General discussion
June 18, 2003 at 05:26 AM
rabbit_runner

Preserving Security Logs

by rabbit_runner . Updated 23 years, 3 months ago

We are working with a customer which had an internal security breach. Now we are required to put safe-guards into place for them. Here is the problem…..
First, the background.
There are 7 network administrators and all have access to the Domain (2000 w/ AD) administrator’s account. No one else knows this account and no one, other than these 7, know the password. A couple of weeks ago, on a Saturday night, someone connected via VPN using the domain administrator’s account. Network monitoring caught this person using the internet for “non-company” purposes and there is a specific “written” company policy against the activity which they were doing. From the WINS database, we were able to determine the name of the computer being used to connect, and therefore pin-point the specific person. When confronted, they admitted the action and are not being delt with, according to the written policy.
Second, the problem.
On the server which was used for the VPN, the security log was deleted, about the same time that this activity (above) was being done. Suspicion would point to the same person. However, we have no way of proving whether this individual, or some other administrator, deleted this particular log. The domain logs were set to a small size and have been written over.
The deletion of a server log has the company managers, just plain livid. (and that is saying it kindly) They are wanting some method in place where the server log files can be copied or kept to prevent such information from coming up “missing”.
In this question, I am not interested in all of the other things that can be done to prevent this from happening. We are ONLY interested (with this question) to preserving all the log files. Does anyone have a method where files can be kept safe, in real-time? Any ideas would be helpful. Thanks.

Michael R.

This discussion is locked

All Comments