<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Marc+Chisinevski</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Marc+Chisinevski"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Marc_Chisinevski"/>
		<updated>2026-06-02T04:59:26Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Global_Education_Committee_-_Application_2&amp;diff=75123</id>
		<title>Global Education Committee - Application 2</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Global_Education_Committee_-_Application_2&amp;diff=75123"/>
				<updated>2009-12-14T10:19:17Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[How to Join a Committee|Click here to return to 'How to Join a Committee' page]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''COMMITTEE APPLICATION FORM''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Applicant's Name'''&lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;Carlos Serrão&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Current and past OWASP Roles''' &lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|OWASP Portuguese Chapter Leader.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Committee Applying for''' &lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|OWASP Global Education Committee.&lt;br /&gt;
 |}&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
Please be aware that for an application to be considered by the board, '''you MUST have 5 recommendations'''.  &lt;br /&gt;
An incomplete application will not be considered for vote.&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;8&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''COMMITTEE RECOMMENDATIONS''' &lt;br /&gt;
 |- &lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Who Recommends/Name''' &lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Role in OWASP'''&lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Recommendation Content''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''1'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Kuai Hinojosa &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Minneapolis - St Paul Chapter President 2008-2010, GEC Chair, Board member of the NYC/NJ Chapter&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|I met Carlos at the Summit in Portugal, Carlos was enthusiastic and started helping the group shooting video of presentations and giving everyone a hand, he supports the OWASP mission and has done a good job organizing the conference in Madrid.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''2'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Fabio Cerullo&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Ireland&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|I am very pleased to recommend Carlos for admission to the Global Education Committee. Carlos is energetic, passionate and genuinely interested in &amp;quot;raising the bar&amp;quot; in application security. He has actively participated in a diverse assortment of activities organizing the IBWAS conference as part of his role as OWASP Portugal Lead and works in one of the biggest universities in Portugal teaching application security.  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''3'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Martin Knobloch&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| OWASP Netherlands, GEC member&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Looking forward to have Carlos in the team!!!&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''4'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Marc Chisinevski&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| OWASP France&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| I met Carlos during IBWAS09. He definitely has the qualities necessary to advance the work of the Global Education Commitee.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''5'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |}&lt;br /&gt;
----&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Global_Education_Committee_-_Application_5&amp;diff=75122</id>
		<title>Global Education Committee - Application 5</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Global_Education_Committee_-_Application_5&amp;diff=75122"/>
				<updated>2009-12-14T07:18:40Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[How to Join a Committee|Click here to return to 'How to Join a Committee' page]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''COMMITTEE APPLICATION FORM''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Applicant's Name'''&lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;Marc Chisinevski&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Current and past OWASP Roles''' &lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|OWASP Logging Project lead and main contributor.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Committee Applying for''' &lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|OWASP Global Education Committee.&lt;br /&gt;
 |}&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
Please be aware that for an application to be considered by the board, '''you MUST have 5 recommendations'''.  &lt;br /&gt;
An incomplete application will not be considered for vote.&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;8&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''COMMITTEE RECOMMENDATIONS''' &lt;br /&gt;
 |- &lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Who Recommends/Name''' &lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Role in OWASP'''&lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Recommendation Content''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''1'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''2'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''3'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''4'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''5'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |}&lt;br /&gt;
----&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=75117</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=75117"/>
				<updated>2009-12-13T22:59:47Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [[:Category:OWASP Logging Project - Roadmap|Roadmap]] &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;The OWASP Logging Project presented at IBWAS09&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:IBWAS09_OWASP_Logging_Project_Presentation.ppt]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:IBWAS09_Proyecto_OWASP_Logging_Presentación_en_Español.ppt]]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Project Roadmap &amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Owasp_Logging_Project_Roadmap.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Logging Guide &amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:OWASP Logging Guide.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Goals  ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Provide tools for software developers in order to help them define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps) &lt;br /&gt;
&lt;br /&gt;
Facilitate the integration of logs from different sources &lt;br /&gt;
&lt;br /&gt;
Facilitate attack reconstruction &lt;br /&gt;
&lt;br /&gt;
Facilitate information sharing around security events&lt;br /&gt;
&lt;br /&gt;
== Existing tools and use cases  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''1) IDE integration''' (auto-completion, templates, logging policy definition support) for guiding software developers to define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
For example, a template can provide checks/hints/defaults s.a. those defined by the OWASP Enterprise Security API :&amp;lt;br&amp;gt;- something equivalent to a generated logging session ID, or a hashed value of the session ID so they can track session specific events without risking the exposure of a live session's ID&amp;lt;br&amp;gt;- identity of the user that caused the event&amp;lt;br&amp;gt;- description of the event (supplied by the caller)&amp;lt;br&amp;gt;- whether the event succeeded or failed (indicated by the caller)&amp;lt;br&amp;gt;- severity level of the event (indicated by the caller)&amp;lt;br&amp;gt;- that this is a security relevant event (indicated by the caller)&amp;lt;br&amp;gt;- hostname or IP where the event occurred (and ideally the user's source IP as well)&amp;lt;br&amp;gt;- a time stamp &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''IDE templates'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/File:Eclipse_Create_Template.png&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/File:NetBeans_Create_Live_Template.png&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://wiki.netbeans.org/Java_EditorUsersGuide&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''OWASP ESAPI Logger''' interface (Logger.java) and implementations&amp;lt;br&amp;gt;http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''2/ Code audit tools''' s.a. OWASP yasca can be easily adapted in order to ensure that logging standards are respected and that log messages are consistent and complete (content, format, timestamps)&amp;lt;br&amp;gt;See http://www.owasp.org/index.php/Category:OWASP_Yasca_Project&amp;lt;br&amp;gt;Related OWASP projects: http://www.owasp.org/index.php/Category:OWASP_Orizon_Project &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''3) Integrating application logs into a Security Information Management configuration'''&amp;lt;br&amp;gt;OSSIM (http://www.ossim.net/) has numerous plugins for parsing webserver, appserver, WAF, IPS, IDS logs and generating/storing events in its standard format. &lt;br /&gt;
&lt;br /&gt;
Adding a plugin for parsing custom application logs is as easy as finding the correct regular expression provided that developers included all relevant information in the log message and that they have done so in a consistent way. &lt;br /&gt;
&lt;br /&gt;
You can refer to the OSSIM database model to see what data is stored for events. &lt;br /&gt;
&lt;br /&gt;
See http://www.owasp.org/index.php/File:OWASP_Logging_Guide.pdf for more details/screenshots on application event integration and correlation via OSSIM &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''4) Reconstructing attacks'''&amp;lt;br&amp;gt;It is difficult to analyze, filter and generally reconstruct an attack because messages are spread around various log levels. &lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
Along the same lines, Arshan Dabirsiaghi's proposal of adding a security log level is very interesting&amp;lt;br&amp;gt;http://www.owasp.org/index.php/How_to_add_a_security_log_level_in_log4j &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''5) Implement scripts for filtering/scrubbing logs in order to enable log data sharing between organizations'''&amp;lt;br&amp;gt;Goal: information sharing around security events&amp;lt;br&amp;gt;Custom logger implementations based on the OWASP ESAPI might also filter out any sensitive data specific to the current application or organization, such as credit cards, social security numbers etc. &lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;See http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
          *** We need your efforts and contribution to this project ***&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Project Identification ====&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] &lt;br /&gt;
[[Category:OWASP_Document]] &lt;br /&gt;
[[Category:OWASP_Alpha_Quality_Document]]&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Logging Project&lt;br /&gt;
| project_description = The goals of this project are:&lt;br /&gt;
* Provide tools for software developers in order to help them define and provide meaningful logs&lt;br /&gt;
* Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps)&lt;br /&gt;
* Facilitate the integration of logs from different sources&lt;br /&gt;
* Facilitate attack reconstruction&lt;br /&gt;
* Facilitate information sharing around security events&lt;br /&gt;
| leader_name = Marc Chisinevski&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Marc_Chisinevski&lt;br /&gt;
| maintainer_name = Marc Chisinevski&lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = Marc_Chisinevski&lt;br /&gt;
| contributor_name1 = Marc Chisinevski&lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = Marc_Chisinevski&lt;br /&gt;
| contributor_name2 = Anthony Lai&lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = Sam Ng&lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-logging&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map = Category:OWASP_Logging_Project_-_Roadmap&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = First Release&lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=75116</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=75116"/>
				<updated>2009-12-13T22:57:28Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [[:Category:OWASP Logging Project - Roadmap|Roadmap]] &lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project presented at IBWAS09&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:IBWAS09_OWASP_Logging_Project_Presentation.ppt]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:IBWAS09_Proyecto_OWASP_Logging_Presentación_en_Español.ppt]]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Project Roadmap &amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Owasp_Logging_Project_Roadmap.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Logging Guide &amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:OWASP Logging Guide.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Goals  ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Provide tools for software developers in order to help them define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps) &lt;br /&gt;
&lt;br /&gt;
Facilitate the integration of logs from different sources &lt;br /&gt;
&lt;br /&gt;
Facilitate attack reconstruction &lt;br /&gt;
&lt;br /&gt;
Facilitate information sharing around security events&lt;br /&gt;
&lt;br /&gt;
== Existing tools and use cases  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''1) IDE integration''' (auto-completion, templates, logging policy definition support) for guiding software developers to define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
For example, a template can provide checks/hints/defaults s.a. those defined by the OWASP Enterprise Security API :&amp;lt;br&amp;gt;- something equivalent to a generated logging session ID, or a hashed value of the session ID so they can track session specific events without risking the exposure of a live session's ID&amp;lt;br&amp;gt;- identity of the user that caused the event&amp;lt;br&amp;gt;- description of the event (supplied by the caller)&amp;lt;br&amp;gt;- whether the event succeeded or failed (indicated by the caller)&amp;lt;br&amp;gt;- severity level of the event (indicated by the caller)&amp;lt;br&amp;gt;- that this is a security relevant event (indicated by the caller)&amp;lt;br&amp;gt;- hostname or IP where the event occurred (and ideally the user's source IP as well)&amp;lt;br&amp;gt;- a time stamp &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''IDE templates'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/File:Eclipse_Create_Template.png&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/File:NetBeans_Create_Live_Template.png&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://wiki.netbeans.org/Java_EditorUsersGuide&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''OWASP ESAPI Logger''' interface (Logger.java) and implementations&amp;lt;br&amp;gt;http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''2/ Code audit tools''' s.a. OWASP yasca can be easily adapted in order to ensure that logging standards are respected and that log messages are consistent and complete (content, format, timestamps)&amp;lt;br&amp;gt;See http://www.owasp.org/index.php/Category:OWASP_Yasca_Project&amp;lt;br&amp;gt;Related OWASP projects: http://www.owasp.org/index.php/Category:OWASP_Orizon_Project &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''3) Integrating application logs into a Security Information Management configuration'''&amp;lt;br&amp;gt;OSSIM (http://www.ossim.net/) has numerous plugins for parsing webserver, appserver, WAF, IPS, IDS logs and generating/storing events in its standard format. &lt;br /&gt;
&lt;br /&gt;
Adding a plugin for parsing custom application logs is as easy as finding the correct regular expression provided that developers included all relevant information in the log message and that they have done so in a consistent way. &lt;br /&gt;
&lt;br /&gt;
You can refer to the OSSIM database model to see what data is stored for events. &lt;br /&gt;
&lt;br /&gt;
See http://www.owasp.org/index.php/File:OWASP_Logging_Guide.pdf for more details/screenshots on application event integration and correlation via OSSIM &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''4) Reconstructing attacks'''&amp;lt;br&amp;gt;It is difficult to analyze, filter and generally reconstruct an attack because messages are spread around various log levels. &lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
Along the same lines, Arshan Dabirsiaghi's proposal of adding a security log level is very interesting&amp;lt;br&amp;gt;http://www.owasp.org/index.php/How_to_add_a_security_log_level_in_log4j &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''5) Implement scripts for filtering/scrubbing logs in order to enable log data sharing between organizations'''&amp;lt;br&amp;gt;Goal: information sharing around security events&amp;lt;br&amp;gt;Custom logger implementations based on the OWASP ESAPI might also filter out any sensitive data specific to the current application or organization, such as credit cards, social security numbers etc. &lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;See http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
          *** We need your efforts and contribution to this project ***&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Project Identification ====&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] &lt;br /&gt;
[[Category:OWASP_Document]] &lt;br /&gt;
[[Category:OWASP_Alpha_Quality_Document]]&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Logging Project&lt;br /&gt;
| project_description = The goals of this project are:&lt;br /&gt;
* Provide tools for software developers in order to help them define and provide meaningful logs&lt;br /&gt;
* Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps)&lt;br /&gt;
* Facilitate the integration of logs from different sources&lt;br /&gt;
* Facilitate attack reconstruction&lt;br /&gt;
* Facilitate information sharing around security events&lt;br /&gt;
| leader_name = Marc Chisinevski&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Marc_Chisinevski&lt;br /&gt;
| maintainer_name = Marc Chisinevski&lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = Marc_Chisinevski&lt;br /&gt;
| contributor_name1 = Marc Chisinevski&lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = Marc_Chisinevski&lt;br /&gt;
| contributor_name2 = Anthony Lai&lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = Sam Ng&lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-logging&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map = Category:OWASP_Logging_Project_-_Roadmap&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = First Release&lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=75115</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=75115"/>
