KIT | KIT-Bibliothek | Impressum | Datenschutz

Security Analysis of Forward Secure Log Sealing in Journald

Dörre, Felix ORCID iD icon 1; Ottenhues, Astrid ORCID iD icon 1
1 Institut für Informationssicherheit und Verlässlichkeit (KASTEL), Karlsruher Institut für Technologie (KIT)

Abstract:

This paper presents a security analysis of forward-secure log sealing in the journald logging system, which is installed by default in almost all modern Linux distributions. Forward-secure log sealing is a cryptographic technique used to ensure the integrity of past log entries even in the event of a full system compromise. We identify multiple security vulnerabilities in journald resulting from a gap between the model of the cryptographic primitives and their usage in a larger context. Our
contribution is both theoretical and practical: As a practical contribution, we discovered attacks on the log sealing in journald and provide descriptions as well as implementations of the attacks. In particular one vulnerability allows to forge arbitrary logs for past entries without the validation tool noticing any problem. This finding completely breaks the security guarantee of log sealing. For all described vulnerabilities we provide patches, the two more serious ones are merged in systemd version 255. As a theoretical contribution, we provide formal definitions that capture the expected security properties of log sealing. We demonstrate our attacks on the vulnerable version of journald by showing how an attacker can defeat this security definition. ... mehr


Preprint §
DOI: 10.5445/IR/1000178591
Veröffentlicht am 31.01.2025
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Informationssicherheit und Verlässlichkeit (KASTEL)
Kompetenzzentrum für angewandte Sicherheitstechnologie (KASTEL)
Publikationstyp Proceedingsbeitrag
Publikationsdatum 23.06.2025
Sprache Englisch
Identifikator ISBN: 978-3-031-95764-2
ISSN: 0302-9743, 1611-3349
KITopen-ID: 1000178591
HGF-Programm 46.23.01 (POF IV, LK 01) Methods for Engineering Secure Systems
Erschienen in Applied Cryptography and Network Security – 23rd International Conference, ACNS 2025, Munich, Germany, June 23–26, 2025, Proceedings, Part II. Ed.: M. Fischlin
Veranstaltung 23rd International Conference on Applied Cryptography and Network Security (ACNS 2025), München, Deutschland, 23.06.2025 – 26.06.2025
Verlag Springer Nature Switzerland
Seiten 315 – 341
Serie Lecture Notes in Computer Science ; 15826
Nachgewiesen in OpenAlex
Dimensions
Scopus
Globale Ziele für nachhaltige Entwicklung Ziel 13 – Maßnahmen zum Klimaschutz
KIT – Die Universität in der Helmholtz-Gemeinschaft
KITopen Landing Page