Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

4/3/2020
10:00 AM
Chris Calvert
Chris Calvert
Commentary
Connect Directly
LinkedIn
RSS
E-Mail vvv
50%
50%

Want to Improve Cloud Security? It Starts with Logging

Remedying the "garbage in, garbage out" problem requires an understanding of what is causing the problem in the first place.

When using event logs to monitor for security violations and incidents, the quality of output is determined by the quality of the input. Much of the logging being used is subpar, and there has been little industry incentive to fix it. This, in turn, is preventing true cloud security because cloud platform logs don't contain useful information.

It doesn't have to be this way. Remedying the "garbage in, garbage out" problem is possible, but it requires an understanding of what is causing the problem in the first place.

The Hidden Problem
Enterprises collect and log data from a variety of IT and security devices. Most software applications and systems produce log files, which include all of the automatically produced and time-stamped documentation of recent system activity. Enterprises then use this data to monitor, protect, understand, and manage their technology-enabled businesses. The data sources have the potential to provide visibility across many different technical perspectives: network, security, application, host-based, cloud, and contextual telemetries, to start. Within each of these categories are infrastructure devices that produce logs and sensors focused on monitoring, be it for IT operations or security.

This log data is the unassuming superhero of IT data. It may not look like much initially, but it has much power. But not all logging is created equal. Much of the data can be inconsistent, hard to understand, and focused only on system or application break/fix. There is little information that could indicate something was potentially malicious.

And if the logging you're using is poor, it's going to have a negative effect on all of your other security measures. While there are common logging formats and methods, there's little agreement or commonality in how the information contained should be used for specific purposes. As a result, logs can be hard to leverage effectively for any purpose.

Compounding this, the law of inertia is at play with respect to how logging currently works. Essentially, there's a pervasive attitude of "it's not broke, don't fix it" – even though, in reality, the way logging is done actually is broken. Security teams are motivated toward change, but how much leverage does a five-person security team have on the likes of Microsoft to produce better logs for Active Directory or Office 365?

This doesn't mean change is impossible. Rather, the leverage for change starts with the procurement department. In other words, market change is driven by purchasing behavior. So it's up to us to economically influence improvements in log quality. This should become a point of competitive selection.

Best Practices and What to Ask of Your Vendor
So how do you ensure you're getting the most out of your logging? There are a few best practices to follow. These include:

  • Focus on the logs that do contain judgment about the potential of malicious activity or find ways to inject that judgment onto the logs with context and security expertise.
  • Only log from sources that matter and collect the information that can support detection and remediation effectively
  • Dial up your security-specific sensors to 11. Make them as loud as possible to give you the most comprehensive visibility – and demand that your vendors produce better security visibility into what's going on with their products.

When it comes to assessing vendors for your logging, it's important to ask some key questions about their solutions and how they work before committing to one. They should be able to answer the following questions for you:

  • What are the most common attack vectors against your product?
  • How many malicious scenarios will your logs identify?
  • How hard is it to parse them so they're normalized with other similar technologies?
  • What's the most effective way to monitor your logging for malicious activity?
  • Do you have a center of excellence for security monitoring of your technology?
  • Which standard log formats are used for output?
  • How hard it is it to introduce new logs based on new attack techniques? What's your update frequency?

If a potential vendor can't or won't explain these things things to you fully, it's time to keep searching for one that can and will.

Making Change Worthwhile
"Garbage in, garbage out" is clearly not a good way to approach a security monitoring strategy. It puts organizations at risk and sucks up too much budget and staff time to be sustainable or tenable. Rather, organizations must incentivize vendors to develop better logging capabilities by making it a purchasing sticking point. Use the best practices and questions above to get the logging capabilities your organization needs to keep your network safe.

Related Articles:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's featured story: "What Should I Do If Someone Is Impersonating My Company in a Phishing Campaign?"

Chris Calvert has over 30 years of experience in defensive information security: 14 years in the defense and intelligence community and 17 years in the commercial industry. He has worked on the Defense Department Joint Staff and held leadership positions in both large and ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
4/30/2020 | 10:25:05 PM
Re: You hit it right on
Unfortunately, I think a lot of the times logging is used more for a compliance checkbox or to troubleshoot an issue and less to support the security objective.

I've noticed two commonalities:

1) Too many logs are collected and there isn't AI correlation to make sense of it efficiently so it becomes noise.

or 

2) Logging isn't set up in the right places so when an event does happen the security unit is blind to it.
NSA Appoints Rob Joyce as Cyber Director
Dark Reading Staff 1/15/2021
Vulnerability Management Has a Data Problem
Tal Morgenstern, Co-Founder & Chief Product Officer, Vulcan Cyber,  1/14/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This is not what I meant by "I would like to share some desk space"
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-1303
PUBLISHED: 2021-01-20
A vulnerability in the user management roles of Cisco DNA Center could allow an authenticated, remote attacker to execute unauthorized commands on an affected device. The vulnerability is due to improper enforcement of actions for assigned user roles. An attacker could exploit this vulnerability by...
CVE-2021-1304
PUBLISHED: 2021-01-20
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information that they are not autho...
CVE-2021-1305
PUBLISHED: 2021-01-20
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information that they are not autho...
CVE-2021-1312
PUBLISHED: 2021-01-20
A vulnerability in the system resource management of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) to the health monitor API on an affected device. The vulnerability is due to inadequate provisioning of kernel parameters f...
CVE-2021-1349
PUBLISHED: 2021-01-20
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct Cypher query language injection attacks on an affected system. The vulnerability is due to insufficient input validation by the web-based management interf...