Skip to main content

Management / Auditlog / Threats / DEV

Logging Evasion via violating size constraints

CCC.AUDITLOG.TH05

An attacker can evade detection by intentionally crafting input that violates the size constraints of a clouds audit logging mechanism. Many systems impose a maximum size limit on individual log entries. By performing an action with oversized data such as whitespace or Unicode injection, the resulting log event, which often includes the offending data, exceeds this limit, which often is redacted in the audit logs.

Related Capabilities

IDTitleDescription
CCC.Core.CP03Access Log PublicationThe service automatically publishes structured, verbose records of activities performed within the scope of the service by external actors.
CCC.Core.CP10Log PublicationThe service automatically publishes structured, verbose records of activities, operations, or events that occur within the service.

External Mappings

FrameworkIDRemarks
OWASPTOP10A09:2021
CWECWE-778Insufficient Logging
CWECWE-223Omission of Security-Relevant Information
CWECWE-20