BETA Shoulder jest w wersji beta — Wyniki mogą czasami być błędne. Twoja opinia kształtuje to, co naprawimy w następnej kolejności. Podziel się opinią
#9 A09:2025

Security Logging and Alerting Failures

This category helps detect, escalate, and respond to active breaches. Without logging and alerting, breaches cannot be detected in time to respond.

Przeglad

Renamed from 'Security Logging and Monitoring Failures' to emphasize actionable alerts over mere monitoring. This category is challenging to test for and isn't well represented in CVE/CVSS data.

Jak Atakujacy To Wykorzystuja

Zrozumienie wzorcow atakow pomaga budowac lepsze zabezpieczenia. To sa techniki, ktore zespoly bezpieczenstwa monitoruja.

Undetected breach

Without proper logging and alerting, attackers can operate undetected for extended periods, exfiltrating data gradually.

Sygnal wykrywania: This is the problem - without alerting, there IS no indicator until it's too late

Log tampering

Attackers with access modify or delete logs to cover their tracks.

Sygnal wykrywania: Gaps in log sequences, modified timestamps, missing entries

Alert fatigue exploitation

Attackers generate noise to cause alert fatigue, then conduct real attacks during the confusion.

Sygnal wykrywania: Spike in low-severity alerts followed by suspicious activity

Jak Zapobiegac

  • Log all login, access control, and server-side input validation failures
  • Ensure logs are in a format easily consumed by log management solutions
  • Ensure log data is encoded correctly to prevent injection attacks
  • Ensure high-value transactions have an audit trail with integrity controls
  • Establish effective alerting with actionable thresholds
  • Establish an incident response and recovery plan
  • Use SIEM or centralized logging with real-time alerting

CWE z Wykrywaniem Shoulder (3)

Te CWE maja reguly wykrywania Shoulder. Kliknij, aby zobaczyc konkretne podatnosci i poprawki.

Inne Zmapowane CWE (2)

Te CWE sa zmapowane do tej kategorii, ale nie maja jeszcze regul Shoulder.