You can edit almost every page by Creating an account and confirming your email.

Alien-Sec New Security Boundaries: Difference between revisions

From EverybodyWiki Bios & Wiki
WikiMasterBot2 (talk | contribs)
m remove duplicates internal links
WikiMasterBot2 (talk | contribs)
m automatic correction by IA
Line 1: Line 1:
{{AFC comment|1=[[WP:NOTGUIDE]]. It's unclear what topic this is addressing because the language is too technical. [[User:LynxTufts|LynxTufts]] ([[User talk:LynxTufts|talk]]) 20:45, 28 March 2018 (UTC)}}
{{AFC comment|1=[[WP:NOTGUIDE]]. It's unclear what topic this is addressing because the language is too technical. [[User:LynxTufts|LynxTufts]] ([[User talk:LynxTufts|talk]]) 20:45, 28 March 2018 (UTC)}}


----
----
Line 9: Line 9:
Each file system is monitored and documented by the operating system manufacturer or third-party software manufacturers, for example: [https://www.alien-sec.com Alien-Sec], SolarWinds, ManageEngine etc.
Each file system is monitored and documented by the operating system manufacturer or third-party software manufacturers, for example: [https://www.alien-sec.com Alien-Sec], SolarWinds, ManageEngine etc.


With This Kind of software you can get:
With this kind of software you can get:
* File System Log collection
* File System Log collection
* Centralized File System log aggregation
* Centralized File System log aggregation
* Long-term log storage and retention
* Long-term log storage and retention
* [[Log rotation]]
* [[Log rotation]]
* [[Log analysis]] for each change that occured (in real-time and in bulk after storage)
* [[Log analysis]] for each change that occurred (in real-time and in bulk after storage)
* File System Log search and reporting.
* File System Log search and reporting.
* File System Anomaly Events.
* File System Anomaly Events.
Line 26: Line 26:
* [[Log management#External links|5 External links]]
* [[Log management#External links|5 External links]]


== Overview[edit] ==
== Overview ==
The primary drivers for log management implementations are concerns about [[Computer security|security]], system and network operations (such as [[System administrator|system]] or [[Network administrator|network administration]]) and regulatory compliance. Logs are generated by nearly every computing device, and can often be directed to different locations both on a local [[file system]] or remote system.
The primary drivers for log management implementations are concerns about [[Computer security|security]], system and network operations (such as [[System administrator|system]] or [[Network administrator|network administration]]) and regulatory compliance. Logs are generated by nearly every computing device, and can often be directed to different locations both on a local [[file system]] or remote system.


Line 32: Line 32:
* Volume: log data can reach hundreds of gigabytes of data per day for a large [[organization]]. Simply collecting, centralizing and storing data at this volume can be challenging.
* Volume: log data can reach hundreds of gigabytes of data per day for a large [[organization]]. Simply collecting, centralizing and storing data at this volume can be challenging.
* Normalization: logs are produced in multiple formats. The process of [[Normalization (statistics)|normalization]] is designed to provide a common output for analysis from diverse sources.
* Normalization: logs are produced in multiple formats. The process of [[Normalization (statistics)|normalization]] is designed to provide a common output for analysis from diverse sources.
* Velocity: The speed at which logs are produced from devices can make collection and aggregation difficult
* Velocity: The speed at which logs are produced from devices can make collection and aggregation difficult.
* Veracity: Log events may not be accurate. This is especially problematic from systems that perform detection, such as [[Intrusion detection system|intrusion detection systems]].
* Veracity: Log events may not be accurate. This is especially problematic from systems that perform detection, such as [[Intrusion detection system|intrusion detection systems]].
* Accuracy: Log events that are very accurate. The recorded information is rich in details that build an accurate description of the documented case, For example: [https://www.alien-sec.com File Tracer].  
* Accuracy: Log events that are very accurate. The recorded information is rich in details that build an accurate description of the documented case, for example: [https://www.alien-sec.com File Tracer].  
Users and potential users of log management may purchase complete commercial tools or build their own log-management and intelligence tools, assembling the functionality from various [[Open source|open-source]] components, or acquire (sub-)systems from commercial vendors. Log management is a complicated process and organizations often make mistakes while approaching it.
Users and potential users of log management may purchase complete commercial tools or build their own log-management and intelligence tools, assembling the functionality from various [[Open source|open-source]] components, or acquire (sub-)systems from commercial vendors. Log management is a complicated process and organizations often make mistakes while approaching it.


Line 45: Line 45:
* to help test new features in a development stage
* to help test new features in a development stage