				<updated>2009-12-13T22:56:00Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [[:Category:OWASP Logging Project - Roadmap|Roadmap]] &lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project presented at IBWAS09&lt;br /&gt;
[[Image:IBWAS09_OWASP_Logging_Project_Presentation.ppt]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:IBWAS09_Proyecto_OWASP_Logging_Presentación_en_Español.ppt]]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Image:Owasp_Logging_Project_Roadmap.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP Logging Guide.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Goals  ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Provide tools for software developers in order to help them define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps) &lt;br /&gt;
&lt;br /&gt;
Facilitate the integration of logs from different sources &lt;br /&gt;
&lt;br /&gt;
Facilitate attack reconstruction &lt;br /&gt;
&lt;br /&gt;
Facilitate information sharing around security events&lt;br /&gt;
&lt;br /&gt;
== Existing tools and use cases  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''1) IDE integration''' (auto-completion, templates, logging policy definition support) for guiding software developers to define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
For example, a template can provide checks/hints/defaults s.a. those defined by the OWASP Enterprise Security API :&amp;lt;br&amp;gt;- something equivalent to a generated logging session ID, or a hashed value of the session ID so they can track session specific events without risking the exposure of a live session's ID&amp;lt;br&amp;gt;- identity of the user that caused the event&amp;lt;br&amp;gt;- description of the event (supplied by the caller)&amp;lt;br&amp;gt;- whether the event succeeded or failed (indicated by the caller)&amp;lt;br&amp;gt;- severity level of the event (indicated by the caller)&amp;lt;br&amp;gt;- that this is a security relevant event (indicated by the caller)&amp;lt;br&amp;gt;- hostname or IP where the event occurred (and ideally the user's source IP as well)&amp;lt;br&amp;gt;- a time stamp &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''IDE templates'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/File:Eclipse_Create_Template.png&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/File:NetBeans_Create_Live_Template.png&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://wiki.netbeans.org/Java_EditorUsersGuide&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''OWASP ESAPI Logger''' interface (Logger.java) and implementations&amp;lt;br&amp;gt;http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''2/ Code audit tools''' s.a. OWASP yasca can be easily adapted in order to ensure that logging standards are respected and that log messages are consistent and complete (content, format, timestamps)&amp;lt;br&amp;gt;See http://www.owasp.org/index.php/Category:OWASP_Yasca_Project&amp;lt;br&amp;gt;Related OWASP projects: http://www.owasp.org/index.php/Category:OWASP_Orizon_Project &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''3) Integrating application logs into a Security Information Management configuration'''&amp;lt;br&amp;gt;OSSIM (http://www.ossim.net/) has numerous plugins for parsing webserver, appserver, WAF, IPS, IDS logs and generating/storing events in its standard format. &lt;br /&gt;
&lt;br /&gt;
Adding a plugin for parsing custom application logs is as easy as finding the correct regular expression provided that developers included all relevant information in the log message and that they have done so in a consistent way. &lt;br /&gt;
&lt;br /&gt;
You can refer to the OSSIM database model to see what data is stored for events. &lt;br /&gt;
&lt;br /&gt;
See http://www.owasp.org/index.php/File:OWASP_Logging_Guide.pdf for more details/screenshots on application event integration and correlation via OSSIM &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''4) Reconstructing attacks'''&amp;lt;br&amp;gt;It is difficult to analyze, filter and generally reconstruct an attack because messages are spread around various log levels. &lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
Along the same lines, Arshan Dabirsiaghi's proposal of adding a security log level is very interesting&amp;lt;br&amp;gt;http://www.owasp.org/index.php/How_to_add_a_security_log_level_in_log4j &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''5) Implement scripts for filtering/scrubbing logs in order to enable log data sharing between organizations'''&amp;lt;br&amp;gt;Goal: information sharing around security events&amp;lt;br&amp;gt;Custom logger implementations based on the OWASP ESAPI might also filter out any sensitive data specific to the current application or organization, such as credit cards, social security numbers etc. &lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;See http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
          *** We need your efforts and contribution to this project ***&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Project Identification ====&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] &lt;br /&gt;
[[Category:OWASP_Document]] &lt;br /&gt;
[[Category:OWASP_Alpha_Quality_Document]]&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Logging Project&lt;br /&gt;
| project_description = The goals of this project are:&lt;br /&gt;
* Provide tools for software developers in order to help them define and provide meaningful logs&lt;br /&gt;
* Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps)&lt;br /&gt;
* Facilitate the integration of logs from different sources&lt;br /&gt;
* Facilitate attack reconstruction&lt;br /&gt;
* Facilitate information sharing around security events&lt;br /&gt;
| leader_name = Marc Chisinevski&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Marc_Chisinevski&lt;br /&gt;
| maintainer_name = Marc Chisinevski&lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = Marc_Chisinevski&lt;br /&gt;
| contributor_name1 = Marc Chisinevski&lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = Marc_Chisinevski&lt;br /&gt;
| contributor_name2 = Anthony Lai&lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = Sam Ng&lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-logging&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map = Category:OWASP_Logging_Project_-_Roadmap&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = First Release&lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=75114</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=75114"/>
				<updated>2009-12-13T22:52:01Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [[:Category:OWASP Logging Project - Roadmap|Roadmap]] &lt;br /&gt;
&lt;br /&gt;
[[Image:IBWAS09_OWASP_Logging_Project_Presentation.ppt]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:Owasp_Logging_Project_Roadmap.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP Logging Guide.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Goals  ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Provide tools for software developers in order to help them define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps) &lt;br /&gt;
&lt;br /&gt;
Facilitate the integration of logs from different sources &lt;br /&gt;
&lt;br /&gt;
Facilitate attack reconstruction &lt;br /&gt;
&lt;br /&gt;
Facilitate information sharing around security events&lt;br /&gt;
&lt;br /&gt;
== Existing tools and use cases  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''1) IDE integration''' (auto-completion, templates, logging policy definition support) for guiding software developers to define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
For example, a template can provide checks/hints/defaults s.a. those defined by the OWASP Enterprise Security API :&amp;lt;br&amp;gt;- something equivalent to a generated logging session ID, or a hashed value of the session ID so they can track session specific events without risking the exposure of a live session's ID&amp;lt;br&amp;gt;- identity of the user that caused the event&amp;lt;br&amp;gt;- description of the event (supplied by the caller)&amp;lt;br&amp;gt;- whether the event succeeded or failed (indicated by the caller)&amp;lt;br&amp;gt;- severity level of the event (indicated by the caller)&amp;lt;br&amp;gt;- that this is a security relevant event (indicated by the caller)&amp;lt;br&amp;gt;- hostname or IP where the event occurred (and ideally the user's source IP as well)&amp;lt;br&amp;gt;- a time stamp &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''IDE templates'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/File:Eclipse_Create_Template.png&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/File:NetBeans_Create_Live_Template.png&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://wiki.netbeans.org/Java_EditorUsersGuide&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''OWASP ESAPI Logger''' interface (Logger.java) and implementations&amp;lt;br&amp;gt;http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''2/ Code audit tools''' s.a. OWASP yasca can be easily adapted in order to ensure that logging standards are respected and that log messages are consistent and complete (content, format, timestamps)&amp;lt;br&amp;gt;See http://www.owasp.org/index.php/Category:OWASP_Yasca_Project&amp;lt;br&amp;gt;Related OWASP projects: http://www.owasp.org/index.php/Category:OWASP_Orizon_Project &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''3) Integrating application logs into a Security Information Management configuration'''&amp;lt;br&amp;gt;OSSIM (http://www.ossim.net/) has numerous plugins for parsing webserver, appserver, WAF, IPS, IDS logs and generating/storing events in its standard format. &lt;br /&gt;
&lt;br /&gt;
Adding a plugin for parsing custom application logs is as easy as finding the correct regular expression provided that developers included all relevant information in the log message and that they have done so in a consistent way. &lt;br /&gt;
&lt;br /&gt;
You can refer to the OSSIM database model to see what data is stored for events. &lt;br /&gt;
&lt;br /&gt;
See http://www.owasp.org/index.php/File:OWASP_Logging_Guide.pdf for more details/screenshots on application event integration and correlation via OSSIM &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''4) Reconstructing attacks'''&amp;lt;br&amp;gt;It is difficult to analyze, filter and generally reconstruct an attack because messages are spread around various log levels. &lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
Along the same lines, Arshan Dabirsiaghi's proposal of adding a security log level is very interesting&amp;lt;br&amp;gt;http://www.owasp.org/index.php/How_to_add_a_security_log_level_in_log4j &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''5) Implement scripts for filtering/scrubbing logs in order to enable log data sharing between organizations'''&amp;lt;br&amp;gt;Goal: information sharing around security events&amp;lt;br&amp;gt;Custom logger implementations based on the OWASP ESAPI might also filter out any sensitive data specific to the current application or organization, such as credit cards, social security numbers etc. &lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;See http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
          *** We need your efforts and contribution to this project ***&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Project Identification ====&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] &lt;br /&gt;
[[Category:OWASP_Document]] &lt;br /&gt;
[[Category:OWASP_Alpha_Quality_Document]]&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Logging Project&lt;br /&gt;
| project_description = The goals of this project are:&lt;br /&gt;
* Provide tools for software developers in order to help them define and provide meaningful logs&lt;br /&gt;
* Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps)&lt;br /&gt;
* Facilitate the integration of logs from different sources&lt;br /&gt;
* Facilitate attack reconstruction&lt;br /&gt;
* Facilitate information sharing around security events&lt;br /&gt;
| leader_name = Marc Chisinevski&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Marc_Chisinevski&lt;br /&gt;
| maintainer_name = Marc Chisinevski&lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = Marc_Chisinevski&lt;br /&gt;
| contributor_name1 = Marc Chisinevski&lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = Marc_Chisinevski&lt;br /&gt;
| contributor_name2 = Anthony Lai&lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = Sam Ng&lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-logging&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map = Category:OWASP_Logging_Project_-_Roadmap&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = First Release&lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:IBWAS09_Proyecto_OWASP_Logging_Presentaci%C3%B3n_en_Espa%C3%B1ol.ppt&amp;diff=75113</id>
		<title>File:IBWAS09 Proyecto OWASP Logging Presentación en Español.ppt</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:IBWAS09_Proyecto_OWASP_Logging_Presentaci%C3%B3n_en_Espa%C3%B1ol.ppt&amp;diff=75113"/>
				<updated>2009-12-13T22:46:26Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:IBWAS09_OWASP_Logging_Project_Presentation.ppt&amp;diff=75112</id>
		<title>File:IBWAS09 OWASP Logging Project Presentation.ppt</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:IBWAS09_OWASP_Logging_Project_Presentation.ppt&amp;diff=75112"/>
				<updated>2009-12-13T22:43:03Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=69929</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=69929"/>
				<updated>2009-09-28T14:30:56Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [[:Category:OWASP Logging Project - Roadmap|Roadmap]] &lt;br /&gt;
&lt;br /&gt;
[[Image:Owasp_Logging_Project_Roadmap.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP Logging Guide.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Goals  ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Provide tools for software developers in order to help them define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps) &lt;br /&gt;
&lt;br /&gt;
Facilitate the integration of logs from different sources &lt;br /&gt;
&lt;br /&gt;
Facilitate attack reconstruction &lt;br /&gt;
&lt;br /&gt;
Facilitate information sharing around security events&lt;br /&gt;
&lt;br /&gt;
== Existing tools and use cases  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''1) IDE integration''' (auto-completion, templates, logging policy definition support) for guiding software developers to define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
For example, a template can provide checks/hints/defaults s.a. those defined by the OWASP Enterprise Security API :&amp;lt;br&amp;gt;- something equivalent to a generated logging session ID, or a hashed value of the session ID so they can track session specific events without risking the exposure of a live session's ID&amp;lt;br&amp;gt;- identity of the user that caused the event&amp;lt;br&amp;gt;- description of the event (supplied by the caller)&amp;lt;br&amp;gt;- whether the event succeeded or failed (indicated by the caller)&amp;lt;br&amp;gt;- severity level of the event (indicated by the caller)&amp;lt;br&amp;gt;- that this is a security relevant event (indicated by the caller)&amp;lt;br&amp;gt;- hostname or IP where the event occurred (and ideally the user's source IP as well)&amp;lt;br&amp;gt;- a time stamp &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''IDE templates'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/File:Eclipse_Create_Template.png&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/File:NetBeans_Create_Live_Template.png&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://wiki.netbeans.org/Java_EditorUsersGuide&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''OWASP ESAPI Logger''' interface (Logger.java) and implementations&amp;lt;br&amp;gt;http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''2/ Code audit tools''' s.a. OWASP yasca can be easily adapted in order to ensure that logging standards are respected and that log messages are consistent and complete (content, format, timestamps)&amp;lt;br&amp;gt;See http://www.owasp.org/index.php/Category:OWASP_Yasca_Project&amp;lt;br&amp;gt;Related OWASP projects: http://www.owasp.org/index.php/Category:OWASP_Orizon_Project &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''3) Integrating application logs into a Security Information Management configuration'''&amp;lt;br&amp;gt;OSSIM (http://www.ossim.net/) has numerous plugins for parsing webserver, appserver, WAF, IPS, IDS logs and generating/storing events in its standard format. &lt;br /&gt;
&lt;br /&gt;
Adding a plugin for parsing custom application logs is as easy as finding the correct regular expression provided that developers included all relevant information in the log message and that they have done so in a consistent way. &lt;br /&gt;
&lt;br /&gt;
You can refer to the OSSIM database model to see what data is stored for events. &lt;br /&gt;
&lt;br /&gt;
See http://www.owasp.org/index.php/File:OWASP_Logging_Guide.pdf for more details/screenshots on application event integration and correlation via OSSIM &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''4) Reconstructing attacks'''&amp;lt;br&amp;gt;It is difficult to analyze, filter and generally reconstruct an attack because messages are spread around various log levels. &lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
Along the same lines, Arshan Dabirsiaghi's proposal of adding a security log level is very interesting&amp;lt;br&amp;gt;http://www.owasp.org/index.php/How_to_add_a_security_log_level_in_log4j &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''5) Implement scripts for filtering/scrubbing logs in order to enable log data sharing between organizations'''&amp;lt;br&amp;gt;Goal: information sharing around security events&amp;lt;br&amp;gt;Custom logger implementations based on the OWASP ESAPI might also filter out any sensitive data specific to the current application or organization, such as credit cards, social security numbers etc. &lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;See http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
          *** We need your efforts and contribution to this project ***&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Project Identification ====&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] &lt;br /&gt;
[[Category:OWASP_Document]] &lt;br /&gt;
[[Category:OWASP_Alpha_Quality_Document]]&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Logging Project&lt;br /&gt;
| project_description = The goals of this project are:&lt;br /&gt;
* Provide tools for software developers in order to help them define and provide meaningful logs&lt;br /&gt;
* Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps)&lt;br /&gt;
* Facilitate the integration of logs from different sources&lt;br /&gt;
* Facilitate attack reconstruction&lt;br /&gt;
* Facilitate information sharing around security events&lt;br /&gt;
| leader_name = Marc Chisinevski&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Marc_Chisinevski&lt;br /&gt;
| maintainer_name = Marc Chisinevski&lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = Marc_Chisinevski&lt;br /&gt;
| contributor_name1 = Marc Chisinevski&lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = Marc_Chisinevski&lt;br /&gt;
