25.12.2014 Views

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Barrie Codona, BSc (Hons) Network Computing, 2007<br />

it was modified <strong>the</strong> asynchronous encryption caused a buffer overflow which in turn<br />

caused <strong>the</strong> application to stop capturing events. There still remains <strong>the</strong> problem <strong>of</strong> <strong>the</strong><br />

possibility <strong>of</strong> a man-in-<strong>the</strong>-middle attack.<br />

The HMAC hash is prone to a brute force attack <strong>and</strong> even more prone to a dictionarybased<br />

attack. It had been found that 21,093 keys could be checked every second. The<br />

only way to minimise <strong>the</strong> risks <strong>of</strong> brute force <strong>and</strong> dictionary attacks would be to use a<br />

large r<strong>and</strong>om key, which should be changed at a predetermined interval, this could be<br />

ei<strong>the</strong>r monthly or yearly. Ano<strong>the</strong>r problem that exists is <strong>the</strong> credibility <strong>of</strong> historical<br />

events in <strong>the</strong> event log could become questionable. Perhaps <strong>the</strong>se could be better<br />

protected by archiving <strong>the</strong>m using encryption.<br />

Overall <strong>the</strong> system successfully managed to capture when <strong>the</strong> ‘Sec<strong>Event</strong>.txt’ file was<br />

being modified while a large number <strong>of</strong> o<strong>the</strong>r events were happening at <strong>the</strong> same time.<br />

These events were <strong>the</strong>n securely stored on <strong>the</strong> Data Archiving system.<br />

67

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!