ベータ Shoulder はベータ版です — 結果が誤っている場合があります。皆さまのフィードバックが次に修正する内容を決定します。 フィードバックを送る
#9 A09:2025

Security Logging and Alerting Failures

This category helps detect, escalate, and respond to active breaches. Without logging and alerting, breaches cannot be detected in time to respond.

概要

Renamed from 'Security Logging and Monitoring Failures' to emphasize actionable alerts over mere monitoring. This category is challenging to test for and isn't well represented in CVE/CVSS data.

攻撃者がこれを悪用する方法

攻撃パターンを理解することで、より優れた防御を構築できます。これらはセキュリティチームが監視する技術です。

Undetected breach

Without proper logging and alerting, attackers can operate undetected for extended periods, exfiltrating data gradually.

検出シグナル: This is the problem - without alerting, there IS no indicator until it's too late

Log tampering

Attackers with access modify or delete logs to cover their tracks.

検出シグナル: Gaps in log sequences, modified timestamps, missing entries

Alert fatigue exploitation

Attackers generate noise to cause alert fatigue, then conduct real attacks during the confusion.

検出シグナル: Spike in low-severity alerts followed by suspicious activity

予防方法

  • Log all login, access control, and server-side input validation failures
  • Ensure logs are in a format easily consumed by log management solutions
  • Ensure log data is encoded correctly to prevent injection attacks
  • Ensure high-value transactions have an audit trail with integrity controls
  • Establish effective alerting with actionable thresholds
  • Establish an incident response and recovery plan
  • Use SIEM or centralized logging with real-time alerting

Shoulder検出付きCWE (3)

これらのCWEにはShoulder検出ルールがあります。クリックして特定の脆弱性と修正を確認してください。

その他のマップされたCWE (2)

これらのCWEはこのカテゴリにマップされていますが、まだShoulderルールがありません。