Article

Monitoring Authorized User Activities: The Importance of a Sound Forensic Audit Trail

Jan 01, 0001

According to a recent study on Insider Threat conducted by the Ponemon Institute, organizations suffer an average of more than 52 incidents of insider fraud annually. Traditional security controls, such as application logging, are often powerless in these situations.

July 2012 

Sponsored by Attachmate Luminet®

attachmate-logo.jpg According to a recent study on Insider Threat conducted by the Ponemon Institute, organizations suffer an average of more than 52 incidents of insider fraud annually. Traditional security controls, such as application logging, are often powerless in these situations. When malicious insiders with legitimate reasons for accessing applications, querying databases, and changing system configurations alter, destroy or obfuscate records, institutions are often left powerless to determine what actually happened. As a result, a detailed audit trail of user access to sensitive corporate data has become a necessity for protecting your corporate brand and information assets. It is also required by an increasing number of government regulations and especially privacy regulations. 

While many organizations maintain access logs most are insufficient due to the following 3 limitations:
 

  1. The logs are missing record and field-level data, and focus solely on a given transaction.  

    The reality is that most existing logs only contain information at the transaction level, such as: Which users accessed which transaction at what time? In these cases, critical information is still missing. Vital questions such as “Which specific records and fields did the user access?’ and “What did the user do with the data?” go unanswered. 

     

  2. Main existing systems fail to log read-only actions, leaving gaps in the records. 

    Most existing logs only record update activities. This leaves critical information about what was viewed, queried or simply accessed out of audit trail entirely. In these cases, there is often no record of the times information was accessed without being changed. This information is extremely important for preventing and investigating information leakage and data theft. Another area where this absence of information reveals significant gaps is in demonstrating access to private or privileged information. 

  3.  

  4. If available, logs represent an incomplete view of activities that is often “hidden” across multiple systems and difficult to correlate.  

    The reality is that many logs are maintained in disparate systems or applications that don’t “talk” to each other. This makes it difficult to find and correlate relevant information—or respond quickly to an audit request. This reality often aids the malicious insider in obscuring their activity.

     

    Legacy systems that were developed a decade or two ago and even many newer systems were not designed for collecting detailed data access logs. Altering logging capabilities or introducing a logging mechanism to these applications frequently required the addition of a logging component to each online program. In a large enterprise, this can add up to tens of thousands of lines of code. An activity of this type can easily translate into hundreds of programmer-months, system performance overhead and additional maintenance. With all the additional time, money and effort such an activity would require, the costs of upgrading a traditional logging system to support modern audit needs with a detailed audit trail quickly becomes exorbitant.

 

What if you could: 

Stop scrambling to piece together incomplete data on scattered enterprise systems in order to create a complete audit trail?

Know for certain whether your standard operating procedures are being followed?

Gather clear and legally actionable forensic evidence—even weeks or months after the user activity occurred?


With the next generation fraud and misuse management software, like Luminet from Attachmate, you can do all that and more—without adding controls or changing a single line of code. 
 
In addition, modern day fraud management solutions with continuous monitoring and behavioral analytics provide other distinct advantages when it comes to monitoring user and system activity for fraud:
 
  1. With the behavioral analytic and real time cross-channel data correlation capabilities within modern day fraud solutions, the user’s identity can be established via a layered credential that takes the ability to demonstrate that a particular user was acting on a system far beyond simple user ID and password.
  2.  
  3. The evidentiary chain of information within the solution is preserved in a way that is protected, encrypted and tamper-evident. All of these protections make data collected during investigations more secure and better able to support prosecution.
  4.  
  5. The unique capabilities of these new tools also help to make the evidence within the data record tamper-evident. Fraudsters typically take steps to hide their attack. With these tools in place, even those efforts to erase those “footprints” in the data record are captured.
  6.  
  7. Configurable business rules track user behavior patterns generating real-time alerts to exceptions. Once alerted, internal auditors can immediately zoom in on specific suspects and replay their actions. When Luminet is integrated within an operational system, an alert can even initiate a “suspend user” action in that system.
 
These solutions help you implement business rules that can be utilized for identifying specific business events and generating configurable logs of these specific events. For example, a business rule can be configured to identify the process of updating credit limit and generate a table in the appropriate relational database with selected attributes of update credit limit actions that exceed a specific threshold. Consider how meaningful that could be in stopping fraud in its tracks.

 

 


 

 

Luminet from Attachmate solves these problems and other out-of-the-box without changing any application code and with no overhead on the existing systems or network. By recording and analyzing user activity on the application level, Luminet generates a very detailed audit trail of user access to the corporate applications and data. This audit trail is invaluable for both real-time and post-event investigations. It enables the internal auditor to search, for example, for all the users who accessed a specific account number in a specific timeframe across any application across any platform in the enterprise. The auditor can zoom in on any user session retrieved by the query and replay the user’s actions screen by screen, keystroke by keystroke.

 

Attachmate offers a product demonstration as the first step in the evaluation of Luminet software. To see how the next generation fraud technology can revolutionize your fraud and audit efforts, click here to contact us. If you would prefer, feel free to call us directly at 1.800.872.2829 and ask for a demonstration today.