| contributor_name2 = Anthony Lai&lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = Sam Ng&lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-logging&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map = Category:OWASP_Logging_Project_-_Roadmap&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = First Release&lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=67897</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=67897"/>
				<updated>2009-08-23T09:47:51Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: /* Feedback and Participation: */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [http://www.owasp.org/index.php/Template:OWASP_Logging_Project [Roadmap]] . &lt;br /&gt;
&lt;br /&gt;
[[Image:Owasp_Logging_Project_Roadmap.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP Logging Guide.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Goals  ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Provide tools for software developers in order to help them define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps) &lt;br /&gt;
&lt;br /&gt;
Facilitate the integration of logs from different sources &lt;br /&gt;
&lt;br /&gt;
Facilitate attack reconstruction &lt;br /&gt;
&lt;br /&gt;
Facilitate information sharing around security events&lt;br /&gt;
&lt;br /&gt;
== Existing tools and use cases  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''1) IDE integration''' (auto-completion, templates, logging policy definition support) for guiding software developers to define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
For example, a template can provide checks/hints/defaults s.a. those defined by the OWASP Enterprise Security API :&amp;lt;br&amp;gt;- something equivalent to a generated logging session ID, or a hashed value of the session ID so they can track session specific events without risking the exposure of a live session's ID&amp;lt;br&amp;gt;- identity of the user that caused the event&amp;lt;br&amp;gt;- description of the event (supplied by the caller)&amp;lt;br&amp;gt;- whether the event succeeded or failed (indicated by the caller)&amp;lt;br&amp;gt;- severity level of the event (indicated by the caller)&amp;lt;br&amp;gt;- that this is a security relevant event (indicated by the caller)&amp;lt;br&amp;gt;- hostname or IP where the event occurred (and ideally the user's source IP as well)&amp;lt;br&amp;gt;- a time stamp &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''IDE templates'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/File:Eclipse_Create_Template.png&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/File:NetBeans_Create_Live_Template.png&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://wiki.netbeans.org/Java_EditorUsersGuide&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''OWASP ESAPI Logger''' interface (Logger.java) and implementations&amp;lt;br&amp;gt;http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''2/ Code audit tools''' s.a. OWASP yasca can be easily adapted in order to ensure that logging standards are respected and that log messages are consistent and complete (content, format, timestamps)&amp;lt;br&amp;gt;See http://www.owasp.org/index.php/Category:OWASP_Yasca_Project&amp;lt;br&amp;gt;Related OWASP projects: http://www.owasp.org/index.php/Category:OWASP_Orizon_Project &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''3) Integrating application logs into a Security Information Management configuration'''&amp;lt;br&amp;gt;OSSIM (http://www.ossim.net/) has numerous plugins for parsing webserver, appserver, WAF, IPS, IDS logs and generating/storing events in its standard format. &lt;br /&gt;
&lt;br /&gt;
Adding a plugin for parsing custom application logs is as easy as finding the correct regular expression provided that developers included all relevant information in the log message and that they have done so in a consistent way. &lt;br /&gt;
&lt;br /&gt;
You can refer to the OSSIM database model to see what data is stored for events. &lt;br /&gt;
&lt;br /&gt;
See http://www.owasp.org/index.php/File:OWASP_Logging_Guide.pdf for more details/screenshots on application event integration and correlation via OSSIM &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''4) Reconstructing attacks'''&amp;lt;br&amp;gt;It is difficult to analyze, filter and generally reconstruct an attack because messages are spread around various log levels. &lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
Along the same lines, Arshan Dabirsiaghi's proposal of adding a security log level is very interesting&amp;lt;br&amp;gt;http://www.owasp.org/index.php/How_to_add_a_security_log_level_in_log4j &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''5) Implement scripts for filtering/scrubbing logs in order to enable log data sharing between organizations'''&amp;lt;br&amp;gt;Goal: information sharing around security events&amp;lt;br&amp;gt;Custom logger implementations based on the OWASP ESAPI might also filter out any sensitive data specific to the current application or organization, such as credit cards, social security numbers etc. &lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;See http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
          *** We need your efforts and contribution to this project ***&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project Identification (Under work)  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: '''Marc Chisinevski'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Logging Project}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=67372</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=67372"/>
				<updated>2009-08-07T13:29:47Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [http://www.owasp.org/index.php/Template:OWASP_Logging_Project [Roadmap]] . &lt;br /&gt;
&lt;br /&gt;
[[Image:Owasp_Logging_Project_Roadmap.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP Logging Guide.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Goals  ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Provide tools for software developers in order to help them define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps) &lt;br /&gt;
&lt;br /&gt;
Facilitate the integration of logs from different sources &lt;br /&gt;
&lt;br /&gt;
Facilitate attack reconstruction &lt;br /&gt;
&lt;br /&gt;
Facilitate information sharing around security events&lt;br /&gt;
&lt;br /&gt;
== Existing tools and use cases  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''1) IDE integration''' (auto-completion, templates, logging policy definition support) for guiding software developers to define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
For example, a template can provide checks/hints/defaults s.a. those defined by the OWASP Enterprise Security API :&amp;lt;br&amp;gt;- something equivalent to a generated logging session ID, or a hashed value of the session ID so they can track session specific events without risking the exposure of a live session's ID&amp;lt;br&amp;gt;- identity of the user that caused the event&amp;lt;br&amp;gt;- description of the event (supplied by the caller)&amp;lt;br&amp;gt;- whether the event succeeded or failed (indicated by the caller)&amp;lt;br&amp;gt;- severity level of the event (indicated by the caller)&amp;lt;br&amp;gt;- that this is a security relevant event (indicated by the caller)&amp;lt;br&amp;gt;- hostname or IP where the event occurred (and ideally the user's source IP as well)&amp;lt;br&amp;gt;- a time stamp &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''IDE templates'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/File:Eclipse_Create_Template.png&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/File:NetBeans_Create_Live_Template.png&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://wiki.netbeans.org/Java_EditorUsersGuide&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''OWASP ESAPI Logger''' interface (Logger.java) and implementations&amp;lt;br&amp;gt;http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''2/ Code audit tools''' s.a. OWASP yasca can be easily adapted in order to ensure that logging standards are respected and that log messages are consistent and complete (content, format, timestamps)&amp;lt;br&amp;gt;See http://www.owasp.org/index.php/Category:OWASP_Yasca_Project&amp;lt;br&amp;gt;Related OWASP projects: http://www.owasp.org/index.php/Category:OWASP_Orizon_Project &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''3) Integrating application logs into a Security Information Management configuration'''&amp;lt;br&amp;gt;OSSIM (http://www.ossim.net/) has numerous plugins for parsing webserver, appserver, WAF, IPS, IDS logs and generating/storing events in its standard format. &lt;br /&gt;
&lt;br /&gt;
Adding a plugin for parsing custom application logs is as easy as finding the correct regular expression provided that developers included all relevant information in the log message and that they have done so in a consistent way. &lt;br /&gt;
&lt;br /&gt;
You can refer to the OSSIM database model to see what data is stored for events. &lt;br /&gt;
&lt;br /&gt;
See http://www.owasp.org/index.php/File:OWASP_Logging_Guide.pdf for more details/screenshots on application event integration and correlation via OSSIM &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''4) Reconstructing attacks'''&amp;lt;br&amp;gt;It is difficult to analyze, filter and generally reconstruct an attack because messages are spread around various log levels. &lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
Along the same lines, Arshan Dabirsiaghi's proposal of adding a security log level is very interesting&amp;lt;br&amp;gt;http://www.owasp.org/index.php/How_to_add_a_security_log_level_in_log4j &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''5) Implement scripts for filtering/scrubbing logs in order to enable log data sharing between organizations'''&amp;lt;br&amp;gt;Goal: information sharing around security events&amp;lt;br&amp;gt;Custom logger implementations based on the OWASP ESAPI might also filter out any sensitive data specific to the current application or organization, such as credit cards, social security numbers etc. &lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;See http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
          *** We need your efforts and contribution to this project ***&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions to owasp@owasp.org. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project Identification (Under work)  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: '''Marc Chisinevski'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Logging Project}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:OWASP_Logging_Guide.pdf&amp;diff=67371</id>
		<title>File:OWASP Logging Guide.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:OWASP_Logging_Guide.pdf&amp;diff=67371"/>
				<updated>2009-08-07T13:16:43Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: uploaded a new version of &amp;quot;File:OWASP Logging Guide.pdf&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The OWASP Logging Guide tries to answer the following questions:&lt;br /&gt;
Why log ?&lt;br /&gt;
What is commonly logged ? &lt;br /&gt;
What are security logs ? &lt;br /&gt;
What are the most common issues with logging ?  &lt;br /&gt;
What are the common functions of a log management infrastructure ? &lt;br /&gt;
How to plan a logging infrastructure ?  &lt;br /&gt;
What is log management ? &lt;br /&gt;
What application logs/events to monitor ?  &lt;br /&gt;
Application logs and Security Information Management systems  &lt;br /&gt;
   Case study - OSSIM (Open Source Security Information Management system)&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=67369</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=67369"/>
				<updated>2009-08-07T13:05:05Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [http://www.owasp.org/index.php/Template:OWASP_Logging_Project [Roadmap]] . &lt;br /&gt;
&lt;br /&gt;
[[Image:Owasp_Logging_Project_Roadmap.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP Logging Guide.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Goals  ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Provide tools for software developers in order to help them define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps) &lt;br /&gt;
&lt;br /&gt;
Facilitate the integration of logs from different sources &lt;br /&gt;
&lt;br /&gt;
Facilitate attack reconstruction &lt;br /&gt;
&lt;br /&gt;
Facilitate information sharing around security events&lt;br /&gt;
&lt;br /&gt;
== Existing tools and use cases  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''1) IDE integration''' (auto-completion, templates, logging policy definition support) for guiding software developers to define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''IDE templates'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/File:Eclipse_Create_Template.png&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/File:NetBeans_Create_Live_Template.png&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
http://wiki.netbeans.org/Java_EditorUsersGuide&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''OWASP ESAPI Logger''' interface (Logger.java) and implementations&amp;lt;br&amp;gt;http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;For example, a template can provide checks/hints/defaults s.a. those defined by the OWASP Enterprise Security API&amp;amp;nbsp;:&amp;lt;br&amp;gt;- something equivalent to a generated logging session ID, or a hashed value of the session ID so they can track session specific events without risking the exposure of a live session's ID&amp;lt;br&amp;gt;- identity of the user that caused the event&amp;lt;br&amp;gt;- description of the event (supplied by the caller)&amp;lt;br&amp;gt;- whether the event succeeded or failed (indicated by the caller)&amp;lt;br&amp;gt;- severity level of the event (indicated by the caller)&amp;lt;br&amp;gt;- that this is a security relevant event (indicated by the caller)&amp;lt;br&amp;gt;- hostname or IP where the event occurred (and ideally the user's source IP as well)&amp;lt;br&amp;gt;- a time stamp &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''2/ Code audit tools''' s.a. OWASP yasca can be easily adapted in order to ensure that logging standards are respected and that log messages are consistent and complete (content, format, timestamps)&amp;lt;br&amp;gt;See http://www.owasp.org/index.php/Category:OWASP_Yasca_Project&amp;lt;br&amp;gt;Related OWASP projects: http://www.owasp.org/index.php/Category:OWASP_Orizon_Project &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''3) Integrating application logs into a Security Information Management configuration'''&amp;lt;br&amp;gt;OSSIM (http://www.ossim.net/) has numerous plugins for parsing webserver, appserver, WAF, IPS, IDS logs and generating/storing events in its standard format. &lt;br /&gt;
&lt;br /&gt;
Adding a plugin for parsing custom application logs is as easy as finding the correct regular expression provided that developers included all relevant information in the log message and that they have done so in a consistent way. &lt;br /&gt;
&lt;br /&gt;
You can refer to the OSSIM database model to see what data is stored for events. &lt;br /&gt;
&lt;br /&gt;
See http://www.owasp.org/index.php/File:OWASP_Logging_Guide.pdf for more details/screenshots on application event integration and correlation via OSSIM &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''4) Reconstructing attacks'''&amp;lt;br&amp;gt;It is difficult to analyze, filter and generally reconstruct an attack because messages are spread around various log levels. &lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
Along the same lines, Arshan Dabirsiaghi's proposal of adding a security log level is very interesting&amp;lt;br&amp;gt;http://www.owasp.org/index.php/How_to_add_a_security_log_level_in_log4j &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''5) Implement scripts for filtering/scrubbing logs in order to enable log data sharing between organizations'''&amp;lt;br&amp;gt;Goal: information sharing around security events&amp;lt;br&amp;gt;Custom logger implementations based on the OWASP ESAPI might also filter out any sensitive data specific to the current application or organization, such as credit cards, social security numbers etc. &lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;See http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
          *** We need your efforts and contribution to this project ***&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions to owasp@owasp.org. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project Identification (Under work)  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: '''Marc Chisinevski'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Logging Project}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=67368</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=67368"/>
				<updated>2009-08-07T13:02:49Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [http://www.owasp.org/index.php/Template:OWASP_Logging_Project [Roadmap]] . &lt;br /&gt;
&lt;br /&gt;
[[Image:Owasp_Logging_Project_Roadmap.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP Logging Guide.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Goals  ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Provide tools for software developers in order to help them define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps) &lt;br /&gt;
&lt;br /&gt;
Facilitate the integration of logs from different sources &lt;br /&gt;
&lt;br /&gt;
Facilitate attack reconstruction &lt;br /&gt;
&lt;br /&gt;
Facilitate information sharing around security events&lt;br /&gt;
&lt;br /&gt;
== Existing tools and use cases  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''1) IDE integration''' (auto-completion, templates, logging policy definition support) for guiding software developers to define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''IDE templates'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/File:Eclipse_Create_Template.png&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/File:NetBeans_Create_Live_Template.png&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
http://wiki.netbeans.org/Java_EditorUsersGuide&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''OWASP ESAPI Logger''' interface (Logger.java) and implementations&amp;lt;br&amp;gt;http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;For example, a template can provide checks/hints/defaults s.a. those defined by the OWASP Enterprise Security API&amp;amp;nbsp;:&amp;lt;br&amp;gt;- something equivalent to a generated logging session ID, or a hashed value of the session ID so they can track session specific events without risking the exposure of a live session's ID&amp;lt;br&amp;gt;- identity of the user that caused the event&amp;lt;br&amp;gt;- description of the event (supplied by the caller)&amp;lt;br&amp;gt;- whether the event succeeded or failed (indicated by the caller)&amp;lt;br&amp;gt;- severity level of the event (indicated by the caller)&amp;lt;br&amp;gt;- that this is a security relevant event (indicated by the caller)&amp;lt;br&amp;gt;- hostname or IP where the event occurred (and ideally the user's source IP as well)&amp;lt;br&amp;gt;- a time stamp &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''2/ Code audit tools''' s.a. OWASP yasca can be easily adapted in order to ensure that logging standards are respected and that log messages are consistent and complete (content, format, timestamps)&amp;lt;br&amp;gt;See http://www.owasp.org/index.php/Category:OWASP_Yasca_Project&amp;lt;br&amp;gt;Related OWASP projects: http://www.owasp.org/index.php/Category:OWASP_Orizon_Project &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''3) Integrating application logs into a Security Information Management configuration'''&amp;lt;br&amp;gt;OSSIM (http://www.ossim.net/) has numerous plugins for parsing webserver, appserver, WAF, IPS, IDS logs and generating/storing events in its standard format. &lt;br /&gt;
