Blog

코더들이 보안을 정복하다: Share & Learn 시리즈 - 불충분한 로깅 및 모니터링

May 30, 2019
Jaap Karan Singh

While we have been exploring topics in these blogs, we've uncovered quite a few dangerous vulnerabilities and malicious exploits that hackers employ to assault networks and bypass defenses. They run quite the gamut from exploiting weaknesses in programming languages, to injecting code using various formats, to hijacking data in transit. It's quite a range of threats, but whenever any of them are successful, there is often one common component shared among their victim's applications.

Insufficient logging and monitoring is one of the most dangerous conditions that can exist within an application's defensive structure. If this vulnerability or condition exists, then almost any advanced attack made against it will eventually be successful. Having insufficient logging and monitoring means that attacks or attempted attacks are not discovered for a very long time, if at all. It basically gives attackers the time they need to find a useful vulnerability and exploit it.

In this episode we will learn:

  • How attackers can use insufficient logging and monitoring
  • Why insufficient logging and monitoring is dangerous
  • Techniques that can fix this vulnerability.

How do Attackers Exploit Insufficient Logging and Monitoring?

At first, attackers don't know if a system is being properly monitored, or if log files are being examined for suspicious activity. But it's easy enough for them to find out. What they will sometimes do is launch some form of inelegant, brute force type of attack, perhaps querying a user database for commonly used passwords. Then they wait a few days and try the same kind of attack again. If they are not blocked from doing it the second time, then it's a good indication that nobody is carefully monitoring the log files for suspicious activity.

Even though it's relatively simple to test an application's defenses and gauge the level of active monitoring happening, it's not a requirement of successful attacks. They can simply launch their attacks in such a way as to make as little noise as possible. More often than not, the combination of too many alerts, alert fatigue, poor security configurations or simply a plethora of exploitable vulnerabilities means that they will have plenty of time to complete their goals before defenders even realize that they are there.

Why is Insufficient Logging and Monitoring Dangerous?

Insufficient logging and monitoring is dangerous because it gives attackers time to not only launch their attacks, but to complete their goals long before defenders can launch a response. How much time depends on the attacked network, but different groups like the Open Web Application Security Project (OWASP) puts the average response time for breached networks at 191 days or longer.

Think about that for a moment. What would happen if robbers held up a bank, people called the police, and it took them half a year to respond?

The robbers would be long gone by the time police arrived. In fact, that same bank can be robbed many more times before the police even respond to the first incident.

It's like that in cybersecurity too. Most of the high profile breaches that you hear about on the news were not smash and grab type of operations. Often times the targeted organization only learns about a breach after the attackers have had more or less full control over data for months or even years. This makes insufficient logging and monitoring one of the most dangerous situations that can happen when trying to practice good cybersecurity.

Eliminating Insufficient Logging and Monitoring

Preventing insufficient logging and monitoring requires two main things. First, all applications must be created with the ability to monitor and log server-side input validation failures with enough user context for security teams to identify the tools and techniques, if not the user accounts, that attackers are using. Or, such input should be formatted into a language like STIX (Structured Threat Information eXpression) which can be quickly processed by security tools to generate appropriate alerts.

Secondly, it's not enough to simply generate good alerts, though that is a start. Organizations also need to establish roles and responsibilities so that those alerts are investigated in a timely fashion. Many successful breaches actually triggered alerts on the attacked networks, but those warning were not heeded because of questions of responsibility. Nobody knew whose job it was to respond, or assumed that someone else was looking into the problem.

A good place to start when assigning responsibilities is adopting an incident response and recovery plan like the one recommended by the National Institute of Standards and Technology (NIST) in special publication 800-61. There are other reference documents, including ones specific to various industries, and they don't have to be followed to the letter. But forming a plan defining who within an organization responds to alerts, and how they go about doing that in a timely fashion, is critical.

More Information about Insufficient Logging and Monitoring

For further reading, you can take a look at what OWASP says about insufficient logging and monitoring. You can also put your newfound defensive knowledge to the test with the free demo of the Secure Code Warrior platform, which trains cybersecurity teams to become the ultimate cyber warriors. To learn more about defeating this vulnerability, and a rogues'gallery of other threats, visit the Secure Code Warrior blog.

Ready to find, fix and eliminate insufficient logging and monitoring right now? Head to our training arena: [Start Here]

태그라인

Govern AI-driven development before it ships

Measure AI-assisted risk, enforce secure coding policy at commit, and accelerate secure delivery across your SDLC.

데모 예약하기
태그라인

Explore more blogs

우리는 이 방법을 잘 알고 있습니다. 우리는 이 두 가지 축복을 골고루 살기 위해 노력하고 있습니다.

browse all
Case Study
Filter Label
This is some text inside of a div block.

Supercharged Security Awareness: How Tournaments are Inspiring Developers at Erste Group

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
Case Study
Filter Label
This is some text inside of a div block.

Security as culture: How Blue Prism cultivates world-class secure developers

Learn how Blue Prism, the global leader in intelligent automation for the enterprise, used Secure Code Warrior's agile learning platform to create a security-first culture with their developers, achieve their business goals, and ship secure code at speed

Learn More
Case Study
Filter Label
This is some text inside of a div block.

하나의 보안 문화: Sage가 애자일 보안 코딩 학습을 통해 보안 챔피언 프로그램을 구축한 방법

Sage가 유연하고 관계 중심적인 접근 방식을 통해 어떻게 보안을 강화하고, 200명 이상의 보안 챔피언을 양성하며, 실질적인 위험 감소를 달성했는지 확인해 보세요.

Learn More
Blog
Filter Label
This is some text inside of a div block.

이제 모든 직원이 AI 사이버 보안의 최전선에 있습니다

엔터프라이즈 기술 환경은 뒤늦게 깨달았을 때는 이미 늦었을 만큼 빠른 속도로 변화하고 있습니다. 우리는 이제 사람이 직접 작성한 코드와 기본적인 코파일럿 지원의 시대를 넘어, 에이전트 기반 개발 수명 주기(ADLC)의 시대로 공식적으로 진입했습니다. 자율형 AI 에이전트는 다양한 기능 전반에 걸쳐 전례 없는 효율성을 약속하지만, 동시에 완전히 새로운 차원의 보안 및 규제 위험을 야기합니다.

Learn More
Blog
Filter Label
This is some text inside of a div block.

7번째 지원 요소: 개발자 인정

인정은 참여의 원동력입니다. Enabler 7은 개발자의 성취를 널리 알리고, 실질적인 보안 코딩 성과를 거둔 개발자에게 보상과 특별한 굿즈를 제공하여 이를 기념합니다.

Learn More
Blog
Filter Label
This is some text inside of a div block.

Gartner® Hype Cycle™ for Application Security 2026 선정

Secure Code Warrior가 Gartner® Hype Cycle™ for Application Security 2026의 Agentic Coding Security 및 Secure Coding Training 부문에 선정되었습니다. 그 이유를 소개합니다.

Learn More

Secure AI-driven development before it ships

See developer risk, enforce policy, and prevent vulnerabilities across your software development lifecycle.

데모 예약하기
No items found.