Audit Logs Management and Security - A Survey
-
Published:2021-06-25
Issue:3
Volume:48
Page:
-
ISSN:2307-4108
-
Container-title:Kuwait Journal of Science
-
language:
-
Short-container-title:KJS publishes peer-review articles in Mathematics, Computer Science, Physics, Statistics, Biology, Chemistry, and Earth & Environmental Sciences.
Author:
Ali Ahmad, ,Ahmed Mansoor,Khan Abid, ,
Abstract
Audit logs are key resources that show the current state of the systems and user activities and are used for cyber forensics and maintenance. These logs are the only source that can help in finding traces of some malicious activities or troubleshooting a system failure. Insight view for troublefree availability of computing resources and performance monitoring and meaningful forensic audit depends on the management and archival system of audit logs. These logs are prone to multidimensional threats and superusers or system administrators have unprecedented access to these logs and can alter these logs as and when required. Similarly, repudiation is another serious issue in computer forensics and non-repudiation can be provided by a secure recording of event logs. Periodic backups, encrypted data transfer, off-site storage and certificate based storage of these logs are commonly being used. In this survey, we searched for the requirements of securing audit logs and available approaches to secure these logs. Based on the available literature, a taxonomy of audit log management is developed. We have drawn a comparison between these approaches and also highlighted the current challenges to these logs security and their available options.
Publisher
Kuwait Journal of Science
Subject
Multidisciplinary
Cited by
1 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献