Home > Ask the Security Experts > Application Security Questions & Answers > Which tools can keep personally identifiable information (PII) out of access logs?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Which tools can keep personally identifiable information (PII) out of access logs?

Michael Cobb EXPERT RESPONSE FROM: Michael Cobb

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 20 June 2007
Which tools can hide the identity of Web server access logs so that they can be viewed and analyzed securely by a third party? I don't want to expose internal IP address information outside of the company.

>
EXPERT RESPONSE
Companies such as Metronome Labs offer tools that can keep log files from including personally identifiable information. The technology prevents the transfer of PII to a third party unless the owner provides explicit permission. However, I do not know of any specific tools that hide internal IP addresses recorded in log files. Before I discuss a possible action, I wonder whether you have considered the underlying issues that have resulted in your need for such a tool.

Firstly, if you do not trust the third party who is analyzing your logs, or do not feel that the company's service level agreement (SLA) provides you with enough assurances, then you need to find another organization to deliver the log-analysis service. Secondly, if you feel that it is imperative to hide internal IP address information, then you should look at undertaking log analysis on your own.

If this is not an option, you could simply use a text editor to do a "search and replace" of key IP addresses. Then, for each found address, you could substitute the IP string with a false one. There are some issues that you should be aware of, though, before you alter your log files.

When doing any log file analysis, you must never work with the original files. In the event of a security incident, log files will be an essential aid in forensic analysis. Therefore, you need to make copies before performing any post-processing or analysis. When used as court evidence, files must be presented in their original form. By making sure that your original logs are never altered, you can be sure that they are still authentic.

If you are running several Web servers, it would be my preference to send the log files to a central syslog server rather than have them written to the local file system. Many attackers now try to hide their tracks by altering or deleting the server's log files. Storing the files on a secure log server therefore makes it a lot harder for malicious hackers to hide their activities.

If you use a central server, it is important that you keep your system clocks synchronized using the Network Time Protocol (NTP). Otherwise, log entries will inevitably appear to be recorded out of order, causing difficulties for many analytical software programs. If you move your logs offline -- to a tape, for example -- you will need to record how the files were moved and where they were moved to. In a criminal investigation where the contents of a backup may need to be investigated, tracking custody of evidence is especially important.

One way to be absolutely sure that a log file has not been modified is to sign and encrypt it using a public-key encryption program such as PGP.

More information:

  • Learn how service-level agreements (SLAs) can ensure compliance across the extended enterprise.
  • Can a security administrator be granted exclusive access to a Windows 2000 security log? Joel Dubin explains why access is all or nothing.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Application Security
    What risks do application virtualization products pose to enterprise security?
    Do BlackBerrys and other mobile devices put sensitive data at risk when used overseas?
    How can quality assurance tools aid software development?
    Should UTM and Web security filtering software be used together?
    Is the iPhone amenable to any method of email encryption?
    What are effective ways to stop instant messaging (IM) spam?
    Is it impossible to successfully remove a rootkit?
    Can IBM's SMash technology secure Web applications?
    Why is backscatter spam so difficult to block?
    What are the risks of disabling the User Account Control (UAC) feature on Windows Vista?

    Web Access Control
    IBM USB banking device stops keyloggers, malware
    Sun launches open source OpenSSO for identity management
    Should a new user have to confirm his or her email address before gaining access?
    Shared Identity Providers Could Soothe Password Chaos
    Users are complaining that they can no longer reach any login site belonging to Microsoft. Any ideas?
    Vista WIL: How to take control of data integrity levels
    Video: Changes ahead for MIT Kerberos Consortium
    Kerberos security evolves for B2B, mobile tech
    Kerberos: Authentication with some drawbacks
    Sun shifts strategy with GRC push

    User Provisioning
    New Sun product illustrates identity management trend
    What tools provide user provisioning and single sign-on for PeopleSoft- and Unix-based products?
    User provisioning: Emerging product features reveal market's future
    Is it possible to write a batch file that allows user access to the local admin group for a short time?
    Quiz: The new school of enterprise authentication
    The steps of privileged account management implementation
    What are best practices for remote management of medical imaging devices?
    Enterprise role management: Trends and best practices
    Societe Generale bolsters internal controls, discovers second insider
    What guidelines do you recommend regarding best practices for user provisioning?

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    access log  (SearchSecurity.com)
    anonymous Web surfing  (SearchSecurity.com)
    authentication, authorization, and accounting  (SearchSecurity.com)
    identity chaos  (SearchSecurity.com)
    multifactor authentication (MFA)  (SearchSecurity.com)
    walled garden  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts