The design of an audit trail analysis tool
Eric A. Fisch, Gregory B. White, Udo W. Pooch · 2002
Discusses the design of a tool that automatically removes security-sensitive information from intruder activity log files collected at a compromised site. The sanitization of sensitive information enables researchers to study the log files without further compromising the security of the affected sites. This paper begins with a brief discussion of the importance of such a tool and a description of the complete sanitization process. This is followed by an examination of the important design issues of the sanitizer. The paper concludes with the final design of a sanitizer for SunOS-based intruder activity logs.>