Skip to main content

OWASP Security Logging and Monitoring Failures Explained

N2K NetworksMay 27, 20256 min92 views
17 connections·20 entities in this video

Understanding OWASP Security Logging and Monitoring Failures

  • 💡 OWASP stands for the Open Web Application Security Project, an international community dedicated to improving software security.
  • 📌 Security logging involves collecting telemetry from applications, while monitoring is the process of analyzing these logs for malicious activity.
  • ⚠️ Security logging and monitoring failures are defined as the absence of telemetry that hinders network defenders from detecting and responding to cyber threats.

Impact and Origin of Logging Failures

  • 🎯 While not a direct vulnerability, these failures significantly impact visibility, incident alerting, and forensics capabilities.
  • 🔑 Logging failures often occur when auditable events are not logged, logged only locally, or logged inadequately.
  • 🔍 Auditable events that should be logged include brute force password attacks, data exfiltration, and tracking high-value transactions.
  • 💡 The concept originated from an educational piece in 2003 by Dave Wickers and Jeff Williams, which evolved into the OWASP Top 10.

OWASP Top 10 and Best Practices

  • 📈 In the 2021 OWASP Top 10 list, security logging and monitoring failures moved to number nine.
  • 🚀 Precise logging doesn't prevent cyberattacks but is crucial for detection and response.
  • 🗣️ It's not enough to simply log events; active monitoring of these logs is essential to identify potential issues.
  • 🛠️ For guidance on what to monitor, consider having a red team attempt to compromise the system and devise alerts based on their successes.
Knowledge graph20 entities · 17 connections

How they connect

An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.

Hover · drag to explore
20 entities
Chapters3 moments

Key Moments

Transcript22 segments

Full Transcript

Topics12 themes

What’s Discussed

OWASPSecurity LoggingSecurity MonitoringTelemetryCybersecurityIncident ResponseData ExfiltrationBrute Force AttacksWeb Application SecurityOWASP Top 10ForensicsRed Teaming
Smart Objects20 · 17 links
Companies· 3
Concepts· 4
Event· 1
People· 6
Medias· 6