#9
A09:2025
Security Logging and Alerting Failures
This category helps detect, escalate, and respond to active breaches. Without logging and alerting, breaches cannot be detected in time to respond.
概述
Renamed from 'Security Logging and Monitoring Failures' to emphasize actionable alerts over mere monitoring. This category is challenging to test for and isn't well represented in CVE/CVSS data.
攻击者如何利用此漏洞
理解攻击模式有助于您构建更好的防御。这些是安全团队监控的技术。
Undetected breach
Without proper logging and alerting, attackers can operate undetected for extended periods, exfiltrating data gradually.
检测信号:
This is the problem - without alerting, there IS no indicator until it's too late
Log tampering
Attackers with access modify or delete logs to cover their tracks.
检测信号:
Gaps in log sequences, modified timestamps, missing entries
Alert fatigue exploitation
Attackers generate noise to cause alert fatigue, then conduct real attacks during the confusion.
检测信号:
Spike in low-severity alerts followed by suspicious activity
如何预防
- Log all login, access control, and server-side input validation failures
- Ensure logs are in a format easily consumed by log management solutions
- Ensure log data is encoded correctly to prevent injection attacks
- Ensure high-value transactions have an audit trail with integrity controls
- Establish effective alerting with actionable thresholds
- Establish an incident response and recovery plan
- Use SIEM or centralized logging with real-time alerting
有Shoulder检测的CWE (3)
这些CWE有Shoulder检测规则。点击查看具体漏洞和修复方法。
其他映射的CWE (2)
这些CWE映射到此类别,但尚无Shoulder规则。