The importance of NGFW logging in the context of cyberattacks
Next-Generation Firewalls (NGFWs) play a critical role in network perimeter defense. The effectiveness of an NGFW as a security tool depends on the quality and completeness of its logs. Typical logging configurations often lack the detail or retention periods necessary for comprehensive cybersecurity incident investigations. This creates visibility gaps, making it difficult to reconstruct events and identify the source and impact of an attack.
Logs are the cornerstone of incident response and compliance. They provide a chronological record of events, allowing security teams to reconstruct the attack vector and assess its impact. Without adequate logs, early detection of intrusions is challenging. CISA emphasizes that effective logs must contain sufficient detail to assist incident responders 1. NIST also highlights the importance of continuous log monitoring for detecting threats—both successful and unsuccessful 2.
Key NGFW log types required for investigation
For effective investigation of cyberattacks on NGFWs, it is critical to collect and analyze a minimum set of log types. CISA recommends logging a wide range of events, including user activity, administrator actions, network traffic, application logins, and system events 1.
- Traffic logs (Connection logs): Record information about allowed and blocked traffic (source and destination IP addresses, ports, protocols, connection status). This is fundamental for understanding network activity and detecting anomalies 2.
- Security event logs (Threat logs): Document detected and blocked threats (intrusions, malware, exploit attempts). They help identify attack vectors and their nature 2.
- URL filtering logs: Detail access to web resources, allowed and blocked URLs. Help detect phishing attempts or access to malicious sites 2.
- VPN connection logs: Record connection ingress/egress, successful/failed authentication attempts, and traffic volume. This is critical for monitoring remote access 2.
- Authentication logs: Record successful and failed user login attempts to the NGFW interface or to resources protected by it. Help detect brute-force attempts or unauthorized access 2.
- System logs: Contain information about NGFW status, configuration changes, reboots, system errors, and firmware updates. Important for auditing changes and detecting unauthorized modifications 2.
Minimum logging contract: What to include and how to justify it
A minimum logging contract is a clearly defined and documented set of log types and their levels of detail that must be enabled on an NGFW, along with their retention periods. This “contract” should balance security requirements, regulatory obligations, and economic feasibility. Overly detailed logging of all traffic can lead to massive data volumes, making it difficult to detect important events and increasing storage costs 2.
When justifying a minimum logging contract, consider:
- Risk: What types of attacks are most likely, and what logs are needed to detect and investigate them?
- Regulatory requirements: Are there industry standards (e.g., PCI DSS, GDPR, HIPAA) that require specific log types to be retained for a defined period?
- Operational complexity: The ability to effectively collect, store, and analyze logs without excessive burden on infrastructure and personnel.
- Cost: The costs of storing and processing logs, which can be optimized using tiered storage strategies (hot, warm, cold) and data compression.
CISA recommends defining what specifically needs to be logged, such as user activity, administrator actions, and network traffic 1. NGFW vendors like Palo Alto Networks 3 and Cisco 4 provide recommendations for logging configuration that can serve as a starting point.
Log retention periods: Balancing risk and cost
Determining optimal log retention periods is a critical decision for CISOs, requiring a balance between security requirements, regulatory obligations, and economic feasibility. Excessive retention increases costs, while insufficient retention increases the risk of being unable to conduct an investigation 2.
Retention period recommendations:
- Operational analysis and troubleshooting: For most operational investigations and troubleshooting, data from the last 14–30 days is sufficient. These logs should be easily accessible for quick analysis.
- Incident investigation and compliance: For comprehensive incident investigation and compliance audits, CISA advises retaining logs for at least one year 1. Some regulatory requirements, such as DFARS, may require retaining relevant monitoring logs and network traffic data for at least 90 days from the incident submission 5. A general rule is to retain at least 12 months of data to ensure its availability if needed.
- Long-term archiving: For long-term regulatory compliance or deep forensic analysis, older logs can be moved to less expensive storage (cold storage) while maintaining the ability to access them in the future.
It is also important to protect logs from unauthorized access or deletion by restricting and monitoring access to them and storing them securely.
Pros and cons of a minimum logging contract
Implementing a minimum logging contract for NGFWs has its advantages and disadvantages.
Pros:
- Cost optimization: Reducing data volumes for storage and processing lowers infrastructure costs (storage, SIEM) and licenses.
- Reduced operational complexity: Smaller data volumes simplify log management, analysis, and searching for relevant information.
- Increased investigation efficiency: Focusing on critical logs allows faster detection and response to incidents, without being distracted by excessive information.
- Regulatory compliance: A clearly defined contract helps ensure compliance with standards that require the retention of specific log types.
Cons:
- Risk of data loss for deep analysis: If the minimum contract is too strict, information critical for investigating complex or previously unknown attacks may be lost.
- Potential visibility gaps: Some non-obvious attack vectors may go unnoticed due to the lack of detailed logs across all aspects of network activity.
- Need for continuous review: Changes in the threat landscape and regulatory requirements necessitate regular review and update of the minimum logging contract.
Practical checklist for auditing NGFW logging configuration
This checklist will help CISOs verify the current logging configuration on their NGFW and ensure it meets the minimum requirements for effective incident investigation. Based on the answers, you can determine the next steps for improvement.
- Traffic logs: Are logs for allowed and denied traffic enabled?
- If NO: Assess the impact and enable allowed and denied traffic logs, justifying a minimum set for 12-month retention.
- Security event logs: Are logs for IDS/IPS triggers, malware detection, and URL filtering enabled?
- If NO: Assess the impact and enable security event logs, ensuring 12-month retention.
- VPN connection logs: Are logs for successful and failed VPN connections enabled?
- If NO: Assess the impact and enable VPN connection logs, ensuring 12-month retention.
- Authentication logs: Are logs for successful and failed user authentication attempts enabled?
- If NO: Assess the impact and enable authentication logs, ensuring 12-month retention.
- System logs: Are NGFW system logs (configuration changes, reboots, updates) enabled?
- If NO: Assess the impact and enable NGFW system logs, ensuring 12-month retention.
- Level of detail: Do the logs contain sufficient detail (IP addresses, ports, protocols, actions, user IDs, full URLs, detected threats)?
- If NO: Review and increase the logging detail level for critical events.
- Centralized storage: Is centralized collection and aggregation of logs ensured (e.g., in a SIEM system)?
- If NO: Implement a centralized log collection system (SIEM/Log Management).
- Retention periods: Are retention periods for each log type defined and adhered to according to internal policies and regulatory requirements?
- If NO: Develop and implement a log retention policy.
- Log protection: Are logs protected from unauthorized access, modification, or deletion?
- If NO: Implement log protection measures (access control, hashing, backup).
- Configuration audit: Is a regular audit of the NGFW logging configuration conducted?
- If NO: Plan and conduct regular audits of the logging configuration.
- Access procedure: Is there a clear procedure for accessing logs for incident investigation?
- If NO: Develop and document a log access procedure.
- Time synchronization: Is time synchronization ensured on the NGFW and the log collection system for correct event correlation?
- If NO: Configure time synchronization (NTP) on all relevant devices.
Softline IT helps plan and implement cybersecurity solutions: from current state audit to an agreed-upon change plan.
Softline IT helps teams plan and implement cybersecurity, from an assessment of the current environment to an agreed change plan.
