{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,20]],"date-time":"2026-02-20T08:35:10Z","timestamp":1771576510624,"version":"3.50.1"},"reference-count":81,"publisher":"Wiley","issue":"17","license":[{"start":{"date-parts":[[2016,10,20]],"date-time":"2016-10-20T00:00:00Z","timestamp":1476921600000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/onlinelibrary.wiley.com\/termsAndConditions#vor"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Security Comm Networks"],"published-print":{"date-parts":[[2016,11,25]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Logging has become a fundamental feature within the modern computer operating systems because of the fact that logging may be used through a variety of applications and fashion, such as system tuning, auditing, and intrusion detection systems. Syslog daemon is the logging implementation in Unix\/Linux platforms, while Windows Event Log is the logging implementation in Microsoft Windows platforms. These logging implementations provide application program interfaces that, in turn, simplify logging functions from data collection to data storage. In this paper, we survey Unix, Linux, and Windows logging mechanisms and introduce their security issues. Copyright \u00a9 2016 John Wiley &amp; Sons, Ltd.<\/jats:p>","DOI":"10.1002\/sec.1677","type":"journal-article","created":{"date-parts":[[2016,10,21]],"date-time":"2016-10-21T02:49:00Z","timestamp":1477018140000},"page":"4804-4821","source":"Crossref","is-referenced-by-count":17,"title":["Computer operating system logging and security issues: a survey"],"prefix":"10.1002","volume":"9","author":[{"given":"Lei","family":"Zeng","sequence":"first","affiliation":[{"name":"Department of Computer Science The University of Alabama Tuscaloosa AL 35487\u20100920 U.S.A."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yang","family":"Xiao","sequence":"additional","affiliation":[{"name":"School of Computer and Software Nanjing University of Information Science and Technology Nanjing 210044 China"},{"name":"Department of Computer Science The University of Alabama Tuscaloosa AL 35487\u20100920 U.S.A."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hui","family":"Chen","sequence":"additional","affiliation":[{"name":"Department of Mathematics and Computer Science Virginia State University Petersburg VA 23806 U.S.A."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bo","family":"Sun","sequence":"additional","affiliation":[{"name":"Department of Computer Science Lamar University Beaumont TX 77710 U.S.A."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wenlin","family":"Han","sequence":"additional","affiliation":[{"name":"Department of Computer Science The University of Alabama Tuscaloosa AL 35487\u20100920 U.S.A."}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"311","published-online":{"date-parts":[[2016,10,20]]},"reference":[{"key":"e_1_2_7_2_1","unstructured":"\u201cPayment Card Industry (PCI) Data Security Standard\u2014Requirements and Security Assessment Procedures version 2.0 \u201dn.d. Available:https:\/\/www.pcisecuritystandards.org\/documents\/pci_dss_v2.pdf"},{"key":"e_1_2_7_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2010.031810.00083"},{"key":"e_1_2_7_4_1","unstructured":"Federal Information Security Management Act of 2002\u2014Wikipedia n.d Available:http:\/\/en.wikipedia.org\/wiki\/FISMA"},{"key":"e_1_2_7_5_1","unstructured":"Wikipedia n.d. Available:http:\/\/en.wikipedia.org\/wiki\/Health_Insurance_Portability_and_Accountability_Act"},{"key":"e_1_2_7_6_1","unstructured":"ISO\/IEC 27001\u2014Wikipedia the free encyclopedia n.d. Available:https:\/\/en.wikipedia.org\/wiki\/ISO\/IEC_27001:2013"},{"key":"e_1_2_7_7_1","unstructured":"COBIT\u2014Wikipedia n.d. Available:http:\/\/en.wikipedia.org\/wiki\/Cobit"},{"key":"e_1_2_7_8_1","unstructured":"Information Technology Infrastructure Library\u2014Wikipedia n.d. Available:http:\/\/en.wikipedia.org\/wiki\/Information_Technology_Infrastructure_Library"},{"key":"e_1_2_7_9_1","unstructured":"Security\u2010evaluated operating system\u2014Wikipedia