Роль журналов событий в выявлении и расследовании инцидентов
Журнал: НБИ технологии @nbi-technologies
Рубрика: Информационные технологии в безопасности и телекоммуникациях
Статья в выпуске: 3 т.19, 2025 года.
Бесплатный доступ
В статье рассматривается роль журналов событий в процессе выявления и расследования компьютерных инцидентов. Проанализированы основные виды логов, их особенности, преимущества и ограничения. Особое внимание уделено связи журналов событий с этапами модели MITRE ATT&CK, что позволяет определить их значимость на различных стадиях кибератаки. Рассмотрены практические методы работы с логами. Приведен обзор современных инструментов, применяемых для анализа и обработки журналов событий.
Короткий адрес: https://sciup.org/149151798
IDS: 149151798 | УДК: 004.056 | DOI: 10.15688/NBIT.jvolsu.2025.3.3
The role of event logs in detecting and investigating incidents
This article analyzes the critical role of event logs in the detection and investigation of computer security incidents. In the context of a significant increase in cyberattacks on Russian businesses in 2025, including reconnaissance and data collection attacks, systematic logging has become an essential security component. The study provides a detailed classification of main log types: system, network, application, security/audit, and infrastructure device logs. Each category is examined in terms of recorded information, practical artifacts for investigations, and inherent challenges related to volume, format diversity, and collection complexities. A central focus is establishing the correlation between different event log types and various stages of a cyberattack as outlined in the MITRE ATT&CK framework. The analysis demonstrates how specific logs provide crucial indicators for tactics such as initial access, execution, lateral movement, and data exfiltration, enabling a comprehensive reconstruction of attack timelines. The article further reviews practical methodologies for effective log management, including centralized collection, normalization, filtration, correlation, and time-series analysis. Finally, the work presents an overview of modern tools that facilitate log analysis, such as SIEM systems (Splunk, ELK stack), centralized log management platforms (Graylog), EDR/XDR solutions, forensic utilities, and threat intelligence platforms. The conclusion emphasizes that a holistic approach integrating diverse log sources with advanced analytical tools is fundamental for effectively combating evolving cyber threats and conducting thorough incident investigations.