3 ms·
This is true! It's also a checklist item that often involves shuffling a lot of bits around, storing them for 60, 90, or 366 days, and then deleting them, and w
by truffdog 5y ago
This is true! It's also a checklist item that often involves shuffling a lot of bits around, storing them for 60, 90, or 366 days, and then deleting them, and without anyone or anything having read them.
- staticassertion 5y agoOK but it's also extremely useful and the backbone of almost all incident response on Linux servers... The fact that it's a checklist really isn't relevant - no one is checklisting that specific system calls are instrumented, and that's not even how compliance works.
- nightfly 5y agoSo is most logging and monitoring. The important part is having those bits around when you _need_ to see them.
- Spidler 5y agoAs with many checklist items, it is a useful technology that when set up and followed, can be totally awesome. Turning on and adding some "proper" filters on the audit subsystem won us the first spot in a CTF, as the early markers that "something is up" turned out to be excellent. But if all you do with it is pipe it to your log server and ignore it? Well, then it's not really going to help you, and is only a checkbox item. I feel that much of this disparaging on various "checklist" items is crappy half-assed semi-elitism. Checklists are _amazing_ tools for preventing accidents in many industries, everything from surgery to trains and flight use them with great success. So why can't information security professionals use them without being derided by others in the business? Perhaps the same reason as doctors insisted that hand washing was time consuming and unnecessary, or the financial institutes that insist that oversight and auditing is unnecessary.