Untitled Document
 Register Now & Save!
Untitled Document
2009 Gold Sponsor
Untitled Document
2009 Silver Sponsor
Untitled Document
2009 Panel Sponsor
Untitled Document
2009 Exhibitors
Untitled Document
2009 Media Sponsors
Latest News
In 2011, Apache Hadoop received tremendous attenti...
AMD said late Tuesday that its chief sales officer...
Intel has finally seen the back of that 2009 antit...
On Tuesday, Clustrix announced the availability of...
What are the legal implications and consequences o...
EMC moved to make Hadoop safe for the Joe Blow big...
Amazon has reined in the price of its S3 storage a...
The focus of Java EE 7 is on the cloud, and specif...
2011 was a year of rapid adoption for public and p...
AMD Thursday told financial analysts it’s gonna tr...
Can't Miss RSS Feed
Subscribe to the RSS Feed & Get All The Conference News As It Happens!
Logs for Better Clouds - Part 7: Log Integrity
Not All Log Management Solutions Created Equal

Not all Log Management solutions are created equal... Trusting your logs.

Log Integrity is at the core of using logs for such purpose as building Trust, providing non-repudiation and indisputable proof in business relationships between Customers and Providers, but also to provide for evidence admissible in a court of law. We saw that not all Log Management solutions are created equal, and we saw some high-level requirements in terms of log collection and log reporting. We need a solution that is simple to deploy - we want an enabler, not a disabler - and a solution that allows a very rich set of APIs to accommodate for very different reporting on all kinds of metrics.

There are 2 other Critical Success Factors that need to be part of the "Not all Log Management Solutions are Created Equal" equation, and these are Log Integrity and Provider Reversibility. Today, more on Log Integrity.

Log Integrity
Logs can be used to foster Trust by providing non-repudiation and indisputable proof... provided that we can Trust the logs, in other words if we can guarantee their integrity. This is important not only for Trust for business relationship between a customer and its provider, but also in case of security breach as logs become prime evidence and need to be admissible in a court of law.  Imagine seeing malicious behavior but not being able to use your logs as evidence because you cannot guarantee that they have not been tampered with. It's like if you knew a crime was committed and you even have a picture of it, but this evidence is thrown away because you cannot prove that it was not photoshop'ed. Too bad...

We need 3 different proofs of integrity are demonstrated;

  1. Proof of integrity of each log - demonstrate that no log has been altered.
  2. Proof of integrity of the log sequence - demonstrate that no log has been added and no log has been deleted.
  3. Proof of integrity of the report - demonstrate that the report is complete and that all logs are reported on.

Once all of these are provided, there is Explicit Trust in raw logs. There are many ways of providing Log Integrity and Log Sequence Integrity, let's have a look at one of the easiest ways, to create a digitally signed - or at least a one-way hashed - chained file of logs.

In the following diagram Figure 7, we see how this can provide for log integrity and log sequence integrity.

Figure 7: Proof of log integrity through log block chaining and signing

In the following diagram Figure 8, we see that any modification of a log or any modification of the log sequence will be immediately detected and that we’ll be able to claim loss of integrity in logs. Without getting into implementation considerations, there are obvious tradeoffs on the size of each log block. The longer the block, the easier the management and the better the performance; the shorter the block, the fewer logs we have to throw away if we were to detect loss of integrity.

Figure 8: Loss of integrity detected

We can now trust the information contained in the raw logs as being genuine, and we can trust the information contained in the reports as being non-tainted. Report completeness needs to be guaranteed by the tool, in other words, there needs to be built-in mechanisms that insure that all logs that need to be part of a report are included in the report generation and computation. This is an inherent function of the tool. We can never prevent accidental or malicious modification of a log, but we can detect modifications with a simple yet powerful way, Log Block Chaining and Signing. This will insure that the logs that we work from are genuine, have not been modified, and represent a clean source of data on top on which we can build non-repudiation and proof of claim, we can claim Trust.

About Gorka Sadowski
Gorka is an expert in Governance and Risk Management. He spent the last 20 years helping large enterprises use technology to automate and enable their business processes, and allowing solution providers to better position, sell and market their solutions to the marketplace. He is today involved with technology-related activities for large end-clients and strategic partners for LogLogic in Europe. Gorka was Director of the Security Group for Unisys France, leading a team of security consultants and managing the integration of complex solutions for global CAC40 corporations. He spent 15 years in the USA, where he was Director of Emerging Technologies at NetScreen in the Silicon Valley. Gorka also held the position of Director of the Security Group for CTP, a software development firm specialized in the design and implementation of custom business applications for the largest companies in America.