&lt;br /&gt;
Adding a plugin for parsing custom application logs is as easy as finding the correct regular expression provided that developers included all relevant information in the log message and that they have done so in a consistent way. &lt;br /&gt;
&lt;br /&gt;
You can refer to the OSSIM database model to see what data is stored for events. &lt;br /&gt;
&lt;br /&gt;
See http://www.owasp.org/index.php/File:OWASP_Logging_Guide.pdf for more details/screenshots on application event integration and correlation via OSSIM &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''4) Reconstructing attacks'''&amp;lt;br&amp;gt;It is difficult to analyze, filter and generally reconstruct an attack because messages are spread around various log levels. &lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
Along the same lines, Arshan Dabirsiaghi's proposal of adding a security log level is very interesting&amp;lt;br&amp;gt;http://www.owasp.org/index.php/How_to_add_a_security_log_level_in_log4j &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''5) Implement scripts for filtering/scrubbing logs in order to enable log data sharing between organizations'''&amp;lt;br&amp;gt;Goal: information sharing around security events&amp;lt;br&amp;gt;Custom logger implementations based on the OWASP ESAPI might also filter out any sensitive data specific to the current application or organization, such as credit cards, social security numbers etc. &lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;See http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
          *** We need your efforts and contribution to this project ***&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions to owasp@owasp.org. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project Identification (Under work)  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: '''Marc Chisinevski'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Logging Project}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=67367</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=67367"/>
				<updated>2009-08-07T13:01:42Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: /* Existing tools and use cases */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [http://www.owasp.org/index.php/Template:OWASP_Logging_Project [Roadmap]] . &lt;br /&gt;
&lt;br /&gt;
[[Image:Owasp_Logging_Project_Roadmap.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP Logging Guide.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Goals  ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Provide tools for software developers in order to help them define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps) &lt;br /&gt;
&lt;br /&gt;
Facilitate the integration of logs from different sources &lt;br /&gt;
&lt;br /&gt;
Facilitate attack reconstruction &lt;br /&gt;
&lt;br /&gt;
Facilitate information sharing around security events &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Existing tools and use cases  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''1) IDE integration''' (auto-completion, templates, logging policy definition support) for guiding software developers to define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''IDE templates'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/File:Eclipse_Create_Template.png&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/File:NetBeans_Create_Live_Template.png&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
http://wiki.netbeans.org/Java_EditorUsersGuide&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''OWASP ESAPI Logger''' interface (Logger.java) and implementations&amp;lt;br&amp;gt;http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;For example, a template can provide checks/hints/defaults s.a. those defined by the OWASP Enterprise Security API&amp;amp;nbsp;:&amp;lt;br&amp;gt;- something equivalent to a generated logging session ID, or a hashed value of the session ID so they can track session specific events without risking the exposure of a live session's ID&amp;lt;br&amp;gt;- identity of the user that caused the event&amp;lt;br&amp;gt;- description of the event (supplied by the caller)&amp;lt;br&amp;gt;- whether the event succeeded or failed (indicated by the caller)&amp;lt;br&amp;gt;- severity level of the event (indicated by the caller)&amp;lt;br&amp;gt;- that this is a security relevant event (indicated by the caller)&amp;lt;br&amp;gt;- hostname or IP where the event occurred (and ideally the user's source IP as well)&amp;lt;br&amp;gt;- a time stamp &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''2/ Code audit tools''' s.a. OWASP yasca can be easily adapted in order to ensure that logging standards are respected and that log messages are consistent and complete (content, format, timestamps)&amp;lt;br&amp;gt;See http://www.owasp.org/index.php/Category:OWASP_Yasca_Project&amp;lt;br&amp;gt;Related OWASP projects: http://www.owasp.org/index.php/Category:OWASP_Orizon_Project &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''3) Integrating application logs into a Security Information Management configuration'''&amp;lt;br&amp;gt;OSSIM (http://www.ossim.net/) has numerous plugins for parsing webserver, appserver, WAF, IPS, IDS logs and generating/storing events in its standard format. &lt;br /&gt;
&lt;br /&gt;
Adding a plugin for parsing custom application logs is as easy as finding the correct regular expression provided that developers included all relevant information in the log message and that they have done so in a consistent way. &lt;br /&gt;
&lt;br /&gt;
You can refer to the OSSIM database model to see what data is stored for events. &lt;br /&gt;
&lt;br /&gt;
See http://www.owasp.org/index.php/File:OWASP_Logging_Guide.pdf for more details/screenshots on application event integration and correlation via OSSIM &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''4) Reconstructing attacks'''&amp;lt;br&amp;gt;It is difficult to analyze, filter and generally reconstruct an attack because messages are spread around various log levels. &lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
Along the same lines, Arshan Dabirsiaghi's proposal of adding a security log level is very interesting&amp;lt;br&amp;gt;http://www.owasp.org/index.php/How_to_add_a_security_log_level_in_log4j &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''5) Implement scripts for filtering/scrubbing logs in order to enable log data sharing between organizations'''&amp;lt;br&amp;gt;Goal: information sharing around security events&amp;lt;br&amp;gt;Custom logger implementations based on the OWASP ESAPI might also filter out any sensitive data specific to the current application or organization, such as credit cards, social security numbers etc. &lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;See http://code.google.com/p/owasp-esapi-java/downloads/list &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
          *** We need your efforts and contribution to this project ***&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions to owasp@owasp.org. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project Identification (Under work)  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: '''Marc Chisinevski'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Logging Project}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:NetBeans_Create_Live_Template.png&amp;diff=67366</id>
		<title>File:NetBeans Create Live Template.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:NetBeans_Create_Live_Template.png&amp;diff=67366"/>
				<updated>2009-08-07T13:00:39Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: NetBeans template&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;NetBeans template&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Eclipse_Create_Template.png&amp;diff=67365</id>
		<title>File:Eclipse Create Template.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Eclipse_Create_Template.png&amp;diff=67365"/>
				<updated>2009-08-07T12:58:21Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: Eclipse template&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Eclipse template&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=67364</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=67364"/>
				<updated>2009-08-07T12:53:15Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: /* Goals */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [http://www.owasp.org/index.php/Template:OWASP_Logging_Project [Roadmap]] . &lt;br /&gt;
&lt;br /&gt;
[[Image:Owasp_Logging_Project_Roadmap.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP Logging Guide.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Goals  ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Provide tools for software developers in order to help them define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps) &lt;br /&gt;
&lt;br /&gt;
Facilitate the integration of logs from different sources &lt;br /&gt;
&lt;br /&gt;
Facilitate attack reconstruction &lt;br /&gt;
&lt;br /&gt;
Facilitate information sharing around security events &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Existing tools and use cases ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''1) IDE integration''' (auto-completion, templates, logging policy definition support) for guiding software developers to define and provide meaningful logs&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''IDE templates''' (Eclipse and NetBeans examples below) helping developers remember to log all necessary information while avoiding too much typing.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''OWASP ESAPI Logger''' interface (Logger.java) and implementations&amp;lt;br&amp;gt;http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;For example, a template can provide checks/hints/defaults s.a. those defined by the OWASP Enterprise Security API :&amp;lt;br&amp;gt;- something equivalent to a generated logging session ID, or a hashed value of the session ID so they can track session specific events without risking the exposure of a live session's ID&amp;lt;br&amp;gt;- identity of the user that caused the event&amp;lt;br&amp;gt;- description of the event (supplied by the caller)&amp;lt;br&amp;gt;- whether the event succeeded or failed (indicated by the caller)&amp;lt;br&amp;gt;- severity level of the event (indicated by the caller)&amp;lt;br&amp;gt;- that this is a security relevant event (indicated by the caller)&amp;lt;br&amp;gt;- hostname or IP where the event occurred (and ideally the user's source IP as well)&amp;lt;br&amp;gt;- a time stamp&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''2/ Code audit tools''' s.a. OWASP yasca can be easily adapted in order to ensure that logging standards are respected and that log messages are consistent and complete (content, format, timestamps)&amp;lt;br&amp;gt;See http://www.owasp.org/index.php/Category:OWASP_Yasca_Project&amp;lt;br&amp;gt;Related OWASP projects: http://www.owasp.org/index.php/Category:OWASP_Orizon_Project&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''3) Integrating application logs into a Security Information Management configuration'''&amp;lt;br&amp;gt;OSSIM (http://www.ossim.net/) has numerous plugins for parsing webserver, appserver, WAF, IPS, IDS logs and generating/storing events in its standard format.&lt;br /&gt;
&lt;br /&gt;
Adding a plugin for parsing custom application logs is as easy as finding the correct regular expression provided that developers included all relevant information in the log message and that they have done so in a consistent way.&lt;br /&gt;
&lt;br /&gt;
You can refer to the OSSIM database model to see what data is stored for events.&lt;br /&gt;
&lt;br /&gt;
See http://www.owasp.org/index.php/File:OWASP_Logging_Guide.pdf for more details/screenshots on application event integration and correlation via OSSIM&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''4) Reconstructing attacks'''&amp;lt;br&amp;gt;It is difficult to analyze, filter and generally reconstruct an attack because messages are spread around various log levels.&lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;http://code.google.com/p/owasp-esapi-java/downloads/list&lt;br /&gt;
&lt;br /&gt;
Along the same lines, Arshan Dabirsiaghi's proposal of adding a security log level is very interesting&amp;lt;br&amp;gt;http://www.owasp.org/index.php/How_to_add_a_security_log_level_in_log4j&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;'''5) Implement scripts for filtering/scrubbing logs in order to enable log data sharing between organizations'''&amp;lt;br&amp;gt;Goal: information sharing around security events&amp;lt;br&amp;gt;Custom logger implementations based on the OWASP ESAPI might also filter out any sensitive data specific to the current application or organization, such as credit cards, social security numbers etc.&lt;br /&gt;
&lt;br /&gt;
See the Logging part of the OWASP ESAPI project&amp;lt;br&amp;gt;See http://code.google.com/p/owasp-esapi-java/downloads/list&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;span style=&amp;quot;font-weight: bold;&amp;quot; /&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
          *** We need your efforts and contribution to this project ***&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions to owasp@owasp.org. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project Identification (Under work)  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: '''Marc Chisinevski'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Logging Project}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66621</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66621"/>
				<updated>2009-07-27T10:26:05Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [http://www.owasp.org/index.php/Template:OWASP_Logging_Project [Roadmap]] . &lt;br /&gt;
&lt;br /&gt;
[[Image:Owasp_Logging_Project_Roadmap.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP Logging Guide.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Goals  ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Provide tools for software developers in order to help them define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps) &lt;br /&gt;
&lt;br /&gt;
Facilitate the integration of logs from different sources &lt;br /&gt;
&lt;br /&gt;
Facilitate attack reconstruction &lt;br /&gt;
&lt;br /&gt;
Facilitate information sharing around security events &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
          *** We need your efforts and contribution to this project ***&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions to owasp@owasp.org. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project Identification (Under work)  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: '''Marc Chisinevski'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Logging Project}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66620</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66620"/>
				<updated>2009-07-27T10:25:29Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [http://www.owasp.org/index.php/Template:OWASP_Logging_Project [Roadmap]] . &lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP_Logging_Project_Roadmap.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP Logging Guide.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Goals  ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Provide tools for software developers in order to help them define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps) &lt;br /&gt;
&lt;br /&gt;
Facilitate the integration of logs from different sources &lt;br /&gt;
&lt;br /&gt;
Facilitate attack reconstruction &lt;br /&gt;
&lt;br /&gt;
Facilitate information sharing around security events &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
          *** We need your efforts and contribution to this project ***&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions to owasp@owasp.org. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project Identification (Under work)  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: '''Marc Chisinevski'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Logging Project}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66619</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66619"/>
				<updated>2009-07-27T10:23:56Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [http://www.owasp.org/index.php/Template:OWASP_Logging_Project [Roadmap]] . &lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP Logging Project Roadmap.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP Logging Guide.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Goals  ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Provide tools for software developers in order to help them define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps) &lt;br /&gt;
&lt;br /&gt;
Facilitate the integration of logs from different sources &lt;br /&gt;
&lt;br /&gt;
Facilitate attack reconstruction &lt;br /&gt;
&lt;br /&gt;
Facilitate information sharing around security events &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
          *** We need your efforts and contribution to this project ***&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions to owasp@owasp.org. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project Identification (Under work)  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: '''Marc Chisinevski'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Logging Project}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66618</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66618"/>
				<updated>2009-07-27T10:21:01Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [http://www.owasp.org/index.php/Template:OWASP_Logging_Project [Roadmap]] . &lt;br /&gt;
&lt;br /&gt;
[[File:OWASP Logging Guide.pdf]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Goals  ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Provide tools for software developers in order to help them define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps) &lt;br /&gt;
&lt;br /&gt;
Facilitate the integration of logs from different sources &lt;br /&gt;
&lt;br /&gt;
Facilitate attack reconstruction &lt;br /&gt;
&lt;br /&gt;
Facilitate information sharing around security events &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
          *** We need your efforts and contribution to this project ***&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions to owasp@owasp.org. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project Identification (Under work)  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: '''Marc Chisinevski'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Logging Project}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:OWASP_Logging_Guide.pdf&amp;diff=66617</id>
		<title>File:OWASP Logging Guide.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:OWASP_Logging_Guide.pdf&amp;diff=66617"/>
				<updated>2009-07-27T10:11:39Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: The OWASP Logging Guide tries to answer the following questions:
Why log ?
What is commonly logged ? 
What are security logs ? 
What are the most common issues with logging ?  
What are the common functions of a log management infrastructure ? 
How to pla&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The OWASP Logging Guide tries to answer the following questions:&lt;br /&gt;
Why log ?&lt;br /&gt;
What is commonly logged ? &lt;br /&gt;
What are security logs ? &lt;br /&gt;
What are the most common issues with logging ?  &lt;br /&gt;
What are the common functions of a log management infrastructure ? &lt;br /&gt;
How to plan a logging infrastructure ?  &lt;br /&gt;
What is log management ? &lt;br /&gt;
What application logs/events to monitor ?  &lt;br /&gt;
Application logs and Security Information Management systems  &lt;br /&gt;
   Case study - OSSIM (Open Source Security Information Management system)&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Owasp_Logging_Project_Roadmap.pdf&amp;diff=66616</id>
		<title>File:Owasp Logging Project Roadmap.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Owasp_Logging_Project_Roadmap.pdf&amp;diff=66616"/>
				<updated>2009-07-27T10:08:21Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: This document describes:

- the goals of the OWASP Logging Project (http://www.owasp.org/index.php/Category:OWASP_Logging_Project) and

- the subprojects that have been launched to attain these objectives&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This document describes:&lt;br /&gt;
&lt;br /&gt;
- the goals of the OWASP Logging Project (http://www.owasp.org/index.php/Category:OWASP_Logging_Project) and&lt;br /&gt;
&lt;br /&gt;
- the subprojects that have been launched to attain these objectives&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Marc_Chisinevski&amp;diff=66615</id>
		<title>User:Marc Chisinevski</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Marc_Chisinevski&amp;diff=66615"/>
				<updated>2009-07-27T09:40:56Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Marc Chisinevski has worked in web application development and security since 2000. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Outside his current position as security manager, he is the project lead for the [[:Category:OWASP_Logging_Project|OWASP Logging Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
He is a Certified Information System Security Professional (CISSP).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For more detailed information, please see my public LinkedIn [http://www.linkedin.com/pub/marc-chisinevski-cissp/4/ba7/358 page].&lt;br /&gt;
&lt;br /&gt;
* Other opensource projects: Asset, inventory and risk management at http://sourceforge.net/projects/assetmng/ &lt;br /&gt;
* To see my wiki contributions, [[:Special:Contributions/Marc Chisinevski|click here]].&lt;br /&gt;
* [mailto:marc.chisinevski@gmail.com Email address].&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Marc_Chisinevski&amp;diff=66614</id>
		<title>User:Marc Chisinevski</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Marc_Chisinevski&amp;diff=66614"/>
				<updated>2009-07-27T09:32:29Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Marc Chisinevski has worked in web application development and security since 2000. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Outside his current position as security manager, he is the project lead for the [[:Category:OWASP_Logging_Project|OWASP Logging Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
He is a Certified Information System Security Professional (CISSP).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For more detailed information, please see my public LinkedIn [http://www.linkedin.com/pub/marc-chisinevski-cissp/4/ba7/358 page].&lt;br /&gt;
&lt;br /&gt;
* To see my wiki contributions, [[:Special:Contributions/Marc Chisinevski|click here]].&lt;br /&gt;
* [mailto:marc.chisinevski@gmail.com Email address].&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:OWASP_Logging_Project_-_A&amp;diff=66613</id>
		<title>Template:OWASP Logging Project - A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:OWASP_Logging_Project_-_A&amp;diff=66613"/>
				<updated>2009-07-27T09:25:57Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| width=&amp;quot;100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;left&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;&amp;lt;big&amp;gt;'''what'''&amp;lt;/big&amp;gt;&amp;lt;/font&amp;gt; &lt;br /&gt;
! align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(255, 255, 255) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; colspan=&amp;quot;1&amp;quot; | &amp;lt;small&amp;gt;''is this project?''&amp;lt;/small&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | &amp;lt;!--'''''Name:'''''&amp;lt;br /&amp;gt;--&amp;gt;'''OWASP Logging Project''' &lt;br /&gt;
'''''Purpose:'''''The goals of this project are: &lt;br /&gt;
&lt;br /&gt;
 Provide tools for software developers in order to help them define and provide meaningful logs&lt;br /&gt;
 Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps)&lt;br /&gt;
 Facilitate the integration of logs from different sources&lt;br /&gt;
 Facilitate attack reconstruction&lt;br /&gt;
 Facilitate information sharing around security events&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;&amp;lt;big&amp;gt;'''who'''&amp;lt;/big&amp;gt;&amp;lt;/font&amp;gt; &lt;br /&gt;
! align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(255, 255, 255) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; colspan=&amp;quot;1&amp;quot; | &amp;lt;small&amp;gt;''is working on this project?''&amp;lt;/small&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | '''''Project Leader:''''' [[User:Marc Chisinevski|Marc Chisinevski]]&amp;lt;br&amp;gt; &lt;br /&gt;
'''''Project Maintainer:''''' [[User:Marc Chisinevski|Marc Chisinevski]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''''Project Contributor(s):''''' [[:User:Marc Chisinevski|Marc Chisinevski]],''[[:User:Alai|Anthony Lai]], '' [[:User:Sng|Sam Ng]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;&amp;lt;big&amp;gt;'''how'''&amp;lt;/big&amp;gt;&amp;lt;/font&amp;gt; &lt;br /&gt;
! align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(255, 255, 255) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; colspan=&amp;quot;1&amp;quot; | &amp;lt;small&amp;gt;''can you learn more?''&amp;lt;/small&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | '''''Project Flyer/Pamphlet:''''' [] &lt;br /&gt;
'''''Mail list:''''' [https://lists.owasp.org/mailman/listinfo/owasp-logging-project Subscribe or read the archives] &lt;br /&gt;
&lt;br /&gt;
'''''Project Roadmap:''''' [[:Category:OWASP Logging Project - Roadmap|To view, click here]] &lt;br /&gt;
&lt;br /&gt;
'''''Project main links:''''' [[:Category:OWASP Logging Project|OWASP Logging Project]]; [] &lt;br /&gt;
&lt;br /&gt;
'''''Project Health:''''' [[Image:Yellow button.JPG|25px]] [[:Category:OWASP Logging Project Project Health - Assessment|Not reviewed/Targeted at Level 1]]&amp;lt;br&amp;gt; &amp;lt;small&amp;gt;''To be reviewed under [[:Assessing Project Health|Assessment Criteria v2.0]]''&amp;lt;/small&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background: rgb(204, 204, 255) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Key Contacts''' &lt;br /&gt;
! align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(255, 255, 255) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | &lt;br /&gt;
*Contact [[User:Marc Chisinevski|Project Leader]] to contribute to this project, &lt;br /&gt;
*Contact [[User:Marc Chisinevski|Project Leader]] or [[:Category:Global Projects Committee|GPC]] to review or sponsor this project, &lt;br /&gt;
*Contact [[:Category:Global Projects Committee|GPC]] to report a problem or concern about this project or to update information.&lt;br /&gt;
&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:OWASP_Logging_Project_-_A&amp;diff=66612</id>
		<title>Template:OWASP Logging Project - A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:OWASP_Logging_Project_-_A&amp;diff=66612"/>
				<updated>2009-07-27T09:24:45Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| width=&amp;quot;100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;left&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;&amp;lt;big&amp;gt;'''what'''&amp;lt;/big&amp;gt;&amp;lt;/font&amp;gt;&lt;br /&gt;
! align=&amp;quot;left&amp;quot; colspan=&amp;quot;1&amp;quot; style=&amp;quot;background: rgb(255, 255, 255) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;lt;small&amp;gt;''is this project?''&amp;lt;/small&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | &amp;lt;!--'''''Name:'''''&amp;lt;br /&amp;gt;--&amp;gt;'''OWASP Logging Project''' &lt;br /&gt;
'''''Purpose:'''''The goals of this project are: &lt;br /&gt;
&lt;br /&gt;
 Provide tools for software developers in order to help them define and provide meaningful logs&lt;br /&gt;
 Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps)&lt;br /&gt;
 Facilitate the integration of logs from different sources&lt;br /&gt;
 Facilitate attack reconstruction&lt;br /&gt;
 Facilitate information sharing around security events&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;&amp;lt;big&amp;gt;'''who'''&amp;lt;/big&amp;gt;&amp;lt;/font&amp;gt;&lt;br /&gt;
! align=&amp;quot;left&amp;quot; colspan=&amp;quot;1&amp;quot; style=&amp;quot;background: rgb(255, 255, 255) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;lt;small&amp;gt;''is working on this project?''&amp;lt;/small&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | '''''Project Leader:''''' [[User:Marc chisinevski|Marc Chisinevski]]&amp;lt;br&amp;gt; &lt;br /&gt;
'''''Project Maintainer:''''' [[User:Marc Chisinevski|Marc Chisinevski]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''''Project Contributor(s):''''' [[:User:Marc Chisinevski|Marc Chisinevski]],'' [[:User:Alai|Anthony Lai]], '' [[:User:Sng|Sam Ng]]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;&amp;lt;big&amp;gt;'''how'''&amp;lt;/big&amp;gt;&amp;lt;/font&amp;gt;&lt;br /&gt;
! align=&amp;quot;left&amp;quot; colspan=&amp;quot;1&amp;quot; style=&amp;quot;background: rgb(255, 255, 255) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;lt;small&amp;gt;''can you learn more?''&amp;lt;/small&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | '''''Project Flyer/Pamphlet:''''' [] &lt;br /&gt;
'''''Mail list:''''' [https://lists.owasp.org/mailman/listinfo/owasp-logging-project Subscribe or read the archives] &lt;br /&gt;
&lt;br /&gt;
'''''Project Roadmap:''''' [[:Category:OWASP Logging Project - Roadmap|To view, click here]] &lt;br /&gt;
&lt;br /&gt;
'''''Project main links:''''' [[:Category:OWASP Logging Project|OWASP Logging Project]]; [] &lt;br /&gt;
&lt;br /&gt;
'''''Project Health:''''' [[Image:Yellow button.JPG|25px]] [[:Category:OWASP Logging Project Project Health - Assessment|Not reviewed/Targeted at Level 1]]&amp;lt;br&amp;gt; &amp;lt;small&amp;gt;''To be reviewed under [[:Assessing Project Health|Assessment Criteria v2.0]]''&amp;lt;/small&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background: rgb(204, 204, 255) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Key Contacts''' &lt;br /&gt;
! align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(255, 255, 255) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | &lt;br /&gt;
*Contact [[User:Marc Chisinevski|Project Leader]] to contribute to this project, &lt;br /&gt;
*Contact [[User:Marc Chisinevski|Project Leader]] or [[:Category:Global Projects Committee|GPC]] to review or sponsor this project, &lt;br /&gt;
*Contact [[:Category:Global Projects Committee|GPC]] to report a problem or concern about this project or to update information.&lt;br /&gt;
&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66611</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66611"/>
				<updated>2009-07-27T09:12:24Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [http://www.owasp.org/index.php/Template:OWASP_Logging_Project [Roadmap]] . &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Goals  ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Provide tools for software developers in order to help them define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps) &lt;br /&gt;
&lt;br /&gt;
Facilitate the integration of logs from different sources &lt;br /&gt;
&lt;br /&gt;
Facilitate attack reconstruction &lt;br /&gt;
&lt;br /&gt;
Facilitate information sharing around security events &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
          *** We need your efforts and contribution to this project ***&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions to owasp@owasp.org. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Project Identification (Under work)  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: '''Marc Chisinevski'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Logging Project}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Logging_Project_Roadmap&amp;diff=66610</id>
		<title>OWASP Logging Project Roadmap</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Logging_Project_Roadmap&amp;diff=66610"/>
				<updated>2009-07-27T09:11:29Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The project's overall goal is to...&lt;br /&gt;
&lt;br /&gt;
  Provide practical guidance for developers and operations staff&lt;br /&gt;
  in securely creating, managing, and reviewing application logs&lt;br /&gt;
&lt;br /&gt;
In the near term, we are focused on the following tactical goals...&lt;br /&gt;
&lt;br /&gt;
# Log format and its standard with reference to global best practice including BS-7799:2005&lt;br /&gt;
# Log filtering and noise reduction&lt;br /&gt;
# Log review checklist, practice and process&lt;br /&gt;
# Identify various logging tool and providing &lt;br /&gt;
&lt;br /&gt;
Here are the current tasks defined to help us achieve these goals&lt;br /&gt;
&lt;br /&gt;
* Study loggging section in BS7799:2005&lt;br /&gt;
* Gather existing logs-related technologies and platform&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66609</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66609"/>
				<updated>2009-07-27T09:10:33Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [http://www.owasp.org/index.php/Template:OWASP_Logging_Project [Roadmap]] . &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Goals  ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Provide tools for software developers in order to help them define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps) &lt;br /&gt;
&lt;br /&gt;
Facilitate the integration of logs from different sources &lt;br /&gt;
&lt;br /&gt;
Facilitate attack reconstruction &lt;br /&gt;
&lt;br /&gt;
Facilitate information sharing around security events &lt;br /&gt;
&lt;br /&gt;
We need your efforts and contribution to this project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions to owasp@owasp.org. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Project Identification (Under work)  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: '''Marc Chisinevski'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Logging Project}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66608</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66608"/>
				<updated>2009-07-27T09:05:05Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [http://www.owasp.org/index.php/Template:OWASP_Logging_Project [Roadmap]] . &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Goals  ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Provide tools for software developers in order to help them define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps) &lt;br /&gt;
&lt;br /&gt;
Facilitate the integration of logs from different sources &lt;br /&gt;
&lt;br /&gt;
Facilitate attack reconstruction &lt;br /&gt;
&lt;br /&gt;
Facilitate information sharing around security events &lt;br /&gt;
&lt;br /&gt;
We need your efforts and contribution to this project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions to owasp@owasp.org. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
== News related to Logging:  ==&lt;br /&gt;
&lt;br /&gt;
== Other Resources and Practice:  ==&lt;br /&gt;
&lt;br /&gt;
*HARDENING WINDOWS TIPS - Audit event log to increase system security&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;http://searchwindowssecurity.techtarget.com/tip/0,289483,sid45_gci1116378,00.html&amp;lt;/u&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*Detecting hack attacks: Application logging is critical&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;http://searchnetworking.techtarget.com/tip/0,289483,sid7_gci1201090,00.html&amp;lt;/u&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project Identification (Under work)  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: '''Marc Chisinevski'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Logging Project}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66607</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66607"/>
				<updated>2009-07-27T09:00:08Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [http://www.owasp.org/index.php/Template:OWASP_Logging_Project [Roadmap]] . &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Goals  ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Provide tools for software developers in order to help them define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps) &lt;br /&gt;
&lt;br /&gt;
Facilitate the integration of logs from different sources &lt;br /&gt;
&lt;br /&gt;
Facilitate attack reconstruction &lt;br /&gt;
&lt;br /&gt;
Facilitate information sharing around security events &lt;br /&gt;
&lt;br /&gt;
We need your efforts and contribution to this project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions to owasp@owasp.org. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
== News related to Logging:  ==&lt;br /&gt;
&lt;br /&gt;
== Other Resources and Practice:  ==&lt;br /&gt;
&lt;br /&gt;
