|
|
Log Forensics Hands-On Lab: 2 hours; requires PC of any type Corporate regulations and the desire to keep confidential information secure have led enterprises to collect and analyze log data to provide a continuous fingerprint of everything that happens on the IT systems. However, this process is subject to a variety of obstacles. Anton will discuss challenges that organizations face while deploying log collection and analysis infrastructure, highlighting the most common mistakes organizations make (including not storing logs long enough to comply with government regulations, not preserving the forensic quality of logs, and only looking for known 'bad records') as well as how to address and correct these mistakes. For a look at a similar presentation go to http://www.slideshare.net/anton_chuvakin/six-mistakes-of-log-management-teaser-preso. Six Mistakes of log Management The presentation will cover operational security challenges that organizations face while deploying log, audit trail and alert collection and analysis infrastructure. The story will center on the common mistakes organizations make in that process. Those include not storing logs long enough, not preserving the forensic quality of the logs, only looking for known bad records as well as others. I will highlight how to avoid these and other mistakes and how to get the most value out of various log files, generated by systems, applications and security devices. Relevant regulatory compliance landscape which impacts log management will also be considered. Biography For more information on Dr. Chuvakin please visit his website at http://www.chuvakin.org/. |