n.d. Available:http:\/\/en.wikipedia.org\/wiki\/Security\u2010evaluated_operating_system"},{"key":"e_1_2_7_10_1","unstructured":"Evaluation Assurance Level n.d.https:\/\/en.wikipedia.org\/wiki\/Evaluation_Assurance_Level"},{"key":"e_1_2_7_11_1","unstructured":"Information Systems Security Organization 1999"},{"key":"e_1_2_7_12_1","unstructured":"Role\u2010based access control\u2014Wikipedia n.d. Available:http:\/\/en.wikipedia.org\/wiki\/RBAC"},{"key":"e_1_2_7_13_1","unstructured":"National Industrial Security Program\u2014Wikipedia n.d. Available:http:\/\/en.wikipedia.org\/wiki\/NISPOM"},{"key":"e_1_2_7_14_1","unstructured":"Sensitive Compartmented Information Facility\u2014Wikipedia n.d. Available:http:\/\/en.wikipedia.org\/wiki\/Sensitive_Compartmented_Information_Facility"},{"key":"e_1_2_7_15_1","unstructured":"SANS Consensus Project Information System Audit Logging Requirements n.d. SANS institute 2007."},{"key":"e_1_2_7_16_1","doi-asserted-by":"publisher","DOI":"10.1002\/sec.10"},{"key":"e_1_2_7_17_1","doi-asserted-by":"publisher","DOI":"10.1504\/IJSNET.2009.028022"},{"issue":"2","key":"e_1_2_7_18_1","first-page":"317","article-title":"Mutual verifiable provable data auditing in public cloud storage","volume":"16","author":"Ren Y","year":"2015","journal-title":"Journal of Internet Technology"},{"key":"e_1_2_7_19_1","doi-asserted-by":"publisher","DOI":"10.1002\/sec.374"},{"key":"e_1_2_7_20_1","first-page":"10","article-title":"Linux in education: integrating a Linux cluster into a production high performance computing environment","volume":"87","author":"Degen H","year":"2001","journal-title":"Linux Journal"},{"key":"e_1_2_7_21_1","doi-asserted-by":"crossref","unstructured":"ZawawyH. KontogiannisK. andMylopoulosJ. Log filtering and interpretation for root cause analysis 2010IEEE International Conference Software Maintenance (ICSM).","DOI":"10.1109\/ICSM.2010.5609556"},{"key":"e_1_2_7_22_1","doi-asserted-by":"publisher","DOI":"10.1504\/IJSN.2013.057699"},{"key":"e_1_2_7_23_1","unstructured":"GunasekaranR. DillowD.A. ShipmanG. M. MaxwellD. andHillJ. J.Correlating log messages for system diagnostics n.d. Available:http:\/\/info.ornl.gov\/sites\/publications\/files\/Pub24270.pdf"},{"key":"e_1_2_7_24_1","doi-asserted-by":"crossref","unstructured":"BhansaliS. ChenW. JongS. EdwardsA. MurrayR. DrinicM. MihockaD. andChauJ. Framework for instruction\u2010level tracing and analysis of program execution Proceedings of the 2ndInternational Conference on Virtual Execution Environments pp. 154\u2010163 2006.","DOI":"10.1145\/1134760.1220164"},{"key":"e_1_2_7_25_1","unstructured":"Debugging\u2014Wikipedia n.d. available:http:\/\/en.wikipedia.org\/wiki\/Debugging"},{"key":"e_1_2_7_26_1","doi-asserted-by":"crossref","unstructured":"AyersA. SchoolerR. MetcalfC. AgarwalA. RheeJ. andWitchelE. TraceBack: first fault diagnosis by reconstruction of distributed control flow Programming Language Design and Implementation (PLDI '05) (2005) 201\u201312.","DOI":"10.1145\/1065010.1065035"},{"key":"e_1_2_7_27_1","doi-asserted-by":"crossref","unstructured":"NethercoteN.andSewardJ. Valgrind: a program supervision framework Electronic Notes in Theoretical Computer Science 89(2003) 2.","DOI":"10.1016\/S1571-0661(04)81042-9"},{"key":"e_1_2_7_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/1089008.1089012"},{"key":"e_1_2_7_29_1","unstructured":"US Department of Defense Department of Defense Trusted Computer System Evaluation Criteria DoD 5200.28\u2010STD Library S225 722 December1985."},{"key":"e_1_2_7_30_1","unstructured":"The International Standard Organization Common Criteria for Information Technology Security Evaluation (CC) Version 3.1 September2006 see:http:\/\/www.commoncriteriaportal.org\/public\/consumer\/index.php?menu=2"},{"key":"e_1_2_7_31_1","doi-asserted-by":"crossref","unstructured":"XiaoY. Flow\u2010Net Methodology for Accountability in Wireless Networks IEEE Network Vol. 23 5 Sept.