Summarizing audit trails in the Aeolus security platform
Wissam Jarjoui · DSpace@MIT (Massachusetts Institute of Technology) · 2012
Aeolus is a programming platform that supports the development of secure applica-tions that preserve the confidentiality of information entrusted to them. An important part of the Aeolus platform is an auditing subsystem that maintains a log in which it stores information about every security related event that occurs while applications run. The log allows later analysis to determine whether the security policies of the application have been followed. For an Aeolus user, analyzing an Aeolus event log can prove to be a daunting task, especially when this log grows to include millions of records. Similarly, storing such an event log can be very costly. The system I present in this thesis provides an interface that allows the creation of user-defined summaries of the Aeolus audit trails, as well as marking of events in the log for future archiving or deletion. Our system makes it easier to analyze the Aeolus event log and less costly to store events of interest. This is done through the use of a QuerySystem and SummaryObjects. I present the system in the context of a sample application based on the financial management service