Skip to content

Define an offline FMC management-audit ingestion contract for actual state-change detections #3215

Description

@Xore

Follow-up to #3180. Research proposal, not implemented or live-validated.

F4 — P2, conditional on an authorized audit source

Title: Define an offline FMC management-audit ingestion contract for actual state-change detections

Labels: security, analysis, enhancement

Proposal: Separate endpoint audit evidence from decoy HTTP logs. If authorized audit exports are available, design a normalizer for principal/role, session, operation, object identifier, result, timestamp and before/after metadata, plus asset and maintenance context. Keep certificate material, private keys, passwords and tokens out of routine records. Correlate only after proving a trustworthy source and timestamp semantics. No appliance access is authorized by this proposal.

Safe synthetic-event acceptance criteria:

  • Offline fabricated audit records distinguish successful/failed/unknown policy changes, user creation and certificate import without changing any real system.
  • Requests-only records cannot become completed-change events; simulated records cannot become real audit events.
  • A scheduled fictional certificate renewal is separated from an unexpected admin creation by explicit maintenance context, not path substrings.
  • Duplicate and out-of-order fixtures retain source identifiers and do not produce duplicate completed actions; missing principal/outcome remains unknown.
  • Resulting records contain no certificate contents/private keys, raw secrets or real infrastructure identifiers.

Snapshot assessed: 00593d1d693cc7fe792beb7d24724dca5f55b2b8. Evidence paths are relative to APIARY. All acceptance tests must be offline and use inert fixtures; no exploitation, credentials, appliance access or deployment is authorized.

BLOCKED / conditional: proceed only after an authorized audit source is available. Tracking this proposal does not authorize obtaining appliance access.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    analysisPayload analysis pipelineenhancementNew feature or requestsecuritySecurity hardening or a security defect

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions