{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/108188"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/108188","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"On the forensic validity of approximated audit logs","abstract":"Auditing is an increasingly essential tool for the defense of computing systems, but the unwieldy nature of log data imposes tremendous burdens on administrators and analysts. To address this issue, a variety of techniques have been proposed for approximating the contents of raw audit logs, facilitating efficient storage and analysis. However, the security value of these approximated logs is difficult to measure - relative to the original log, it is unclear if these techniques retain the forensic evidence needed to effectively investigate threats. Unfortunately, prior work has only been able to investigate this issue anecdotally, demonstrating sufficient evidence is retained for specific attack scenarios. In this work, we address this gap in the literature through formalizing metrics for quantifying the forensic validity of an approximated audit log under differing threat models. In addition to providing quantifiable security arguments for prior work, we also identify a novel point in the approximation design space - that log events describing benign system activity can be aggressively approximated, while events that encode anomalous behavior should be preserved with lossless fidelity. We instantiate this notion of Attack-Preserving forensic validity in Approx, a new approximation technique that eliminates the redundancy of voluminous file I/O associated with benign process activities. We systematically evaluate Approx alongside a corpus of exemplar approximation techniques from prior work. We demonstrate that, while Approx enjoys comparable log reduction rates, it is able to retain 100% of attack-associated log events; in contrast, we make the surprising discovery that prior approaches for log approximation retain as little as 7.3% of forensic evidence under the Attack-Preserving metric. This work thus establishes trustworthy foundations for the design of the next generation of efficient auditing frameworks.","abstract_html":"Auditing is an increasingly essential tool for the defense of computing systems, but the unwieldy nature of log data imposes tremendous burdens on administrators and analysts. To address this issue, a variety of techniques have been proposed for approximating the contents of raw audit logs, facilitating efficient storage and analysis. However, the security value of these approximated logs is difficult to measure - relative to the original log, it is unclear if these techniques retain the forensic evidence needed to effectively investigate threats. Unfortunately, prior work has only been able to investigate this issue anecdotally, demonstrating sufficient evidence is retained for specific attack scenarios. In this work, we address this gap in the literature through formalizing metrics for quantifying the forensic validity of an approximated audit log under differing threat models. In addition to providing quantifiable security arguments for prior work, we also identify a novel point in the approximation design space - that log events describing benign system activity can be aggressively approximated, while events that encode anomalous behavior should be preserved with lossless fidelity. We instantiate this notion of Attack-Preserving forensic validity in Approx, a new approximation technique that eliminates the redundancy of voluminous file I/O associated with benign process activities. We systematically evaluate Approx alongside a corpus of exemplar approximation techniques from prior work. We demonstrate that, while Approx enjoys comparable log reduction rates, it is able to retain 100% of attack-associated log events; in contrast, we make the surprising discovery that prior approaches for log approximation retain as little as 7.3% of forensic evidence under the Attack-Preserving metric. This work thus establishes trustworthy foundations for the design of the next generation of efficient auditing frameworks.","abstract_has_math":false,"creators":["Michael, Noor Sultan"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Bates, Adam"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2020,"date_issued":"2020-08-26T23:58:48Z","date_published":"2020-08-26T23:58:48Z","updated_at":"2026-07-22T22:24:47Z","subjects":["Security","Privacy","Intrusion Detection Systems","Auditing","Data Provenance","Digital Forensics"],"languages":["en"],"rights":["Copyright 2020 Noor Michael"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/108188","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Bates, Adam"]},{"key":"dc:creator","label":"Author","values":["Michael, Noor Sultan"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2020-08-26T23:58:48Z","2022-08-26T23:58:55Z","2020-05-13","2020-05"]},{"key":"dc:type","label":"Dc Type","values":["text","Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Security","Privacy","Intrusion Detection Systems","Auditing","Data Provenance","Digital Forensics"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2020 Noor Michael"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/108188"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Auditing is an increasingly essential tool for the defense of computing systems, but the unwieldy nature of log data imposes tremendous burdens on administrators and analysts. To address this issue, a variety of techniques have been proposed for approximating the contents of raw audit logs, facilitating efficient storage and analysis. However, the security value of these approximated logs is difficult to measure - relative to the original log, it is unclear if these techniques retain the