New regulations about keeping logs
There has just been a new regulation about keeping network logs for last 6 months.
According to the regulation 5651,
Internet endpoints, DHCP IP distribution records, and traffic information of Web, e-mail and FTP servers in your organization’s intranet have to be saved in the format mentioned in the law; in a form that, their consistency, integrity, and the hashes of the files are preserved and their privacy is assured.
I am really curious how DHCP records will help if some violations occur in the network. If something occurs, and you are judged, the court applies for an authority. In Turkey, anyone can be an authority. All you should know is how to use Frontpage. If the authority can’t find a solution, he asks for the logs. This regulation just fulfills this requirement.
How will the system admins make sure that the log information’s consistency, integrity and the hashes of the files are preserved and their privacy is assured? If an admin is sure that the log is in safe, he can also protect the system against hacks. May be sending the last 6 months logs to the government’s servers can be a solution.
However, this solution has problems too. How the governments will build a logging log server, and how they will protect these servers against hacks?
I have even not mentioned how it will cost, who will analyze all these logs, find the needed information, automate, and adjust the system according to the requirements in that field.
Judges judge according to how expert’s judge in IT cases. This is why a regulation something like this is needed. However, this regulation is open to violations. How will experts make sure that the information on those systems are real?
Anyway, Expert (authority) system is a problem in Turkey, just like any government related case. Our government could not see yet that digital information is not reliable. Anyone may be hurt because of these laws and regulations. Who will protect innocent people’s rights?