*HARDENING WINDOWS TIPS - Audit event log to increase system security&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;http://searchwindowssecurity.techtarget.com/tip/0,289483,sid45_gci1116378,00.html&amp;lt;/u&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*Detecting hack attacks: Application logging is critical&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;http://searchnetworking.techtarget.com/tip/0,289483,sid7_gci1201090,00.html&amp;lt;/u&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project Identification (Under work)  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: '''Marc Chisinevski'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Logging Project - GPC Tab}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66606</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66606"/>
				<updated>2009-07-27T08:58:45Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [http://www.owasp.org/index.php/Template:OWASP_Logging_Project] . &lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/Template:OWASP_Logging_Project &lt;br /&gt;
&lt;br /&gt;
== Goals  ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Provide tools for software developers in order to help them define and provide meaningful logs &lt;br /&gt;
&lt;br /&gt;
Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps) &lt;br /&gt;
&lt;br /&gt;
Facilitate the integration of logs from different sources &lt;br /&gt;
&lt;br /&gt;
Facilitate attack reconstruction &lt;br /&gt;
&lt;br /&gt;
Facilitate information sharing around security events &lt;br /&gt;
&lt;br /&gt;
We need your efforts and contribution to this project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions to owasp@owasp.org. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
== News related to Logging:  ==&lt;br /&gt;
&lt;br /&gt;
== Other Resources and Practice:  ==&lt;br /&gt;
&lt;br /&gt;
*HARDENING WINDOWS TIPS - Audit event log to increase system security&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;http://searchwindowssecurity.techtarget.com/tip/0,289483,sid45_gci1116378,00.html&amp;lt;/u&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*Detecting hack attacks: Application logging is critical&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;http://searchnetworking.techtarget.com/tip/0,289483,sid7_gci1201090,00.html&amp;lt;/u&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project Identification (Under work)  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: '''Marc Chisinevski'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Logging Project - GPC Tab}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66605</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66605"/>
				<updated>2009-07-27T08:56:14Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [[OWASP Logging Project Roadmap]] . &lt;br /&gt;
&lt;br /&gt;
== Goals ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Provide tools for software developers in order to help them define and provide meaningful logs&lt;br /&gt;
&lt;br /&gt;
Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps)&lt;br /&gt;
&lt;br /&gt;
Facilitate the integration of logs from different sources&lt;br /&gt;
&lt;br /&gt;
Facilitate attack reconstruction&lt;br /&gt;
&lt;br /&gt;
Facilitate information sharing around security events&lt;br /&gt;
&lt;br /&gt;
We need your efforts and contribution to this project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions to owasp@owasp.org. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
== News related to Logging:  ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Other Resources and Practice:  ==&lt;br /&gt;
&lt;br /&gt;
*HARDENING WINDOWS TIPS - Audit event log to increase system security&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;http://searchwindowssecurity.techtarget.com/tip/0,289483,sid45_gci1116378,00.html&amp;lt;/u&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*Detecting hack attacks: Application logging is critical&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;http://searchnetworking.techtarget.com/tip/0,289483,sid7_gci1201090,00.html&amp;lt;/u&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project Identification (Under work)  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: '''Marc Chisinevski'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Logging Project - GPC Tab}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66604</id>
		<title>Category:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project&amp;diff=66604"/>
				<updated>2009-07-27T08:53:46Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
The OWASP Logging Project [[OWASP Logging Project Roadmap]] . &lt;br /&gt;
&lt;br /&gt;
== Goals ==&lt;br /&gt;
&lt;br /&gt;
http://www.pisa.org.hk/event/eventlog-mgt.jpg &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
# Provide tools for software developers in order to help them define&lt;br /&gt;
and provide meaningful logs&lt;br /&gt;
# Provide code audit tools to ensure that log messages are&lt;br /&gt;
consistent and complete (content, format, timestamps)&lt;br /&gt;
# Facilitate the integration of logs from different sources&lt;br /&gt;
# Facilitate attack reconstruction&lt;br /&gt;
# Facilitate information sharing around security events&lt;br /&gt;
&lt;br /&gt;
We need your efforts and contribution to this project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation:  ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Logging Project useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions to owasp@owasp.org. To join the OWASP Logging Project mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-logging subscription page.] &lt;br /&gt;
&lt;br /&gt;
== News related to Logging:  ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Other Resources and Practice:  ==&lt;br /&gt;
&lt;br /&gt;
*HARDENING WINDOWS TIPS - Audit event log to increase system security&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;http://searchwindowssecurity.techtarget.com/tip/0,289483,sid45_gci1116378,00.html&amp;lt;/u&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*Detecting hack attacks: Application logging is critical&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;http://searchnetworking.techtarget.com/tip/0,289483,sid7_gci1201090,00.html&amp;lt;/u&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project Identification (Under work)  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: '''Marc Chisinevski'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Logging Project - GPC Tab}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Logging Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project_-_Roadmap&amp;diff=66603</id>
		<title>Category:OWASP Logging Project - Roadmap</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project_-_Roadmap&amp;diff=66603"/>
				<updated>2009-07-27T08:42:43Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== '''OWASP Logging Project Roadmap''' ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== '''Goals''' ===&lt;br /&gt;
&lt;br /&gt;
*Provide tools for software developers in order to help them define and provide meaningful logs &lt;br /&gt;
*Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps) &amp;lt;br&amp;gt;&lt;br /&gt;
*Facilitate the integration of logs from different sources &amp;lt;br&amp;gt;&lt;br /&gt;
*Facilitate attack reconstruction &amp;lt;br&amp;gt;&lt;br /&gt;
*Facilitate information sharing around security events&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== '''Subprojects&amp;amp;nbsp; '''(Your contributions on any of the subjects below are very welcome)&amp;lt;br&amp;gt; ===&lt;br /&gt;
&lt;br /&gt;
1) IDE integration (auto-completion, templates, logging policy definition support) for guiding software developers to define and provide meaningful logs&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2) Implement the Standardized Common Event Expression (CEE) for Event Interoperability. &lt;br /&gt;
&lt;br /&gt;
CEE includes: Event Taxonomy, Standard terminology, Log Syntax, Consistent data elements and format, Log Transport Standard communications mechanisms, Log Recommendations See http://cee.mitre.org/ and http://n2.nabble.com/attachment/1143183/0/useCases_A2.doc&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3) Integrating application logs into a Security Information Management configuration&lt;br /&gt;
&lt;br /&gt;
OSSIM (http://www.ossim.net/) has numerous plugins for parsing webserver, appserver, WAF, IPS, IDS logs and generating/storing events in its standard format. &lt;br /&gt;
&lt;br /&gt;
Adding a plugin for parsing custom application logs is as easy as finding the correct regular expression provided that developers included all relevant information in the log message and that they have done so in a consistent way. &lt;br /&gt;
&lt;br /&gt;
You can refer to the OSSIM database model to see what data is stored for events. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4) Reconstructing attacks It is difficult to analyze, filter and generally reconstruct an attack because messages are spread around various log levels.&lt;br /&gt;
&lt;br /&gt;
Arshan Dabirsiaghi's proposal of adding a security log level is very interesting See http://www.owasp.org/index.php/How_to_add_a_security_log_level_in_log4j&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
5) Implement automated code audit tools (s.a. OWASP yasca) to ensure that log messages are consistent and complete (content, format, timestamps) &lt;br /&gt;
&lt;br /&gt;
Related OWASP projects: http://www.owasp.org/index.php/Category:OWASP_Orizon_Project &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
6) Implement scripts for filtering/scrubbing logs in order to enable log data sharing between organizations Goal: information sharing around security events&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project_-_Roadmap&amp;diff=66602</id>
		<title>Category:OWASP Logging Project - Roadmap</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Logging_Project_-_Roadmap&amp;diff=66602"/>
				<updated>2009-07-27T08:36:23Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: Created page with 'OWASP Logging Project Roadmap Goals � Provide tools for software developers in order to help them define and provide meaningful logs � Provide code audit tools to ensure that…'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;OWASP Logging Project Roadmap&lt;br /&gt;
Goals&lt;br /&gt;
� Provide tools for software developers in order to help them define&lt;br /&gt;
and provide meaningful logs&lt;br /&gt;
� Provide code audit tools to ensure that log messages are&lt;br /&gt;
consistent and complete (content, format, timestamps)&lt;br /&gt;
� Facilitate the integration of logs from different sources&lt;br /&gt;
� Facilitate attack reconstruction&lt;br /&gt;
� Facilitate information sharing around security events&lt;br /&gt;
Subprojects&lt;br /&gt;
1) IDE integration (auto-completion, templates, logging policy definition support) for&lt;br /&gt;
guiding software developers to define and provide meaningful logs&lt;br /&gt;
2) Implement the Standardized Common Event Expression (CEE) for Event&lt;br /&gt;
Interoperability.&lt;br /&gt;
CEE includes: Event Taxonomy, Standard terminology, Log Syntax, Consistent data&lt;br /&gt;
elements and format, Log Transport Standard communications mechanisms, Log&lt;br /&gt;
Recommendations&lt;br /&gt;
See http://cee.mitre.org/ and http://n2.nabble.com/attachment/1143183/0/useCases_A2.doc&lt;br /&gt;
3) Integrating application logs into a Security Information Management configuration&lt;br /&gt;
OSSIM (http://www.ossim.net/) has numerous plugins for parsing webserver, appserver,&lt;br /&gt;
WAF, IPS, IDS logs and generating/storing events in its standard format.&lt;br /&gt;
Adding a plugin for parsing custom application logs is as easy as finding the correct&lt;br /&gt;
regular expression provided that developers included all relevant information in the&lt;br /&gt;
log message and that they have done so in a consistent way.&lt;br /&gt;
You can refer to the OSSIM database model to see what data is stored for events.&lt;br /&gt;
4) Reconstructing attacks&lt;br /&gt;
It is difficult to analyze, filter and generally reconstruct an attack because messages&lt;br /&gt;
are spread around various log levels.&lt;br /&gt;
Arshan Dabirsiaghi's proposal of adding a security log level is very interesting&lt;br /&gt;
See http://www.owasp.org/index.php/How_to_add_a_security_log_level_in_log4j&lt;br /&gt;
5) Implement automated code audit tools (s.a. OWASP yasca) to ensure that log&lt;br /&gt;
messages are consistent and complete (content, format, timestamps)&lt;br /&gt;
Related OWASP projects: http://www.owasp.org/index.php/Category:OWASP_Orizon_Project&lt;br /&gt;
6) Implement scripts for filtering/scrubbing logs in order to enable log data sharing&lt;br /&gt;
between organizations&lt;br /&gt;
Goal: information sharing around security events&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:OWASP_Logging_Project_-_A&amp;diff=66601</id>
		<title>Template:OWASP Logging Project - A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:OWASP_Logging_Project_-_A&amp;diff=66601"/>
				<updated>2009-07-27T08:35:03Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| width=&amp;quot;100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;left&amp;quot; &lt;br /&gt;
! style=&amp;quot;background:#7b8abd;&amp;quot; | &amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;&amp;lt;big&amp;gt;'''what'''&amp;lt;/big&amp;gt;&lt;br /&gt;
! style=&amp;quot;background:#ffffff;&amp;quot; align=&amp;quot;left&amp;quot; colspan=&amp;quot;1&amp;quot; | &amp;lt;small&amp;gt;''is this project?''&amp;lt;/small&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | &amp;lt;!--'''''Name:'''''&amp;lt;br /&amp;gt;--&amp;gt;'''OWASP Logging Project'''&lt;br /&gt;
&lt;br /&gt;
''''' Purpose: '''''The goals of this project are:&lt;br /&gt;
 Provide tools for software developers in order to help them define and provide meaningful logs&lt;br /&gt;
 Provide code audit tools to ensure that log messages are consistent and complete (content, format, timestamps)&lt;br /&gt;
 Facilitate the integration of logs from different sources&lt;br /&gt;
 Facilitate attack reconstruction&lt;br /&gt;
 Facilitate information sharing around security events&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background:#7b8abd;&amp;quot; | &amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;&amp;lt;big&amp;gt;'''who'''&amp;lt;/big&amp;gt;&lt;br /&gt;
! style=&amp;quot;background:#ffffff;&amp;quot; align=&amp;quot;left&amp;quot; colspan=&amp;quot;1&amp;quot; | &amp;lt;small&amp;gt;''is working on this project?''&amp;lt;/small&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | '''''Project Leader:''''' [[User:Marc chisinevski|Marc Chisinevski]]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''''Project Maintainer:''''' [[User:Marc Chisinevski|Marc Chisinevski]]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''''Project Contributor(s):''''' [[:User:Marc Chisinevski|Marc Chisinevski]], []&lt;br /&gt;
'''''Project Contributor(s):''''' [[:User:Alai|Anthony Lai]], []&lt;br /&gt;
'''''Project Contributor(s):''''' [[:User:Sng|Sam Ng]], []&lt;br /&gt;
anthonylai@owasp.org&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background:#7b8abd;&amp;quot; | &amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;&amp;lt;big&amp;gt;'''how'''&amp;lt;/big&amp;gt;&lt;br /&gt;
! style=&amp;quot;background:#ffffff;&amp;quot; align=&amp;quot;left&amp;quot; colspan=&amp;quot;1&amp;quot; | &amp;lt;small&amp;gt;''can you learn more?''&amp;lt;/small&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | '''''Project Flyer/Pamphlet:''''' []&lt;br /&gt;
&lt;br /&gt;
'''''Mail list:''''' [https://lists.owasp.org/mailman/listinfo/owasp-logging-project Subscribe or read the archives]&lt;br /&gt;
&lt;br /&gt;
'''''Project Roadmap:''''' [[:Category:OWASP Logging Project - Roadmap|To view, click here]]&lt;br /&gt;
&lt;br /&gt;
'''''Project main links:''''' [[:Category:OWASP Logging Project|OWASP Logging Project]]; []&lt;br /&gt;
&lt;br /&gt;
'''''Project Health:''''' [[Image:Yellow button.JPG|25px]] [[:Category:OWASP Logging Project Project Health - Assessment|Not reviewed/Targeted at Level 1]]&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;small&amp;gt;''To be reviewed under [[:Assessing Project Health|Assessment Criteria v2.0]]''&amp;lt;/small&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background:#ccccff;&amp;quot; |'''Key Contacts'''&lt;br /&gt;
! style=&amp;quot;background:#ffffff;&amp;quot; align=&amp;quot;left&amp;quot; |&lt;br /&gt;
|- &lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | &lt;br /&gt;
* Contact [[User:Marc Chisinevski|Project Leader]] to contribute to this project, &lt;br /&gt;
* Contact [[User:Marc Chisinevski|Project Leader]] or [[:Category:Global Projects Committee|GPC]] to review or sponsor this project,&lt;br /&gt;
* Contact [[:Category:Global Projects Committee|GPC]] to report a problem or concern about this project or to update information.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:OWASP_Logging_Project_-_A&amp;diff=66600</id>
		<title>Template:OWASP Logging Project - A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:OWASP_Logging_Project_-_A&amp;diff=66600"/>
				<updated>2009-07-27T08:31:58Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: Created page with '{| width=&amp;quot;100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;left&amp;quot;  ! style=&amp;quot;background:#7b8abd;&amp;quot; | &amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;&amp;lt;big&amp;gt;'''what'''&amp;lt;/big&amp;gt; ! style=&amp;quot;background:#ffffff;&amp;quot; align=&amp;quot;left&amp;quot; colspan=&amp;quot;1&amp;quot; | &amp;lt;small…'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| width=&amp;quot;100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;left&amp;quot; &lt;br /&gt;
! style=&amp;quot;background:#7b8abd;&amp;quot; | &amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;&amp;lt;big&amp;gt;'''what'''&amp;lt;/big&amp;gt;&lt;br /&gt;
