Central Log Management (CLM)
An appropriately implemented Central Log Management (CLM) produces an irrepudiable trace of the security related events of a system. The irrefutability is achieved via mutual TLS authentication between the logging service and connected components as well as by employing tamper-evident encryption of the data-at-rest storage.
A centrally managed log allows security incidents to be detected and addressed. It is also possible to generate reports that are required by regulatory frameworks.
On one hand, the ability to detect and respond to security events requires data to be collected and stored at a sufficient level of detail. On the other hand, regulations like the GDPR limit how much information can be stored, for how long time and how it can be used.
GDPR Compliant Monitoring of DNS and SMTP
As a DNS provider, we are obliged by the NIS2 to collect log of the usage of our authoritative DNS server. This includes the IP addresses and timestamps of all requests.
An IP address may be considered to be personal data. The GDPR allows personal data to be collected to satisfy a legal obligation, such as that imposed by NIS2. Furthermore, authoritative DNS servers like ours are not normally accessed by end users but by recursive caching resolvers that are typically run by Internet Service Providers, which is what actual end users would rely on. That is, our DNS servers should receive traffic from other DNS servers that are run by companies, not private persons.
Some administrative communication regarding to the DNS service involves e-mail via our public SMTP server. Similar to our authoritative DNS server, that server is intended to be accessed by other SMTP servers that are run by organisations or companies, not private persons. A similar reasoning applies to collecting usage statistics.
Collecting Log on Authenticated Users
The contracts with our customers give us consent to process their data and store it according to our data retention policy. Any actions of users who have authenticated themselves in our system may be logged. Either they are legitimate users who have consented to that, or we have a legitimate interest to detect and report security incidents.
Given that the first line of defence of most of our services is a VPN gateway, we must collect information on connection establishment as well as authentication failures. The public IP address of the user as well as the corresponding tunneled address in the VPN will be recorded together.
Similarly, for any of our services that require authentication, whether it is inside a VPN or on the public Internet, we will log connect and disconnect events, as appropriate. There is also some log coverage of internal components that are not directly exposed to end users.
How to Process the Information
The collected information will be stored according to our data retention policy and the applicable regulations.
Because of the sheer volume, we cannot rely on humans to detect all anomalies. We employ a multi-stage solution that combines machine learning and artificial intelligence.