Transforming Raw Authentication Logs into Interpretable Events

Seth Hastings, Tyler Moore, Corey Bolger, Philip Schumway · 2024

Authentication logs can be helpful to Security Operations Centers (SOCs), but they are often messy, reporting details more relevant to system configurations than user experiences and spreading information on a single authentication session across multiple entries.This paper presents a method for converting raw authentication logs into user-centered "event logs" that exclude non-interactive sessions and capture critical aspects of the authentication experience.This method is demonstrated using real data from a university spanning three semesters.Event construction is presented along with several examples to demonstrate the utility of event logs in the context of a SOC.Authentication success rates are shown to widely vary, with the bottom 5% of users failing more than one third of authentication events.A proactive SOC could utilize such data to assist struggling users.Event logs can also identify persistently locked out users.2.5% of the population under study was locked out in a given week, indicating that interventions by SOC analysts to reinstate locked-out users could be manageable.A final application of event logs can identify problematic applications with above average authentication failure rates that spike periodically.It also identifies lapsed applications with no successful authentications, which account for over 50% of unique applications in our sample.

Read the paper · More papers on PaperTik