A Novel Event-Oriented Architecture for Logging and Auditing in Distributed Systems
Elnaz B. Noeparast, Reza Ravani · Advances in Network and Communications · 2012
Due to widespread communications and unsafe accesses in distributed systems, controlling and auditing of events are considered as one of the major challenges to achieve security goals. Several methods have been introduced with some drawbacks such as the integrated information accuracy concern, server overhead and impossibility of client management in emergency situations. This paper presents a new architecture for logging and auditing systems. Tampering and losing data prevention, reducing server overhead during data collection and integration and notifying the clients' status to server to apply suitable security policy are the main goals of the proposed architecture. In our system architecture, system events are classified to four categories, negligible, marginal, critical and catastrophic. Only the information of critical and catastrophic events will be sent to the server during emergencies. Also, this paper presents a method for data encryption which has a validity period and it will be updated periodically from the server.