ContentsThe library

The Mistakes Behind Most Breaches

Could You Reconstruct It Afterwards

Last timeSomebody Else's Code

Every earlier lesson assumed you find out. The test of your logging is not whether it exists but whether you can answer, today, a question you will be asked under pressure.

The four questions

Every lesson so far has been about a mistake and its repair. This one is

about the case where the repair was missed, which is the case you should

plan for, since the whole course has been a list of things that keep

happening to competent teams.

When it happens, you will be asked four questions, in roughly this order,

by somebody who needs answers today. What did they reach. When did it

start. Is it still happening. Who else is affected.

That list is the entire specification for your logging. Anything that

helps answer those four is worth keeping, and anything that does not is

volume. The useful property of stating it this way is that it replaces an

unbounded ambition, log everything, with a finite test you can apply to

each decision.

FIG 1The four questions, against what systems usually record
asked in every incident,answerable from a typicaneeds the record identifneeds retention beyond a
what did they reach1010
when did it start1100
is it still happening1100
who else is affected1011
The two marked cells are the usual failure. A typical request log answers when and whether it is continuing, because it records times and addresses, and cannot answer what was reached, because it records the address of the endpoint and not the identifier of the record returned. The bottom row fails for a different reason, which is that the data was deleted before anybody asked.

The six fields

So what has to be in an event. Six things, and the two that go missing

are predictable.

FIG 2The minimum security-relevant event
plaintext
who       the acting account, by stable identifier
          not a display name, which changes

what      the action, from a fixed vocabulary
          read, update, delete, export, grant

which     the identifier of the record acted on
          this is the field that gets omitted
          and it is the one question one needs

where     the source address, and the session
          so two sessions of one account differ

when      a timestamp with an offset, from a
          clock synchronised to a known source

outcome   succeeded, refused, or failed
          refusals matter more than successes
          when you are looking for an attempt

two rules about content:
  no credentials, tokens or card numbers
  no field whose own exposure would be an
  incident, because a log is read widely
Six fields, the first four of which nearly every system already has. The fifth and sixth are the ones that make the difference between a log you can search and a log you can investigate with, and neither costs anything to add.

The identifier of the record is the one that gets left out, and leaving it

out is the difference between knowing that somebody called the invoice

endpoint four thousand times and knowing which four thousand invoices

they received. The first is a shape. The second is the answer to question

one, and it is the one you will have to put in a letter to the people

affected.

Refusals are the second omission. A system that logs only what succeeded

cannot show you the eleven thousand attempts that failed before the

successful one, which is usually the clearest signal there was and often

the only thing distinguishing an attack from ordinary use.

The lesson stops here

4 more paragraphs to go

You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.

The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.

See the planThe contents

This is the reading half

Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.

The contents

The rest of this course

  1. 01One Mistake, Wearing Different Clothes
  2. 02The Caller Is Not Running Your Softwareopening only
  3. 03The Most Common Serious Finding There Isopening only
  4. 04Follow It From the Field to the Place It Runsopening only
  5. 05Your Server Can Reach Things Nobody Outside Canopening only
  6. 06Nobody Chose This, Which Is the Problemopening only
  7. 07Most of What You Ship, You Did Not Writeopening only
  8. 08Could You Reconstruct It Afterwardsyou are here

Read alongside