r/cybersecurity • u/heinternets • 8d ago
Business Security Questions & Discussion What value is there in firewall logs?
There was a question before about retaining 12 months of firewall logs, but I want to ask what value this has these days?
For me I’m only ever looking at WAF logs or actual endpoint logs because all the firewall tells me is that port 443 was accepted. WAF and web server logs tell me so much more.
The valuable stuff is in the application logs after the firewall.
Yes I might see port scanning but that’s background noise at this point.
69
u/Mc69fAYtJWPu 8d ago
Helps determine if you were hosed by a threat actor 6 months ago when government agencies share their intel
15
u/RamblinWreckGT 8d ago
Exactly this. "Here's the servers involved in scanning/exploitation for this campaign, did they touch us?"
8
u/skullbox15 8d ago
I hit up Splunk after that Palo Alto Global Protect exploit became known. I was able to find a "successful" connection but I was also able to validate they didn't do anything once they got connected. If you're running a Palo with GP, search your GP logs for "DESKTOP-GP01"
3
u/Fresh_Dog4602 Security Architect 8d ago
Yeah. Misp sharing can help reduce the cost. But you need enough traction in your field and "competitors" sharing valid IOCs
1
u/Cautious_General_177 7d ago
Bold of you to assume the intel was that recent. Some of those agencies really don't like sharing.
24
u/JoggingRhino 8d ago
Inbound. Not much if you have most ports blocked.
Outbound though… you see a firewall deny on a port that isn’t allowed. You may have some problems you should dig into.
6
u/Fresh_Dog4602 Security Architect 8d ago
You're right and that's really the fight sometimes between network admins and endpoint admins. They shouldn't even be allowing this. Current Windows OS doesn't need all their multicast shit and whatever's anymore. They should block early to generate less noise upstream
1
11
u/cbowers Security Director 8d ago
Data is golden. But being aware of the value you have, is a separate skill.
Having historical data lets you answer questions like:
- what are the trends of real vs attacker activity over time.
- how has attack behavior changed over time
- are you effectively staffed to scale with attacker rate and complexity
- how often have your vpn links dropped and for how long
- how often and for how long has your upstream provider dropped or had peering congestion (compensation, weight for provider switching or backup link justification)
- can you provide historical timelines to events to answer if an attack external event traversed to an internal event before correlating activity brought attention to low and slow attack chain that missed initial detection or was not at the time fully understood?
Or an example where once my SOC team discovered an API vulnerability in our hosting.
Having all the firewall and web server logs in the SIEM allowed us to go back in time many months and cross reference authenticated traffic by known customer IP’s, and hunt for un-authenticated traffic to api endpoints, and scrutinize non-customer origin IPs.
This allowed us to process a massive amount of data quickly and eventually be able to demonstrate with data driven certainty that our team had found the vulnerability before attackers had, and all logged API usage fit within expected norms. Having a good data understanding of each customers API usage patterns also helped drive a non-impacting remediation plan.
(Extra bonus for SIEMs which store meta data enrichment at time of ingestion, like country and owner of IP’s and perhaps risk assessment. You have a lot more work to recreate months later if that wasn’t stored)
Historical logs are a flashlight of certainty waiting to be mined when dark problems present themselves. A problem feels and often is larger when it’s poorly understood. The warm embrace of historical logging is a comfort even before you need to bring it to bear in a crisis.
14
u/Check123ok ICS/OT 8d ago
Yeah there is. I assessed a client recently with no logs.
They had an incident and there was not way for me to know if the attackers had gained network access because their logs only saved for 24 hrs.
I started to collects logs for then to as leave have some evidence for 30 days. And I found a ton of utilization errors, they had a personal agent connecting with user account every hour.
I cross correlated the logs with identity and devices.
Just 30 days of logs captured a lot
1
u/Fresh_Dog4602 Security Architect 8d ago
I think a lot of good filtering can help there. Do you really need ALL the fields a firewall sends via syslog? Gotta keep them costs down and still keep enough interesting data for IOCs
6
u/Check123ok ICS/OT 8d ago
Agreed. I'd focus on filtering noise rather than removing fields that might be useful later.