\/Oct.2009 30\u201037.","DOI":"10.1109\/MNET.2009.5274919"},{"key":"e_1_2_7_32_1","doi-asserted-by":"crossref","unstructured":"SallachD.L. A deductive database audit trail Proceedings of the 1922 ACM\/SIGAPP Symposium on Applied Computing: Technological Challenges of 1990s pp. 314\u2013319 1990.","DOI":"10.1145\/143559.150704"},{"key":"e_1_2_7_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/1047915.1047918"},{"key":"e_1_2_7_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/1368506.1368511"},{"key":"e_1_2_7_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/CC.2016.7559076"},{"key":"e_1_2_7_36_1","doi-asserted-by":"publisher","DOI":"10.1002\/dac.853"},{"key":"e_1_2_7_37_1","doi-asserted-by":"crossref","unstructured":"SunB. OsborneL. XiaoY. andGuizaniS. Intrusion detection techniques in mobile ad hoc and wireless sensor networks IEEE Wireless Communications Magazine Oct.2007 56\u201063.","DOI":"10.1109\/MWC.2007.4396943"},{"key":"e_1_2_7_38_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11277-014-1604-7"},{"key":"e_1_2_7_39_1","doi-asserted-by":"crossref","unstructured":"ZhouZ. WangY. WuQ.M. J. YangC. SunX. Effective and efficient global context verification for image copy detection IEEE Transactions on Information Forensics and Security DOI:10.1109\/TIFS.2016.2601065 2016.","DOI":"10.1109\/TIFS.2016.2601065"},{"key":"e_1_2_7_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2014.2381872"},{"key":"e_1_2_7_41_1","doi-asserted-by":"publisher","DOI":"10.1504\/IJSN.2016.075074"},{"key":"e_1_2_7_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.2008.4481350"},{"key":"e_1_2_7_43_1","doi-asserted-by":"crossref","unstructured":"ChouB.andTataraK. A secure virtualized logging scheme for digital forensics in comparison with kernel module approach 2008International Conference on Information Security and Assurance.","DOI":"10.1109\/ISA.2008.96"},{"key":"e_1_2_7_44_1","unstructured":"ZengL. ChenH. andXiaoY. Accountable administration and implementation in operating systems IEEE GLOBECOM2011."},{"key":"e_1_2_7_45_1","unstructured":"ZengL. ChenH. andXiaoY. Accountable administration in operating systems International Journal of Information and Computer Security accepted 2016."},{"key":"e_1_2_7_46_1","unstructured":"ChuvakinA. IT data management and monitoring for ISO27000 family of standards n.d. Available:http:\/\/www.loglogic.com\/iso27000."},{"key":"e_1_2_7_47_1","unstructured":"ISO\u201027001 n.d.http:\/\/searchsecurity.techtarget.co.uk\/definition\/ISO\u201027001"},{"key":"e_1_2_7_48_1","unstructured":"ISO27002 n.d. Available http:\/\/www.27000.org\/iso\u201027002.htm."},{"key":"e_1_2_7_49_1","unstructured":"KentK.andSouppayaM. Guide to computer security log management National Institute of Standards and Technology 2006."},{"key":"e_1_2_7_50_1","unstructured":"TurnbullJ. Linux Chapter 9 Understanding Logging and Log Monitoring Apress 2005."},{"key":"e_1_2_7_51_1","unstructured":"ForteD. V. MarutiC. VetturiM. R.andZambilliM. SecSyslog: an approach to secure logging based on covert channels Proceedings of the First International Workshop on Systematic Approaches to Digital Forensic Engineering (SADFEf05) 2005."},{"key":"e_1_2_7_52_1","unstructured":"Syslog\u2014Wikipedia n.d. available:http:\/\/en.wikipedia.org\/wiki\/Syslog."},{"key":"e_1_2_7_53_1","unstructured":"Introduction to Syslog Protocol n.d. available:http:\/\/www.monitorware.com\/common\/en\/articles\/syslog\u2010described.php."},{"key":"e_1_2_7_54_1","unstructured":"BauerM. syslog configuration Linux Journal Dec2001 http:\/\/www.linuxjournal.com\/article\/5476"},{"key":"e_1_2_7_55_1","unstructured":"RFC 5424\u2014The Syslog Protocol n.d. available:http:\/\/tools.ietf.org\/html\/rfc5424#page\u20108."},{"key":"e_1_2_7_56_1","volume-title":"Understanding the Linux Kernel","author":"Bovet DP","year":"2001"},{"key":"e_1_2_7_57_1","unstructured":"syslog\u2010ng\u2014multiplatform syslog server and logging daemon n.d.http:\/\/www.balabit.com\/network\u2010security\/syslog\u2010ng"},{"key":"e_1_2_7_58_1","unstructured":"Balabit technical report. n.d. Available:https:\/\/www.balabit.com\/network\u2010security\/syslog\u2010ng\/opensource\u2010logging\u2010system\/features\/comparison"},{"key":"e_1_2_7_59_1","unstructured":"rsyslog. n.d. Available:http:\/\/www.rsyslog.com\/"},{"key":"e_1_2_7_60_1","unstructured":"sysdig. n.d. Available:http:\/\/www.sysdig.org\/"},{"key":"e_1_2_7_61_1","unstructured":"Nagios. n.d. Available:www.nagios.org"},{"key":"e_1_2_7_62_1","unstructured":"Graylog. n.d. Available:www.graylog.org"},{"key":"e_1_2_7_63_1","unstructured":"KLogView. n.d. Available: