Auditing the Internet

Jon David · Network Security · 1996

The audit function is frequently an afterthought in the design and installation of security. The primary goal of security is viewed as the prevention of compromise, and often only after a breach is it realized that existing audit abilities, if at all present, are grossly deficient. Auditing allows transactions and activities to be tracked — from their point of origin, through intermediate steps, to their final state. Since it is possible to breach any security, an extensive audit ability is necessary to determine how the breach succeeded (i.e. how the intruder/unauthorized user got in) and what damages, if any, were done.

Read the paper · More papers on PaperTik