== Deployment life-cycle[edit] ==
== Deployment life-cycle ==
One view<sup>[''[[wikipedia:Citation needed|citation needed]]'']</sup> of assessing the maturity of an organization in terms of the deployment of log-management tools might use<sup>[''[[wikipedia:No original research|original research?]]'']</sup> successive levels such as:
One view<sup>[''[[wikipedia:Citation needed|citation needed]]'']</sup> of assessing the maturity of an organization in terms of the deployment of log-management tools might use<sup>[''[[wikipedia:No original research|original research?]]'']</sup> successive levels such as:
# in the initial stages, organizations use different log-analyzers for analyzing the logs in the devices on the security-perimeter. They aim to identify the patterns of attack on the perimeter infrastructure of the organization.
# In the initial stages, organizations use different log-analyzers for analyzing the logs in the devices on the security-perimeter. They aim to identify the patterns of attack on the perimeter infrastructure of the organization.
# with increased use of integrated computing, organizations mandate logs to identify the access and usage of confidential data within the security-perimeter.
# With increased use of integrated computing, organizations mandate logs to identify the access and usage of confidential data within the security-perimeter.
# at the next level of maturity, the log analyzer can track and monitor the performance and availability of systems at the level of the [[Business|enterprise]] — especially of those information-assets whose availability organizations regard as vital.
# At the next level of maturity, the log analyzer can track and monitor the performance and availability of systems at the level of the [[Business|enterprise]] — especially of those information-assets whose availability organizations regard as vital.
# organizations integrate the logs of various [[business]]-applications into an enterprise log manager for better [[value proposition]].
# Organizations integrate the logs of various [[business]]-applications into an enterprise log manager for better [[value proposition]].
# organizations merge the physical-access monitoring and the logical-access monitoring into a single view.
# Organizations merge the physical-access monitoring and the logical-access monitoring into a single view.


== See also[edit] ==
== See also ==
* [[Audit trail]]
* [[Audit trail]]
* [[Common Base Event]]
* [[Common Base Event]]
Line 67: Line 67:
* [[Web log analysis software]]
* [[Web log analysis software]]


== External links[edit] ==
== External links ==
* [https://www.alien-sec.com ShadowRDP Remote Control Tool for Easy Terminal Environment Sessions Control and Support]
* [https://www.alien-sec.com ShadowRDP Remote Control Tool for Easy Terminal Environment Sessions Control and Support]
* [https://www.alien-sec.com File Tracer - Monitor Multiple Folders for Any Changes, Automatically Create Events in Windows Event Log]
* [https://www.alien-sec.com File Tracer - Monitor Multiple Folders for Any Changes, Automatically Create Events in Windows Event Log]

Revision as of 22:55, 11 January 2026




File Tracer - File system monitoring is an essential process that allows for information about changes or actions in the monitored file system or folders.

Each file system is monitored and documented by the operating system manufacturer or third-party software manufacturers, for example: Alien-Sec, SolarWinds, ManageEngine etc.

With this kind of software you can get:

  • File System Log collection
  • Centralized File System log aggregation
  • Long-term log storage and retention
  • Log rotation
  • Log analysis for each change that occurred (in real-time and in bulk after storage)
  • File System Log search and reporting.
  • File System Anomaly Events.

Contents

 [[null hide]]

Overview

The primary drivers for log management implementations are concerns about security, system and network operations (such as system or network administration) and regulatory compliance. Logs are generated by nearly every computing device, and can often be directed to different locations both on a local file system or remote system.

Effectively analyzing large volumes of diverse logs can pose many challenges, such as:

  • Volume: log data can reach hundreds of gigabytes of data per day for a large organization. Simply collecting, centralizing and storing data at this volume can be challenging.
  • Normalization: logs are produced in multiple formats. The process of normalization is designed to provide a common output for analysis from diverse sources.
  • Velocity: The speed at which logs are produced from devices can make collection and aggregation difficult.
  • Veracity: Log events may not be accurate. This is especially problematic from systems that perform detection, such as intrusion detection systems.
  • Accuracy: Log events that are very accurate. The recorded information is rich in details that build an accurate description of the documented case, for example: File Tracer.

Users and potential users of log management may purchase complete commercial tools or build their own log-management and intelligence tools, assembling the functionality from various open-source components, or acquire (sub-)systems from commercial vendors. Log management is a complicated process and organizations often make mistakes while approaching it.

Suggestions were made[by whom?] to change the definition of logging. This change would keep matters both more pure and more easily maintainable:

  • Logging would then be defined as all instantly discardable data on the technical process of an application or website, as it represents and processes data and user input.
  • Auditing, then, would involve data that is not immediately discardable. In other words: data that is assembled in the auditing process, is stored persistently, is protected by authorization schemes and is, always, connected to some end-user functional requirement.

Logging can produce technical information usable for the maintenance of applications or websites. It can serve:

  • to define whether a reported bug is actually a bug
  • to help analyze, reproduce and solve bugs
  • to help test new features in a development stage

Deployment life-cycle

One view[citation needed] of assessing the maturity of an organization in terms of the deployment of log-management tools might use[original research?] successive levels such as:

  1. In the initial stages, organizations use different log-analyzers for analyzing the logs in the devices on the security-perimeter. They aim to identify the patterns of attack on the perimeter infrastructure of the organization.
  2. With increased use of integrated computing, organizations mandate logs to identify the access and usage of confidential data within the security-perimeter.
  3. At the next level of maturity, the log analyzer can track and monitor the performance and availability of systems at the level of the enterprise — especially of those information-assets whose availability organizations regard as vital.
  4. Organizations integrate the logs of various business-applications into an enterprise log manager for better value proposition.
  5. Organizations merge the physical-access monitoring and the logical-access monitoring into a single view.

See also

External links

References



This article "Alien-Sec New Security Boundaries" is from Wikipedia. The list of its authors can be seen in its historical and/or the page Edithistory:Alien-Sec New Security Boundaries. Articles copied from Draft Namespace on Wikipedia could be seen on the Draft Namespace of Wikipedia and not main one.