! style=&amp;quot;background:#ffffff;&amp;quot; align=&amp;quot;left&amp;quot; colspan=&amp;quot;1&amp;quot; | &amp;lt;small&amp;gt;''is this project?''&amp;lt;/small&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | &amp;lt;!--'''''Name:'''''&amp;lt;br /&amp;gt;--&amp;gt;'''OWASP Logging Project'''&lt;br /&gt;
&lt;br /&gt;
''''' Purpose: '''''This CD collects some of the best open source security projects in a single environment. Web developers, testers and security professionals can boot from this Live CD and have access to a full security testing suite.&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background:#7b8abd;&amp;quot; | &amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;&amp;lt;big&amp;gt;'''who'''&amp;lt;/big&amp;gt;&lt;br /&gt;
! style=&amp;quot;background:#ffffff;&amp;quot; align=&amp;quot;left&amp;quot; colspan=&amp;quot;1&amp;quot; | &amp;lt;small&amp;gt;''is working on this project?''&amp;lt;/small&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | '''''Project Leader:''''' [[User:Mchisinevski|Marc Chisinevski]]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''''Project Maintainer:''''' [[User:Mchisinevski|Marc Chisinevski]]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''''Project Contributor(s):''''' [[:User:Mchisinevski|Marc Chisinevski]], []&lt;br /&gt;
'''''Project Contributor(s):''''' [[:User:Alai|Anthony Lai]], []&lt;br /&gt;
'''''Project Contributor(s):''''' [[:User:Sng|Sam Ng]], []&lt;br /&gt;
anthonylai@owasp.org&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background:#7b8abd;&amp;quot; | &amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;&amp;lt;big&amp;gt;'''how'''&amp;lt;/big&amp;gt;&lt;br /&gt;
! style=&amp;quot;background:#ffffff;&amp;quot; align=&amp;quot;left&amp;quot; colspan=&amp;quot;1&amp;quot; | &amp;lt;small&amp;gt;''can you learn more?''&amp;lt;/small&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | '''''Project Flyer/Pamphlet:''''' []&lt;br /&gt;
&lt;br /&gt;
'''''Mail list:''''' [https://lists.owasp.org/mailman/listinfo/owasp-logging-project Subscribe or read the archives]&lt;br /&gt;
&lt;br /&gt;
'''''Project Roadmap:''''' [[:Category:OWASP Logging Project - Roadmap|To view, click here]]&lt;br /&gt;
&lt;br /&gt;
'''''Project main links:''''' [[:Category:OWASP Logging Project|OWASP Logging Project]]; []&lt;br /&gt;
&lt;br /&gt;
'''''Project Health:''''' [[Image:Yellow button.JPG|25px]] [[:Category:OWASP Logging Project Project Health - Assessment|Not reviewed/Targeted at Level 1]]&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;small&amp;gt;''To be reviewed under [[:Assessing Project Health|Assessment Criteria v2.0]]''&amp;lt;/small&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;background:#ccccff;&amp;quot; |'''Key Contacts'''&lt;br /&gt;
! style=&amp;quot;background:#ffffff;&amp;quot; align=&amp;quot;left&amp;quot; |&lt;br /&gt;
|- &lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | &lt;br /&gt;
* Contact [[User:Mchisinevski|Project Leader]] to contribute to this project, &lt;br /&gt;
* Contact [[User:Mchisinevski|Project Leader]] or [[:Category:Global Projects Committee|GPC]] to review or sponsor this project,&lt;br /&gt;
* Contact [[:Category:Global Projects Committee|GPC]] to report a problem or concern about this project or to update information.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:OWASP_Logging_Project&amp;diff=66599</id>
		<title>Template:OWASP Logging Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:OWASP_Logging_Project&amp;diff=66599"/>
				<updated>2009-07-27T08:22:20Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: Created page with '&amp;lt;!-- ############################################################################ NOTE:  THIS TEMPLATE IS MANAGED BY THE GLOBAL PROJECTS COMMITTEE.   IF YOU ARE NOT A MEMBER OF T…'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--&lt;br /&gt;
############################################################################&lt;br /&gt;
NOTE:  THIS TEMPLATE IS MANAGED BY THE GLOBAL PROJECTS COMMITTEE.  &lt;br /&gt;
IF YOU ARE NOT A MEMBER OF THE GLOBAL PROJECTS COMMITTEE, PLEASE DO NOT&lt;br /&gt;
MODIFY THE VALUES IN THIS TABLE.  IF IT NEEDS TO BE UPDATED, PLEASE NOTIFY &lt;br /&gt;
THE GLOBAL PROJECTS COMMITTEE BY SENDING AN EMAIL TO THE COMMITTEES MAIL&lt;br /&gt;
LIST.  SEE THE GLOBAL PROJECTS COMMITTEE PAGE FOR MORE INFORMATION&lt;br /&gt;
############################################################################&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{|border=&amp;quot;0&amp;quot; cellpadding=&amp;quot;2&amp;quot; cellspacing=&amp;quot;3&amp;quot;&lt;br /&gt;
!width=&amp;quot;50%&amp;quot; style=&amp;quot;background:white;&amp;quot; | PROJECT INFO&amp;lt;br&amp;gt; &amp;lt;small&amp;gt;''What does this OWASP project offer you?''&amp;lt;/small&amp;gt;&lt;br /&gt;
!width=&amp;quot;50%&amp;quot; style=&amp;quot;background:white;&amp;quot; | RELEASE(S) INFO&amp;lt;br&amp;gt; &amp;lt;small&amp;gt;''What does this OWASP project release offer you?''&amp;lt;/small&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|valign=&amp;quot;top&amp;quot;|{{Template:OWASP Logging Project - A}}&lt;br /&gt;
|valign=&amp;quot;top&amp;quot;|{{Template:OWASP Logging Project - B}}&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Season_of_Code_2009_-_Applications&amp;diff=66125</id>
		<title>OWASP Season of Code 2009 - Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Season_of_Code_2009_-_Applications&amp;diff=66125"/>
				<updated>2009-07-16T12:07:01Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''This page contains project Applications to the [[OWASP Season of Code 2009|OWASP Season of Code 2009]]'''.&lt;br /&gt;
&lt;br /&gt;
= A few notes =&lt;br /&gt;
*'''If you want to apply for a OWASP SoC 09 sponsorship you HAVE TO USE THIS PAGE for your application.'''&lt;br /&gt;
** See [[OWASP Season of Code 2009#HOW TO PARTICIPATE (TO DEVELOPERS)|How To Participate]] for what to do once you completed your Application.&lt;br /&gt;
** Please remember that projects will be selected and funded based on how well they meet the [[OWASP_Season_of_Code_2009#SELECTION_CRITERIA|Selection Criteria]].&lt;br /&gt;
** Please see [[OWASP Summer of Code 2008 Applications|OWASP SoC 08]], [[OWASP Spring Of Code 2007 Applications|OWASP SpoC 07]] for examples of Applications and [[OWASP Autumn of Code 2006 - Applications|OWASP AoC 06]]. &lt;br /&gt;
* '''You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include [[OWASP Season of Code 2009 - Applications - Proposal Type|this information in your proposal]].&lt;br /&gt;
'''&lt;br /&gt;
&lt;br /&gt;
= Applications - {Fill in below}  =&lt;br /&gt;
&lt;br /&gt;
== Application 1  ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 95%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: white none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; colspan=&amp;quot;2&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Applicant's Identification/Project Release Leader&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Igor Kranjec&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Designation/Name &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | ASTRanger (Abstract Syntax Tree Ranger)&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | First (proposed) Reviewer&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Paulo Coimbra&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Security Issue Addressed &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
'''Prelude''' &lt;br /&gt;
&lt;br /&gt;
A commonly available tool for the Source Code static analysis (SCA, Static Code Analyzer) is a tool aimed to perform a parsing of the application source code in order to create a reference model on which to apply specific rules to identify problems and create a detailed report. There are a number of complete and efficient SCA tools available on the market. &lt;br /&gt;
&lt;br /&gt;
'''Problem to be addressed''' &lt;br /&gt;
&lt;br /&gt;
Based on our experience an ideal SCA tool should have the following additional characteristics: - multiplatform support; &lt;br /&gt;
&lt;br /&gt;
- multi programming language support (with complete grammars, without “syntax holes”); &lt;br /&gt;
&lt;br /&gt;
- ability to execute in stand alone mode or integrated with the most utilized development environment; &lt;br /&gt;
&lt;br /&gt;
- Open Source distribution, with a strong community support; &lt;br /&gt;
&lt;br /&gt;
- Security issues dedicated, with a clean separation between the analysis engine and vulnerability repository; &lt;br /&gt;
&lt;br /&gt;
- Able to analyze large code bases with high performance. &lt;br /&gt;
&lt;br /&gt;
'''Proposal''' &lt;br /&gt;
&lt;br /&gt;
ASTRanger Project foresees the prototype development of a tool for the static analysis of source code that is going to address all of the above problems and will be able to assure that correct security rules (based on OWASP best practices) will be applied at the same time of the source code implementation. The tool will be embedded on the application developed, in such a way becoming a real Security Framework. &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Prioritized area&amp;lt;br&amp;gt;(''Please choose from'' [[OWASP Season of Code 2009#HOW_TO_PARTICIPATE_.28TO_DEVELOPERS.29|''here'']]) &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Enterprise usability of OWASP projects&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Project Release Roadmap &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
'''Milestones''': &lt;br /&gt;
&lt;br /&gt;
June 30, 2009 - Project Begins &lt;br /&gt;
&lt;br /&gt;
July 10, 2009 – Requirements Analysis: Functional Requirements Document (FRD) &lt;br /&gt;
&lt;br /&gt;
July 16, 2009 – Requirements Analysis: SAR (System Architectural Requirements) &lt;br /&gt;
&lt;br /&gt;
July 20, 2009 – Identify vulnerabilities and exploitation methods. &lt;br /&gt;
&lt;br /&gt;
July 24, 2009 - Defining rules set for selected vulnerabilities &lt;br /&gt;
&lt;br /&gt;
July 28 2 2009 - Create thresholds for generating security alerts &lt;br /&gt;
&lt;br /&gt;
Aug 3 2009 - Define parsing source code actions in response to security alerts &lt;br /&gt;
&lt;br /&gt;
Aug 6 2009 - Development &lt;br /&gt;
&lt;br /&gt;
Aug 18 2009 – Test and debugging &lt;br /&gt;
&lt;br /&gt;
Aug 28, 2009 - Peer Review &amp;amp;amp; Revisions &lt;br /&gt;
&lt;br /&gt;
Aug 31, 2009 – Deliver of Prototype (Project Completion) &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Other Questions &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;amp;#124;} &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Application 2  ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 95%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: white none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Applicant's Identification/Project Release Leader&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Marc Chisinevski&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Designation/Name &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Asset management (asset identification, valuation and risk assessment based on ISO27005)&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | First (proposed) Reviewer&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Paulo Coimbra&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Security Issue Addressed &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
'''Prelude''' &lt;br /&gt;
&lt;br /&gt;
Please find the sources and documentation at http://sourceforge.net/projects/assetmng.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The application is already production-ready. However, the functionalities below need further analysis: &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp; - Asset management (asset identification, valuation and risk assessment based on ISO27005); integration with opensource Security Information Management systems is currently being discussed. &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp; - Party management (clients, providers) &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp; - Contract and license management - integration with opensource tools such as OCS Inventory needs to be investigated, assetmng offering complementary functionalities. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Problems to be addressed''' &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp; - Integration of different asset valuation and risk assessment models; &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp; - Integration with opensource Security Information Management systems &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-weight: bold;&amp;quot;&amp;gt;Functionalities&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt; 1/ already implemented: managers/business analysts use the interface in order to: &lt;br /&gt;
&lt;br /&gt;
  - define assets and business process and their intrinsic values;&lt;br /&gt;
  &lt;br /&gt;
  - classify these assets according to ISO27005 guidelines&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
&lt;br /&gt;
2/ to be developed: the application calculates asset values taking into an account&amp;amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
  - the intrinsic value of the asset defined in step 1;&lt;br /&gt;
  &lt;br /&gt;
  - the values of other assets depending on this asset;&lt;br /&gt;
  &lt;br /&gt;
  - the values of business processes using the asset.&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
&lt;br /&gt;
The concept of an “asset” derived from ISO 27005 &lt;br /&gt;
&lt;br /&gt;
====== ================================================  ======&lt;br /&gt;
&lt;br /&gt;
An asset can be: &lt;br /&gt;
&lt;br /&gt;
- a business process or activity; &lt;br /&gt;
&lt;br /&gt;
- information; &lt;br /&gt;
&lt;br /&gt;
- a supporting asset such as a server or a network device. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
3/ already implemented: the Legal or HR departments can use the application in order to manage parties and contracts &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
4/ already implemented: IT or helpdesk can use the application in order to manage licenses as well as their relationships to contracts and servers &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Prioritized area&amp;lt;br&amp;gt;(''Please choose from'' [[OWASP Season of Code 2009#HOW_TO_PARTICIPATE_.28TO_DEVELOPERS.29|''here'']]) &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Enterprise usability of OWASP projects&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Project Release Roadmap &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
'''Milestones''': &lt;br /&gt;
&lt;br /&gt;
July 16th, 2009 - Sources and documentation published at http://sourceforge.net/projects/assetmng &lt;br /&gt;
&lt;br /&gt;
August 1st, 2009 – Identify improvements, new functionalities and integration options &lt;br /&gt;
&lt;br /&gt;
Aug 10th, 2009 - Development &lt;br /&gt;
&lt;br /&gt;
Aug 18th, 2009 – Test and debugging &lt;br /&gt;
&lt;br /&gt;
Aug 28, 2009 - Peer Review &amp;amp;amp; Revisions &lt;br /&gt;
&lt;br /&gt;
Aug 31, 2009 – Deliver of Prototype (Project Completion) &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Other Questions &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;amp;#124;}&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Season_of_Code_2009_-_Applications&amp;diff=66124</id>
		<title>OWASP Season of Code 2009 - Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Season_of_Code_2009_-_Applications&amp;diff=66124"/>
				<updated>2009-07-16T12:04:56Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''This page contains project Applications to the [[OWASP Season of Code 2009|OWASP Season of Code 2009]]'''.&lt;br /&gt;
&lt;br /&gt;
= A few notes =&lt;br /&gt;
*'''If you want to apply for a OWASP SoC 09 sponsorship you HAVE TO USE THIS PAGE for your application.'''&lt;br /&gt;
** See [[OWASP Season of Code 2009#HOW TO PARTICIPATE (TO DEVELOPERS)|How To Participate]] for what to do once you completed your Application.&lt;br /&gt;
** Please remember that projects will be selected and funded based on how well they meet the [[OWASP_Season_of_Code_2009#SELECTION_CRITERIA|Selection Criteria]].&lt;br /&gt;
** Please see [[OWASP Summer of Code 2008 Applications|OWASP SoC 08]], [[OWASP Spring Of Code 2007 Applications|OWASP SpoC 07]] for examples of Applications and [[OWASP Autumn of Code 2006 - Applications|OWASP AoC 06]]. &lt;br /&gt;
* '''You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include [[OWASP Season of Code 2009 - Applications - Proposal Type|this information in your proposal]].&lt;br /&gt;
'''&lt;br /&gt;
&lt;br /&gt;
= Applications - {Fill in below}  =&lt;br /&gt;
&lt;br /&gt;
== Application 1  ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 95%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: white none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; colspan=&amp;quot;2&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Applicant's Identification/Project Release Leader&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Igor Kranjec&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Designation/Name &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | ASTRanger (Abstract Syntax Tree Ranger)&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | First (proposed) Reviewer&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Paulo Coimbra&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Security Issue Addressed &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
'''Prelude''' &lt;br /&gt;
&lt;br /&gt;
A commonly available tool for the Source Code static analysis (SCA, Static Code Analyzer) is a tool aimed to perform a parsing of the application source code in order to create a reference model on which to apply specific rules to identify problems and create a detailed report. There are a number of complete and efficient SCA tools available on the market. &lt;br /&gt;
&lt;br /&gt;
'''Problem to be addressed''' &lt;br /&gt;
&lt;br /&gt;
