Follow-up to #3180. Research proposal, not implemented or live-validated.
F4 — P2, conditional on an authorized audit source
Title: Define an offline FMC management-audit ingestion contract for actual state-change detections
Labels: security, analysis, enhancement
Proposal: Separate endpoint audit evidence from decoy HTTP logs. If authorized audit exports are available, design a normalizer for principal/role, session, operation, object identifier, result, timestamp and before/after metadata, plus asset and maintenance context. Keep certificate material, private keys, passwords and tokens out of routine records. Correlate only after proving a trustworthy source and timestamp semantics. No appliance access is authorized by this proposal.
Safe synthetic-event acceptance criteria:
- Offline fabricated audit records distinguish successful/failed/unknown policy changes, user creation and certificate import without changing any real system.
- Requests-only records cannot become completed-change events; simulated records cannot become real audit events.
- A scheduled fictional certificate renewal is separated from an unexpected admin creation by explicit maintenance context, not path substrings.
- Duplicate and out-of-order fixtures retain source identifiers and do not produce duplicate completed actions; missing principal/outcome remains unknown.
- Resulting records contain no certificate contents/private keys, raw secrets or real infrastructure identifiers.
Snapshot assessed: 00593d1d693cc7fe792beb7d24724dca5f55b2b8. Evidence paths are relative to APIARY. All acceptance tests must be offline and use inert fixtures; no exploitation, credentials, appliance access or deployment is authorized.
BLOCKED / conditional: proceed only after an authorized audit source is available. Tracking this proposal does not authorize obtaining appliance access.
Follow-up to #3180. Research proposal, not implemented or live-validated.
F4 — P2, conditional on an authorized audit source
Title: Define an offline FMC management-audit ingestion contract for actual state-change detections
Labels:
security,analysis,enhancementProposal: Separate endpoint audit evidence from decoy HTTP logs. If authorized audit exports are available, design a normalizer for principal/role, session, operation, object identifier, result, timestamp and before/after metadata, plus asset and maintenance context. Keep certificate material, private keys, passwords and tokens out of routine records. Correlate only after proving a trustworthy source and timestamp semantics. No appliance access is authorized by this proposal.
Safe synthetic-event acceptance criteria:
Snapshot assessed:
00593d1d693cc7fe792beb7d24724dca5f55b2b8. Evidence paths are relative to APIARY. All acceptance tests must be offline and use inert fixtures; no exploitation, credentials, appliance access or deployment is authorized.BLOCKED / conditional: proceed only after an authorized audit source is available. Tracking this proposal does not authorize obtaining appliance access.