klogview.sourceforge.net"},{"key":"e_1_2_7_64_1","unstructured":"OSSEC. n.d. Available: ossec.github.io"},{"key":"e_1_2_7_65_1","unstructured":"fail2ban. n.d. Available:http:\/\/www.fail2ban.org\/"},{"key":"e_1_2_7_66_1","unstructured":"Redhat Inc Linux auditing discussion available:http:\/\/www.redhat.com\/mailman\/listinfo\/linux\u2010audit Sep 28 2007."},{"key":"e_1_2_7_67_1","unstructured":"SUSE Linux AG Linux audit\u2010subsystem design documentation for kernel 2.6 version 0.1 SUSE Linux AG and Novell Inc 2004 available: http:\/\/\/www.uniforum.chi.il.us\/slides\/HardeningLinux\/LAuS\u2010Design.pdf Sep 28 2007."},{"key":"e_1_2_7_68_1","volume-title":"Linux Kernel Development","author":"Love R","year":"2005"},{"key":"e_1_2_7_69_1","unstructured":"The EVTX log format and its radical impact on existing compliance strategies 2007. Doriansoftware."},{"key":"e_1_2_7_70_1","unstructured":"CharterB. SANS Institute InfoSec Reading Room\u2014EVTX and Windows Event Logging 2008. SANS Institute. Available:http:\/\/www.sans.org\/reading\u2010room\/whitepapers\/logging\/evtx\u2010windows\u2010event\u2010logging\u201032949"},{"key":"e_1_2_7_71_1","unstructured":"Event properties. Retrieved July 29 2011 from Microsoft Web site:http:\/\/technet.microsoft.com\/en\u2010us\/library\/cc765981.aspx."},{"key":"e_1_2_7_72_1","unstructured":"Event logs and channels in windows event log. n.d. from Microsoft Web site:http:\/\/msdn.microsoft.com\/enus\/library\/aa385225.aspx."},{"key":"e_1_2_7_73_1","unstructured":"Event viewer\u2014Wikipedia n.d. available:http:\/\/en.wikipedia.org\/wiki\/Event_Viewer."},{"key":"e_1_2_7_74_1","unstructured":"MennV. (2006 November).Windows Vista: new tools for event management in Windows Vista. TechNet Magazine. from Microsoft Web site:http:\/\/technet.microsoft.com\/en\u2010us\/magazine\/cc160886.aspx."},{"key":"e_1_2_7_75_1","unstructured":"Authentication for Remote Connections. fn.d. rom Microsoft Web site:http:\/\/msdn.microsoft.com\/en\u2010us\/library\/aa384295(VS.85).aspx."},{"key":"e_1_2_7_76_1","unstructured":"EventTracker. n.d. Available:http:\/\/www.eventtracker.com\/"},{"key":"e_1_2_7_77_1","unstructured":"splunk. n.d. Available:http:\/\/www.splunk.com\/"},{"key":"e_1_2_7_78_1","unstructured":"ADAudit Plus. n.d. Available:https:\/\/www.manageengine.com"},{"key":"e_1_2_7_79_1","unstructured":"LOGalyze. n.d. Available:http:\/\/www.logalyze.com\/"},{"key":"e_1_2_7_80_1","unstructured":"Microsoft Log Parser. n.d. Available:https:\/\/technet.microsoft.com\/en\u2010us\/scriptcenter\/dd919274.aspx"},{"key":"e_1_2_7_81_1","unstructured":"Project Lasso. n.d. Available:http:\/\/sourceforge.net\/projects\/lassolog\/"},{"key":"e_1_2_7_82_1","unstructured":"ShenkJ. SANS Sixth Annual Log Management Survey Report April2010 A SANS Whitepaper."}],"container-title":["Security and Communication Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.wiley.com\/onlinelibrary\/tdm\/v1\/articles\/10.1002%2Fsec.1677","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.wiley.com\/onlinelibrary\/tdm\/v1\/articles\/10.1002%2Fsec.1677","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/onlinelibrary.wiley.com\/doi\/pdf\/10.1002\/sec.1677","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,11]],"date-time":"2025-06-11T18:54:36Z","timestamp":1749668076000},"score":1,"resource":{"primary":{"URL":"https:\/\/onlinelibrary.wiley.com\/doi\/10.1002\/sec.1677"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,10,20]]},"references-count":81,"journal-issue":{"issue":"17","published-print":{"date-parts":[[2016,11,25]]}},"alternative-id":["10.1002\/sec.1677"],"URL":"https:\/\/doi.org\/10.1002\/sec.1677","archive":["Portico"],"relation":{},"ISSN":["1939-0114","1939-0122"],"issn-type":[{"value":"1939-0114","type":"print"},{"value":"1939-0122","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,10,20]]}}}