br> <a href="mailto:[email protected]">[email protected]</a><br> <a href="http://www.loganalysis.org/mailman/listinfo/loganalysis" target="_blank">http://www.loganalysis.org/mailman/listinfo/loganalysis</a><br> <br> _______________________________________________<br> LogAnalysis mailing list<br> <a href="mailto:[email protected]">[email protected]</a><br> <a href="http://www.loganalysis.org/mailman/listinfo/loganalysis" target="_blank">http://www.loganalysis.org/mailman/listinfo/loganalysis</a><br> </div></div></blockquote></div><br> ------=_Part_12534_11170418.1210184027672-- --===============0712517187== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ LogAnalysis mailing list [email protected] http://www.loganalysis.org/mailman/listinfo/loganalysis --===============0712517187==--