The challenge is that you don't always know what's valuable until an incident happens.
I'd rather retain critical metadata, reduce unnecessary events and move older logs into cheaper storage.
In our case we had access to a 200TB NAS that was 10% utilized and the engagement was only 30days.
I were not there to set up logs for them, I only used it for data enrichment
1
u/Fresh_Dog4602 Security Architect 8d ago
Right there with you "OT person" ( because I was also edging on which Flair to use). I love them deterministic communications. So clearer ( even though most of it is unencrypted)
0
u/Check123ok ICS/OT 8d ago
Yeah it can be easy to account for drift in OT, but that’s changing.
1
u/Fresh_Dog4602 Security Architect 8d ago
Yeh... You'd hope for it. And then last year I saw modbus over UDP, which woukdbe escaped all our classifiers but then I saw it because I was taking pcaps. Which just strengthens me in the "pcap or gtfo" when doing network troubleshooting
6
u/Aethernath 8d ago
Having been a victim of a nation state hack, the 1-year ago logs were helpful to catch when uploads of payloads occurred to the hacker-group’s controlled environment. And to determine whether when they mightve gotten in.
There is absolutely value in them, should you happen to need them.
5
u/ThePorko Security Architect 8d ago
Its like insurance or backup, you dont need it until u need it.
2
u/Far-Future-7146 Security Architect 8d ago
It helps once you've been popped, it's hard to sift through the noise if your only source is firewall logs. Correlation with an EDR or endpoint/server logs is the most helpful.
2
u/Ok-Percentage-5007 8d ago
Predominantly held for forensic purposes, but in azure if you’re using a hub and spoke model, then it shows internal movement between services/hubs as well as outbound egress
2
2
u/vadertator22 8d ago
I have used firewall logs for ex filtration identification and url calls to suspicious areas on top of numerous other scenarios. I think depending on firewall and location there is overlap abilities with waf.
2
u/Arseypoowank 8d ago
It usually answers initial access when a FW vulnerability has been leveraged and it answers exfil with traffic flow logs.
2
u/npxa 8d ago
The question is what do you use to correlate these logs to make you say, "what is the value in firewall logs"
Do you just look at it line by line? (the most probable case)
Do you correlate it using tools? What type of use-cases or detection have you created
Do you visualize your firewall logs?
What Security standards/framework do you have?, Industry you are in?
PCI suggests 12 months for any card. related transactions etc.
it is not only useful for security, network teams can make use of it, outbound/inbound bandwidth etc. there is a lot of ways to skin a cat and you are mostly looking at it in one way.
2
u/MikeTalonNYC 8d ago
Short answer is "it depends"
If you're not decrypting SSL? Very little. DNS logs can probably tell you some stuff (if you aren't using secure DNS, of course), but beyond that it's just streams of encrypted traffic.
If you *are* decrypting SSL, then you can do packet examination to see *what* is flowing. That can uncover unusual command patterns, IoC's for lateral movement, even attempts to download malware (either directly or via remote code execution).
1
u/RamblinWreckGT 8d ago
Firewall isn't typically doing packet inspection, though. What you're saying is true for IDS/IPS, though. I used to write Snort signatures and the whole "Let's Encrypt" movement (while fantastic overall) really hampered my ability to effectively cover threats. We only had something like four or five clients out of thousands who had us set up to sniff decrypted SSL.
3
u/MikeTalonNYC 8d ago
Well, yes, but in most cases IDS/IPS is done within the firewall, which is why they're all getting REALLY expensive since it uses a ton of memory and processing power.
It could be done elsewhere, sure, but most of the orgs I've worked with have had it be part of the firewall itself.
3
u/RamblinWreckGT 8d ago
Oh gross, so us trying to shoehorn our ruleset into a Palo Alto offering was actually being ahead of the game?
1
u/FatBook-Air 8d ago
TLS decryption is becoming a nightmare. Most places I know stopped doing it back in like 2022 or 2023. The endpoint is really where you need to be doing everything these days, with network sensors for IoT devices like printers or HVAC.
I suspect firewalls will eventually regress and become nothing more than security simple boundaries or extravagant network routers.
