Authors:
Luca Patzelt
1
;
Georg Neugebauer
1
;
Meik Döll
2
;
Sacha Hack
1
;
Tim Höner
1
and
Marko Schuba
1
Affiliations:
1
Department of Electrical Engineering and Computer Science, FH Aachen University of Applied Sciences, Eupener Str. 70, 52066 Aachen, Germany
;
2
SOPTIM AG, Im Süsterfeld 5-7, 52072 Aachen, Germany
Keyword(s):
Auditing, Auditing Framework, Audit Trail, End-to-End Audit Trail, E2E Audit Trail, Pseudonymisation.
Abstract:
In today’s world, there are more and more IT systems that are interconnected to provide services to a wide variety of business classes. Since their services are usually inevitably linked to financial and political interests, the number of attacks aimed at disrupting or profiting from these and the associated systems in various ways is constantly increasing. In this paper we design and implement a framework for the comprehensive auditing of IT systems in system architectures of different enterprise classes. For our solution, we evaluate formal requirements regarding audit trails, provide concepts for the pseudonymisation of audit data, develop software components for E2E audit trails and finally present a secure system architecture based on Kubernetes and Istio in conjunction with the storage components ArangoDB and HashiCorp Vault to achieve an efficient framework for creating E2E audit trails.