Analisi dei log d'&eacutevento (logs) Análise dos diários de acontecimentos (registos) Analyse der Logs Analyse des journaux d'événements (logs) Análisis de los registros

Analysing logs

One of the best ways to detect intrusions is to monitor event logs (sometimes called logs for short).

In general, servers store logs of their activity, and in particular any errors encountered, in files.

Therefore, after a computer attack, it is rare for the hacker to successfully compromise a system on the first try. He/she usually works by trial and error, testing out various requests.

This is why log monitoring can be used to detect suspicious activity. It is particularly important to monitor the logs of security-related software; as well-configured as they may be, they may still be the target of an attack.

Concept of noise

In reality, it is not obvious which alerts are triggered by real attacks by worms and viruses, and which are caused by tools such as vulnerability analysers.

For this reason, most attacks on servers are attacks which are completely unable to compromise the system (such as Microsoft IIS server attacks used on Linux servers with Apache).

They do, however, trigger false alarms, causing what is known as "noise", which makes it harder to focus on real alarms.

Article written 22 July 2005 by Jean-François Pillou.

Last update on Thursday October 16, 2008 02:43:19 PM.This document entitled « Analysing logs » from Kioskea (en.kioskea.net) is made available under the Creative Commons license. You can copy, modify copies of this page, under the conditions stipulated by the licence, as this note appears clearly.

Best answers for « Analysing logs » in :
Monitoring event logs Show Analysing logs One of the best ways to detect intrusions is to monitor event logs (sometimes called logs for short). In general, servers store logs of their activity, and in particular any errors encountered, in files. Therefore, after a computer...
Attack detection Show Analysing logs One of the best ways to detect intrusions is to monitor event logs (sometimes called logs for short). In general, servers store logs of their activity, and in particular any errors encountered, in files. Therefore, after a computer...
Online scan with Kaspersky ShowOnline scan with Kaspersky Intro Getting started Computer Analysis Analysis results Backup Report Intro At about Kaspersky Online Scanner 7.0 Kaspersky Online Scanner does not remove, but it lists in a report any infections...
[Apache]Monitoring web traffic in real-time Show[Apache]Monitoring web traffic in real-time There are tool endemic to Apache web server allowing a real-time analysis of the web traffic: Log files can be used by specialized software to develop a comprehensive and complete analysis of...
Filtering Apache logs / conditional Logging ShowFiltering Apache logs / conditional Logging Log-ins used by Apache Web server is usually very wordy, they contain all type of information (image files, style sheets, javascript, son RSS, etc.) This can be very troublesome when trying to...
Download ESBPDF Analysis ShowThe economic or financial analysis of a project always requires calculation of probability in order to estimate its feasibility. To help you to calculate and obtain a reliable result, you need a powerful tool like ESBPDF Analysis. This program...
Analyst-programmer (developer) ShowDeveloper The profession of a developer (also called an analyst-programmer) involves designing and developing a computer application; that is, transcribing a need into a computer-based solution written in computer language. Historically, computer...
Analyst programmer ShowAnalyst programmer The analyst is to the programmer what designing is to programming. It is a design profession that involves translating the client's needs into instructions, i.e. drawing up the project specifications or the functional...
Network equipment - The switch ShowSwitches A switch is a multi-port bridge, meaning that it is an active element working on layer 2 of the OSI model. The switch analyses the frames coming in on its entry ports and filters the data in order to focus solely on the right ports (this...