Registration and audit. The structure of automated control of computer facilities

Automatic accounting is the cornerstone of computer technology management. This means that computers must automatically determine their basic characteristics, and in accordance with certain regulations, transfer them to the database. On the basis of automatic audit data, information about the company and employees, a storage of information about computing equipment (SVT storage) is formed. It is advisable to consider the SVT repository as an integral part of the enterprise's unified information repository.

Using the SVT storage, various structural divisions of the enterprise (accounting, economists, IT department) can analyze, plan and predict the performance of computing equipment. The analytical work of these departments should be organized in such a way that, on the one hand, the departments can perform the control functions assigned to them, and on the other hand, prepare up-to-date summary information for management.

Monitoring analytic reports at various levels of detail should not be limited to viewing paper reports. An effective form of presenting operational data is an interactive information board, on which information about the operation of computing equipment is graphically presented in the form of tables, graphs and on various diagrams (organizational structure of an enterprise, production process, etc.).

Based on the current summary information presented in various sections, the management can make informed and informed decisions on the computerization of their enterprise.

Automatic accounting of computer equipment

Automatic accounting of computer equipment consists in diagnostics, collection and storage of information about the characteristics of computers and peripherals.

Diagnostics (audit) of computer characteristics

Diagnostics is carried out by an auditor program that runs on the user's computer and acts as a personal electronic agent for computer technology. The auditor agent can be launched:

In the domain - when registering a user

· In a workgroup — when the operating system is loaded.

The launch of the auditor agent on the user's machines must be ensured by the administrators of the enterprise information system. Depending on its configuration, the auditor agent can be constantly launched on the user's machine, or unloaded after the audit. Detailed recommendations for administrators are provided in the Administrators Guide.

The characteristics of computing technology can be roughly divided

by the way they are diagnosed:

· Automatic (the amount of RAM, the type and frequency of the processor, the amount of hard drives, the presence and type of CD-ROM, etc.). Automatically determined by the agent-auditor.

· Custom (location, username and mailing address, possible malfunctions). They are entered by the user at the first start of the agent-auditor (location) or at the initiative of the user (malfunctions in the operation of computers and peripherals).

for the object being characterized

Processor specifications

Motherboard specifications

RAM characteristics

External storage characteristics

Graphics card specifications

Sound card specifications

Network characteristics

User characteristics

Location characteristics

· Errors and malfunctions.


4.4.2. Definition and content of registration and audit of information systems

Registration is another mechanism for ensuring the security of the information system. This mechanism is based on the accountability of the security management system, records all security-related events, such as:

  • entry and exit of access subjects;

  • starting and ending programs;

  • issuance of printed documents;

  • attempts to access protected resources;

  • changing the powers of access subjects;

  • changing the status of access objects, etc.

The effectiveness of the security system is fundamentally increased if the registration mechanism is supplemented with an audit mechanism. This allows you to quickly identify violations, identify weaknesses in the protection system, analyze the patterns of the system, evaluate the work of users, etc.

Audit Is an analysis of the accumulated information, carried out promptly in real time or periodically (for example, once a day). An operational audit with an automatic response to identified abnormal situations is called active.

The implementation of registration and audit mechanisms makes it possible to solve the following tasks of ensuring information security:

  • keeping users and administrators accountable;

  • providing the ability to reconstruct the sequence of events;

  • detection of attempts to breach information security;

  • providing information to identify and analyze problems.
The considered registration and audit mechanisms are a powerful psychological tool reminding potential violators of the inevitability of punishment for unauthorized actions, and users - for possible critical errors.

The practical means of registration and auditing are:

  • various system utilities and application programs;

  • registration (system or audit) journal.
The first tool is usually in addition to monitoring by the system administrator. A comprehensive approach to logging and auditing is provided using a log book.

^ Log

A fragment of the security log of the operating system registration and audit subsystem is shown in rice. 4.4.1.

Figure 4.4.1.

Detection of attempts at information security breaches is part of the active audit function, whose tasks are to promptly identify suspicious activity and provide tools for an automatic response to it.

Under suspicious activity means the behavior of a user or a component of an information system that is malicious (in accordance with a predetermined security policy) or atypical (in accordance with accepted criteria).

For example, the audit subsystem, monitoring the user login (registration) procedure, counts the number of unsuccessful login attempts. If the set threshold for such attempts is exceeded, the audit subsystem generates a signal that the account of this user is blocked.

4.4.3. Registration stages and methods of auditing information system events

The organization of registration of events related to the security of the information system includes at least three stages:

  1. Collection and storage of information about events.

  2. Protecting the contents of the logbook.

  3. Analysis of the contents of the logbook.
At the first stage, the data to be collected and stored, the period for cleaning and archiving the journal, the degree of centralization of management, the place and means of storing the journal, the possibility of registering encrypted information, etc. are determined.

The registered data must be protected, first of all, from unauthorized modification and, possibly, disclosure.

The most important step is the analysis of registration information. There are several methods for analyzing information in order to identify unauthorized actions.

^ Statistical Methods are based on the accumulation of the average parameters of the functioning of subsystems and the comparison of the current parameters with them. The presence of certain deviations can signal the possibility of some threats.

^ Heuristic methods use models of scenarios of unauthorized actions, which are described by logical rules or models of actions, which together lead to unauthorized actions.

4.4.4. Conclusions on the topic

  1. The effectiveness of the security system is fundamentally increased if the registration mechanism is supplemented with an audit mechanism. This allows you to quickly identify violations, identify weaknesses in the protection system, analyze the patterns of the system, and evaluate the work of users.

  2. The registration mechanism is based on the accountability of the security system, records all events related to security.

  3. Auditing system events Is an analysis of the accumulated information, carried out promptly in real time or periodically (for example, once a day).

  4. Registration and audit mechanisms are a powerful psychological tool that reminds potential violators of the inevitability of punishment for unauthorized actions, and users - for possible critical errors.

  5. ^ Log Is a chronologically ordered set of records of the results of the activities of the subjects of the system, sufficient to restore, view and analyze the sequence of actions surrounding or leading to the execution of operations, procedures or events during a transaction in order to control the final result.

  6. Registration of events related to the security of an information system includes at least three stages: collection and storage of information about events, protection of the contents of the logbook, and analysis of the contents of the logbook.

  7. Audit methods can be statistical and heuristic.

  8. For information systems certified for security, the list of controlled events is determined by the working document of the State Technical Commission of the Russian Federation: "Regulations on the certification of computer technology and communications equipment and systems in accordance with information security requirements."

4.4.5. Questions for self-control

  1. What is the registration mechanism based on?

  2. What security events are logged?

  3. How are registration and audit mechanisms different?

  4. Give the definition of an audit of information system events.

  5. What is related to the means of registration and audit?

  6. What is a log book? Its shape.

  7. What is suspicious activity?

  8. What are the steps involved in registration and audit mechanisms?

  9. Describe the well-known methods of auditing the security of information systems.

4.4.6. Links to additional materials (printed and electronic resources)


  1. Galatenko V.A.Fundamentals of information security. - M: Internet University