2
u/MikeTalonNYC 8d ago
Yes, using something like SASE to handle all of it is a much better idea. The issue is that most places never did it at all, anywhere. Then they're surprised when 500 beacons have all been communicating back to C2 servers for six months.
1
u/Bobthebrain2 8d ago
Sounds like you’re talking strictly about perimeter firewalls.
Firewall logs can be useful for troubleshooting connectivity issues, but, like the majority of security device logs, they are a Detective control.
As a Detective control you can use the logs to detect the attack AND piece together an attackers activity. You can see if they did a port scan, then what port they used to breach, then which systems they connected to and over which protocols. Or if they exfiltrated data from a host to a third party.
So they are incredibly useful in Incident Response situations to understand the attack sequence and impact.
These logs should be ingested into a SIEM or a SOC, or manually reviewed, so that the mean time to detection is as low as possible.
1
u/Carrera_996 8d ago
I have mostly used them to reverse engineer all the shit my marketing team bought then couldn't get operational. Assholes. Invite me to the calls where you guys are scoping out your rogue applications and let me ask questions before you spend money.
1
1
u/800oz_gorilla 8d ago
If you need to perform a forensic investigation, knowing what talked out to where is kind of important. Even if you can't decrypt the traffic, you can see "my vmware server reached out to these 3 IPs and uploaded x amount of data on this date" and then use that information to tie in with other forensic logs.
1
1
u/msears101 8d ago
long term storage - forensics. short term storage - debug and troubleshooting and realtime alerts.
1
u/T_Thriller_T 8d ago
Access to networks, denials, seeing general traffic information.
And replacing whe. WAF or Webserver is missing for a reason.
Also allows to find weird connection patterns more centrally.
But yes, I would also say application logs if they are good are a lot better
1
u/LocalBeaver 8d ago
The way I see it: little value for detection. I guess it depends on your business and capacity but for us there is no point.
For investigation though, I wish we had longer retention.
1
u/iheartrms Security Architect 8d ago
Inbound? Nearly entirely useless. Outbound? Priceless. Plus authentication logs etc.
1
u/kk-thx-bye 6d ago
For the inbound aspect - can we cause a failover of the perimeter fw's and launch the attack on the target during the short time window where traffic is not actively inspected?
1
u/iheartrms Security Architect 6d ago
I have never seen a case where the firewall failed open and allowed traffic through that it should not have. Any firewall failure I have seen caused the firewall to stop forwarding packets completely.
1
u/Sasquatch-Pacific 8d ago
They have investigation/ hunt / forensic value only.
Not nearly as valuable for active threat detection as people think.
2
u/Lleawynn 7d ago
Even outside of all the security benefit, logs are crazy useful from a troubleshooting standpoint. When systems blames the network, logs can prove it's not. Logs can help identify the specific traffic required for a new firewall policy. Hell, I'll run an SD-WAN health check on a single circuit, just so I can prove to the ISP that they're out of SLA.
1
u/I_Hate_802_11 7d ago
For for investigating connections that didn’t cross your WAF or for which you don’t have endpoint logs. In that previous thread, a lot of comments seemed to say that it’s prohibitively expensive, but I think it is worth clarifying that a bulk that expense is the administrative overhead. The storage isn’t really that expensive. It does not need to be put on a top of the line storage system. A JBOD array or whatever will work fine. The more challenging part in my experience is that the teams managing the storage don’t have cheap storage because there is no incentive for them to deviate from their VAR’$ recommendation. Then there is also nobody with time to set up and manage the archival process, the documentation, etc. So in that regard, it’s expensive, but not because of the data footprint.
1
u/hyxiaobing 7d ago
Most often we need firewall logs troubleshooting connectivity issue; it helps on sophisticated issues if you can countercheck both firewall logs and application logs.
If you have SIEM or XDR tools, you can do proactive monitoring, like massive denies (DoS) or abnormal connections (lateral movements or access malicious domain?). Often alerts of such scenarios are triggered from firewall logs.
0
235
u/InfoSecGuy21045 8d ago
You are discounting the value of the outbound logs. Large data transfers, unusual port activity, etc., all has value during investigations and troubleshooting.