forensic evidence needed to effectively investigate threats. Unfortunately, prior work has only been able to investigate this issue anecdotally, demonstrating sufficient evidence is retained for specific attack scenarios. In this work, we address this gap in the literature through formalizing metrics for quantifying the forensic validity of an approximated audit log under differing threat models. In addition to providing quantifiable security arguments for prior work, we also identify a novel point in the approximation design space - that log events describing benign system activity can be aggressively approximated, while events that encode anomalous behavior should be preserved with lossless fidelity. We instantiate this notion of Attack-Preserving forensic validity in Approx, a new approximation technique that eliminates the redundancy of voluminous file I/O associated with benign process activities. We systematically evaluate Approx alongside a corpus of exemplar approximation techniques from prior work. We demonstrate that, while Approx enjoys comparable log reduction rates, it is able to retain 100% of attack-associated log events; in contrast, we make the surprising discovery that prior approaches for log approximation retain as little as 7.3% of forensic evidence under the Attack-Preserving metric. This work thus establishes trustworthy foundations for the design of the next generation of efficient auditing frameworks.","Submission published under a 24 month embargo labeled 'U of I Access', the embargo will last until 2022-05-01","The student, Noor Michael, accepted the attached license on 2020-05-12 at 12:15.","The student, Noor Michael, submitted this Thesis for approval on 2020-05-12 at 12:27.","This Thesis was approved for publication on 2020-05-13 at 08:30.","DSpace SAF Submission Ingestion Package generated from Vireo submission #15351 on 2020-08-25 at 17:31:12","Made available in DSpace on 2020-08-26T23:58:48Z (GMT). No. of bitstreams: 2 MICHAEL-THESIS-2020.pdf: 883036 bytes, checksum: ec348d5d9acf144aa4b85b7740a27fd0 (MD5) LICENSE.txt: 4209 bytes, checksum: 240cabeadb8849c2226cf92a030fe925 (MD5) Previous issue date: 2020-05-13","Embargo set by: Seth Robbins for item 115801 Lift date: 2022-08-26T23:58:55Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only"]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["On the forensic validity of approximated audit logs"]}]}],"canonical_facts":{"dc:contributor":["Bates, Adam"],"dc:creator":["Michael, Noor Sultan"],"dc:date":["2020-08-26T23:58:48Z","2022-08-26T23:58:55Z","2020-05-13","2020-05"],"dc:description":["Auditing is an increasingly essential tool for the defense of computing systems, but the unwieldy nature of log data imposes tremendous burdens on administrators and analysts. To address this issue, a variety of techniques have been proposed for approximating the contents of raw audit logs, facilitating efficient storage and analysis. However, the security value of these approximated logs is difficult to measure - relative to the original log, it is unclear if these techniques retain the forensic evidence needed to effectively investigate threats. Unfortunately, prior work has only been able to investigate this issue anecdotally, demonstrating sufficient evidence is retained for specific attack scenarios. In this work, we address this gap in the literature through formalizing metrics for quantifying the forensic validity of an approximated audit log under differing threat models. In addition to providing quantifiable security arguments for prior work, we also identify a novel point in the approximation design space - that log events describing benign system activity can be aggressively approximated, while events that encode anomalous behavior should be preserved with lossless fidelity. We instantiate this notion of Attack-Preserving forensic validity in Approx, a new approximation technique that eliminates the redundancy of voluminous file I/O associated with benign process activities. We systematically evaluate Approx alongside a corpus of exemplar approximation techniques from prior work. We demonstrate that, while Approx enjoys comparable log reduction rates, it is able to retain 100% of attack-associated log events; in contrast, we make the surprising discovery that prior approaches for log approximation retain as little as 7.3% of forensic evidence under the Attack-Preserving metric. This work thus establishes trustworthy foundations for the design of the next generation of efficient auditing frameworks.","Submission published under a 24 month embargo labeled 'U of I Access', the embargo will last until 2022-05-01","The student, Noor Michael, accepted the attached license on 2020-05-12 at 12:15.","The student, Noor Michael, submitted this Thesis for approval on 2020-05-12 at 12:27.","This Thesis was approved for publication on 2020-05-13 at 08:30.","DSpace SAF Submission Ingestion Package generated from Vireo submission #15351 on 2020-08-25 at 17:31:12","Made available in DSpace on 2020-08-26T23:58:48Z (GMT). No. of bitstreams: 2 MICHAEL-THESIS-2020.pdf: 883036 bytes, checksum: ec348d5d9acf144aa4b85b7740a27fd0 (MD5) LICENSE.txt: 4209 bytes, checksum: 240cabeadb8849c2226cf92a030fe925 (MD5) Previous issue date: 2020-05-13","Embargo set by: Seth Robbins for item 115801 Lift date: 2022-08-26T23:58:55Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only"],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/2142/108188"],"dc:language":["en"],"dc:rights":["Copyright 2020 Noor Michael"],"dc:subject":["Security","Privacy","Intrusion Detection Systems","Auditing","Data Provenance","Digital Forensics"],"dc:title":["On the forensic validity of approximated audit logs"],"dc:type":["text","Thesis"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:47Z"}