Cloud application logging for forensics

Cloud application logging for forensics
复制标题

用于取证的云应用程序日志记录

DOI:
--
复制
发表时间:
2011
期刊:
ACM Symposium on Applied Computing
影响因子:
--
通讯作者:
R. Marty
R. Marty
中科院分区:
--
文献类型:
--
作者:
R. Marty

文献摘要

被引文献

相似文献

数据是基于云的服务基础设施中最重要的分析数据之一。在任何时候,服务所有者和运营商都需要了解每个基础设施组件的状态,以进行故障监控,评估功能使用情况,并监控业务流程。应用程序开发人员以及安全人员需要访问历史信息以进行调试和取证调查。本文讨论了一个日志框架和准则,提供了一个积极主动的方法来记录,以确保所需的法医调查的数据已经生成和收集。标准化的框架消除了日志记录利益相关者重新发明自己的标准的需要。这些准则确保收集与云基础设施和软件即服务(SaaS)用例相关的关键信息,作为深度防御策略的一部分。此外,它们还确保日志使用者可以有效而轻松地分析、处理和关联发出的日志记录。本文的第二部分强调了理论基础,该部分涵盖了在公共云服务上运行的示例SaaS产品中实现框架。虽然该框架的目标是应用程序开发人员并需要他们的支持,但收集的数据对于全面的法医调查至关重要。此外,它还帮助日志架构的IT架构师和技术评估人员构建面向业务的日志框架。
Logs are one of the most important pieces of analytical data in a cloud-based service infrastructure. At any point in time, service owners and operators need to understand the status of each infrastructure component for fault monitoring, to assess feature usage, and to monitor business processes. Application developers, as well as security personnel, need access to historic information for debugging and forensic investigations. This paper discusses a logging framework and guidelines that provide a proactive approach to logging to ensure that the data needed for forensic investigations has been generated and collected. The standardized framework eliminates the need for logging stakeholders to reinvent their own standards. These guidelines make sure that critical information associated with cloud infrastructure and software as a service (SaaS) use-cases are collected as part of a defense in depth strategy. In addition, they ensure that log consumers can effectively and easily analyze, process, and correlate the emitted log records. The theoretical foundations are emphasized in the second part of the paper that covers the implementation of the framework in an example SaaS offering running on a public cloud service. While the framework is targeted towards and requires the buy-in from application developers, the data collected is critical to enable comprehensive forensic investigations. In addition, it helps IT architects and technical evaluators of logging architectures build a business oriented logging framework.