Untitled Document

Call 201 802-3021 or Click Here to Save $400!

Save $400

 Sponsorship Opportunities

SYS-CON's International Cloud Computing Conference & Expo, held each year in California, New York and Prague is the leading event covering the fast-emerging Cloud Computing market for Enterprise IT professionals. Co-located with the International Virtualization Conference & Expo, the combined event will surely deliver the #1 i-Technology educational and networking opportunity of the year for those seeking to establish a market lead anywhere in the multiple layers of the Cloud Computing ecosystem.





Who Should Attend?

Senior Technologists including CIOs, CTOs, VPs of technology, IT directors and managers, network and storage managers, network engineers, enterprise architects, communications and networking specialists, directors of infrastructure Business Executives including CEOs, CMOs, CIOs, presidents, VPs, directors, business development; product and purchasing managers.


Video Coverage of Cloud Computing Expo

Brian Stevens: The Opening of Virtualization
Jon Wallace: User Environment Management – The Third Layer of the Desktop
Brian Duckering & Ken Berryman: Managing Hybrid Endpoint Environments
Preeti Somal: Game-Changing Technology for Enterprise Cloud and Applications

 Conference Media Sponsor: Cloud Computing Journal

Cloud Computing Journal aims to help open the eyes of Enterprise IT professionals to the economics and strategies that utility/cloud computing provides. Cloud computing - the provision of scalable IT resources as a service, using Internet technologies - potentially impacts every aspect of how IT deploys and operates software.

Government IT Conference & Expo 2009
Allstar Conference Faculty Lineup Will Include...


CHEVALIER

Novell Canada

DICARLO

Sun Micosystems

FOXWELL

Sun Microsystems Federal

GABHART

Web Age Solutions

GREENBERG

Integralis

HAHN

Tranxition

WILLIAMS

Maxworks

JACKSON

Dataline, LLC

KHOSLA

IBM

KRZYSKO

US Departement of Defense

LIBERMAN

Lieberman Software

MARKS

AgilePath

MORGENTHAL

QinetiQ North America

RYAN

Asankya

TRAJMAN

Vertica

WHITE

BDNA


SYS-CON EVENTS


Past Events Archive

Cloud Computing Conference & Expo
2009 East

cloudcomputingexpo
2009east.sys-con.com/
Virtualization Conference & Expo
2009 East

virtualizationconference
2009east.sys-con.com/
Cloud Computing Conference & Expo
2008 West

cloudcomputingexpo
2008west.sys-con.com/
SOAWorld Conference & Expo 2008 West
soaworld2008.com/
Virtualization Conference & Expo 2008 West
virtualizationconference
2008west.sys-con.com
AJAXWorld Conference & Expo 2008 West
ajaxoct08.sys-con.com
SOAWorld Conference & Expo 2008 East
soa2008east.sys-con.com
Virtualization Conference & Expo 2008 East
virt2008east.sys-con.com
AJAXWorld 2008 Conference & Expo East
ajaxmar08.sys-con.com
SOAWorld Conference & Expo 2007 West
www.soaworld2007.com
Virtualization Conference & Expo 2007 West
virt2007west.sys-con.com
AJAXWorld 2007 Conference & Expo West
ajaxoct07.sys-con.com

Cloud Computing Expo Alumni Delegates Represents...

• AccuRev
• Adea Solutions
• Adobe Systems, Inc [3 delegates]
• ADP
• Aeropostale, Inc
• Aetna
• Akbank Training Center
• American Family Insurance
• American International College
• American Modern Insurance
• Amphion Innovations
• Amplify LLC, Clipmarks [2 delegates]
• Anderson Consulting
• Arrow Electronics [3 delegates]
• Ashcroft Inc
• Athabasca University
• ATS
• Audatex
• Avanade, Inc.
• Avaya Inc. [5 delegates]
• Azul [2 delegates]
• Backbase [2 delegates]
• Bank of America
• Bank of NY
• Barnes and Noble
• Barnex Investment International Limited
• BEA
• Bear Stearns [2 delegates]
• Bendel Newspaper Company Limited
• BizInnovative
• Bloomberg [2 delegates]
• BlueBrick Inc.
• BMC Software
• Boeing
• Bottomline Technologies [2 delegates]
• BP
• Broadcom

   read more...
Cloud Computing Blogs
In other words, VMware’s server density is higher. Boles suggests this means that customers should be “assessing virtualisation on a ‘cost per application’ basis. VM density has a sign
Traditionally, the way people have implemented high availability is by using a high-availability management package like Linux-HA[1], then configure it in detail for each application, file system moun