Based on our experience an ideal SCA tool should have the following additional characteristics: - multiplatform support; &lt;br /&gt;
&lt;br /&gt;
- multi programming language support (with complete grammars, without “syntax holes”); &lt;br /&gt;
&lt;br /&gt;
- ability to execute in stand alone mode or integrated with the most utilized development environment; &lt;br /&gt;
&lt;br /&gt;
- Open Source distribution, with a strong community support; &lt;br /&gt;
&lt;br /&gt;
- Security issues dedicated, with a clean separation between the analysis engine and vulnerability repository; &lt;br /&gt;
&lt;br /&gt;
- Able to analyze large code bases with high performance. &lt;br /&gt;
&lt;br /&gt;
'''Proposal''' &lt;br /&gt;
&lt;br /&gt;
ASTRanger Project foresees the prototype development of a tool for the static analysis of source code that is going to address all of the above problems and will be able to assure that correct security rules (based on OWASP best practices) will be applied at the same time of the source code implementation. The tool will be embedded on the application developed, in such a way becoming a real Security Framework. &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Prioritized area&amp;lt;br&amp;gt;(''Please choose from'' [[OWASP Season of Code 2009#HOW_TO_PARTICIPATE_.28TO_DEVELOPERS.29|''here'']]) &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Enterprise usability of OWASP projects&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Project Release Roadmap &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
'''Milestones''': &lt;br /&gt;
&lt;br /&gt;
June 30, 2009 - Project Begins &lt;br /&gt;
&lt;br /&gt;
July 10, 2009 – Requirements Analysis: Functional Requirements Document (FRD) &lt;br /&gt;
&lt;br /&gt;
July 16, 2009 – Requirements Analysis: SAR (System Architectural Requirements) &lt;br /&gt;
&lt;br /&gt;
July 20, 2009 – Identify vulnerabilities and exploitation methods. &lt;br /&gt;
&lt;br /&gt;
July 24, 2009 - Defining rules set for selected vulnerabilities &lt;br /&gt;
&lt;br /&gt;
July 28 2 2009 - Create thresholds for generating security alerts &lt;br /&gt;
&lt;br /&gt;
Aug 3 2009 - Define parsing source code actions in response to security alerts &lt;br /&gt;
&lt;br /&gt;
Aug 6 2009 - Development &lt;br /&gt;
&lt;br /&gt;
Aug 18 2009 – Test and debugging &lt;br /&gt;
&lt;br /&gt;
Aug 28, 2009 - Peer Review &amp;amp;amp; Revisions &lt;br /&gt;
&lt;br /&gt;
Aug 31, 2009 – Deliver of Prototype (Project Completion) &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Other Questions &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;amp;#124;} &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Application 2  ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 95%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; style=&amp;quot;background: white none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Applicant's Identification/Project Release Leader&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Marc Chisinevski&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Designation/Name &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Asset management (asset identification, valuation and risk assessment based on ISO27005)&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | First (proposed) Reviewer&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Paulo Coimbra&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Security Issue Addressed &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
'''Prelude''' &lt;br /&gt;
&lt;br /&gt;
Please find the sources and documentation at http://sourceforge.net/projects/assetmng.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The application is already production-ready. However, the functionalities below need further analysis:&lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp; - Asset management (asset identification, valuation and risk assessment based on ISO27005); integration with opensource Security Information Management systems is currently being discussed. &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp; - Party management (clients, providers) &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp; - Contract and license management - integration with opensource tools such as OCS Inventory needs to be investigated, assetmng offering complementary functionalities. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Problems to be addressed''' &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp; - Integration of different asset valuation and risk assessment models; &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp; - Integration with opensource Security Information Management systems &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-weight: bold;&amp;quot;&amp;gt;Functionalities&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt; 1/ already implemented: managers/business analysts use the interface in order to: &lt;br /&gt;
&lt;br /&gt;
  - define assets and business process and their intrinsic values;&lt;br /&gt;
  &lt;br /&gt;
  - classify these assets according to ISO27005 guidelines&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
&lt;br /&gt;
2/ to be developed: the application calculates asset values taking into an account&amp;amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
  - the intrinsic value of the asset defined in step 1;&lt;br /&gt;
  &lt;br /&gt;
  - the values of other assets depending on this asset;&lt;br /&gt;
  &lt;br /&gt;
  - the values of business processes using the asset.&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
&lt;br /&gt;
The concept of an “asset” derived from ISO 27005 &lt;br /&gt;
&lt;br /&gt;
====== ================================================ ======&lt;br /&gt;
&lt;br /&gt;
An asset can be: &lt;br /&gt;
&lt;br /&gt;
- a business process or activity; &lt;br /&gt;
&lt;br /&gt;
- information; &lt;br /&gt;
&lt;br /&gt;
- a supporting asset such as a server or a network device. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3/ already implemented: the Legal or HR departments can use the application in order to manager parties and contracts&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4/ already implemented: IT or helpdesk can use the application in order to manage licenses as well as their relationships to contracts and servers&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Prioritized area&amp;lt;br&amp;gt;(''Please choose from'' [[OWASP Season of Code 2009#HOW_TO_PARTICIPATE_.28TO_DEVELOPERS.29|''here'']]) &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Enterprise usability of OWASP projects&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Project Release Roadmap &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
'''Milestones''': &lt;br /&gt;
&lt;br /&gt;
July 16th, 2009 - Sources and documentation published at http://sourceforge.net/projects/assetmng &lt;br /&gt;
&lt;br /&gt;
August 1st, 2009 – Identify improvements, new functionalities and integration options &lt;br /&gt;
&lt;br /&gt;
Aug 10th, 2009 - Development &lt;br /&gt;
&lt;br /&gt;
Aug 18th, 2009 – Test and debugging &lt;br /&gt;
&lt;br /&gt;
Aug 28, 2009 - Peer Review &amp;amp;amp; Revisions &lt;br /&gt;
&lt;br /&gt;
Aug 31, 2009 – Deliver of Prototype (Project Completion) &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Other Questions &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;amp;#124;}&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Season_of_Code_2009_-_Applications_-_Proposal_Type&amp;diff=66123</id>
		<title>OWASP Season of Code 2009 - Applications - Proposal Type</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Season_of_Code_2009_-_Applications_-_Proposal_Type&amp;diff=66123"/>
				<updated>2009-07-16T11:51:00Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Suggested Proposal Type  =&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 95%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; style=&amp;quot;background: rgb(64, 88, 160) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | '''Suggested Proposal Type'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Description''' &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''To be filled in below'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Applicant's Identification/Project Release Leader&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Designation/Name &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | First (proposed) Reviewer&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Security Issue Addressed &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Prioritized area&amp;lt;br&amp;gt;(''Please choose from'' [[OWASP Season of Code 2009#HOW_TO_PARTICIPATE_.28TO_DEVELOPERS.29|''here'']]) &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
Project Release Roadmap &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Other Questions &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Season_of_Code_2009_-_Applications_-_Proposal_Type&amp;diff=66122</id>
		<title>OWASP Season of Code 2009 - Applications - Proposal Type</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Season_of_Code_2009_-_Applications_-_Proposal_Type&amp;diff=66122"/>
				<updated>2009-07-16T11:49:24Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: Undo revision 66121 by Marc Chisinevski (Talk)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Suggested Proposal Type  =&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 95%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(64, 88, 160) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Suggested Proposal Type'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Description''' &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''To be filled in below'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Applicant's Identification/Project Release Leader&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Marc Chisinevski&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Designation/Name &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | assetmng&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | First (proposed) Reviewer&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Kate Hartmann&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Security Issue Addressed &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Asset identification, valuation and risk assessment (ISO 27005)&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Prioritized area&amp;lt;br&amp;gt;(''Please choose from'' [[OWASP Season of Code 2009#HOW_TO_PARTICIPATE_.28TO_DEVELOPERS.29|''here'']]) &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Enterprise usability&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
Project Release Roadmap &lt;br /&gt;
&lt;br /&gt;
Asset management (asset identification, valuation and risk assessment based on ISO27005): integration with opensource Security Information Management systems such as OSSIM is currently being discussed.&lt;br /&gt;
&lt;br /&gt;
Party management (clients, providers)&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Contract and license management - integration with opensource tools such as OCS Inventory needs to be investigated, assetmng offering complementary functionalities.&lt;br /&gt;
&lt;br /&gt;
The assetmng app is database-independent thanks to the Django framework and functions on Windows and Linux. &lt;br /&gt;
&lt;br /&gt;
Please provide feedback.&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Other Questions &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Please see: http://sourceforge.net/projects/assetmng/&amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Season_of_Code_2009_-_Applications_-_Proposal_Type&amp;diff=66121</id>
		<title>OWASP Season of Code 2009 - Applications - Proposal Type</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Season_of_Code_2009_-_Applications_-_Proposal_Type&amp;diff=66121"/>
				<updated>2009-07-16T11:48:55Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: Undo revision 66119 by Marc Chisinevski (Talk)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Suggested Proposal Type  =&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 95%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; style=&amp;quot;background: rgb(64, 88, 160) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | '''Suggested Proposal Type'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Description''' &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''To be filled in below'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Applicant's Identification/Project Release Leader&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Marc Chisinevski&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Designation/Name &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | assetmng&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | First (proposed) Reviewer&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Kate Hartmann&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Security Issue Addressed &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Asset identification, valuation and risk assessment (ISO 27005)&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Prioritized area&amp;lt;br&amp;gt;(''Please choose from'' [[OWASP Season of Code 2009#HOW_TO_PARTICIPATE_.28TO_DEVELOPERS.29|''here'']]) &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Enterprise usability&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Project Release Roadmap&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Other Questions &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Please see: http://sourceforge.net/projects/assetmng/&amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Season_of_Code_2009_-_Applications&amp;diff=66120</id>
		<title>OWASP Season of Code 2009 - Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Season_of_Code_2009_-_Applications&amp;diff=66120"/>
				<updated>2009-07-16T11:45:44Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''This page contains project Applications to the [[OWASP Season of Code 2009|OWASP Season of Code 2009]]'''.&lt;br /&gt;
&lt;br /&gt;
= A few notes =&lt;br /&gt;
*'''If you want to apply for a OWASP SoC 09 sponsorship you HAVE TO USE THIS PAGE for your application.'''&lt;br /&gt;
** See [[OWASP Season of Code 2009#HOW TO PARTICIPATE (TO DEVELOPERS)|How To Participate]] for what to do once you completed your Application.&lt;br /&gt;
** Please remember that projects will be selected and funded based on how well they meet the [[OWASP_Season_of_Code_2009#SELECTION_CRITERIA|Selection Criteria]].&lt;br /&gt;
** Please see [[OWASP Summer of Code 2008 Applications|OWASP SoC 08]], [[OWASP Spring Of Code 2007 Applications|OWASP SpoC 07]] for examples of Applications and [[OWASP Autumn of Code 2006 - Applications|OWASP AoC 06]]. &lt;br /&gt;
* '''You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include [[OWASP Season of Code 2009 - Applications - Proposal Type|this information in your proposal]].&lt;br /&gt;
'''&lt;br /&gt;
&lt;br /&gt;
= Applications - {Fill in below}  =&lt;br /&gt;
&lt;br /&gt;
== Application 1  ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 95%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: white none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; colspan=&amp;quot;2&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Applicant's Identification/Project Release Leader&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Igor Kranjec&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Designation/Name &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | ASTRanger (Abstract Syntax Tree Ranger)&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | First (proposed) Reviewer&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Paulo Coimbra&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Security Issue Addressed &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
'''Prelude''' &lt;br /&gt;
&lt;br /&gt;
A commonly available tool for the Source Code static analysis (SCA, Static Code Analyzer) is a tool aimed to perform a parsing of the application source code in order to create a reference model on which to apply specific rules to identify problems and create a detailed report. There are a number of complete and efficient SCA tools available on the market. &lt;br /&gt;
&lt;br /&gt;
'''Problem to be addressed''' &lt;br /&gt;
&lt;br /&gt;
Based on our experience an ideal SCA tool should have the following additional characteristics: - multiplatform support; &lt;br /&gt;
&lt;br /&gt;
- multi programming language support (with complete grammars, without “syntax holes”); &lt;br /&gt;
&lt;br /&gt;
- ability to execute in stand alone mode or integrated with the most utilized development environment; &lt;br /&gt;
&lt;br /&gt;
- Open Source distribution, with a strong community support; &lt;br /&gt;
&lt;br /&gt;
- Security issues dedicated, with a clean separation between the analysis engine and vulnerability repository; &lt;br /&gt;
&lt;br /&gt;
- Able to analyze large code bases with high performance. &lt;br /&gt;
&lt;br /&gt;
'''Proposal''' &lt;br /&gt;
&lt;br /&gt;
ASTRanger Project foresees the prototype development of a tool for the static analysis of source code that is going to address all of the above problems and will be able to assure that correct security rules (based on OWASP best practices) will be applied at the same time of the source code implementation. The tool will be embedded on the application developed, in such a way becoming a real Security Framework. &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Prioritized area&amp;lt;br&amp;gt;(''Please choose from'' [[OWASP Season of Code 2009#HOW_TO_PARTICIPATE_.28TO_DEVELOPERS.29|''here'']]) &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Enterprise usability of OWASP projects&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Project Release Roadmap &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
'''Milestones''': &lt;br /&gt;
&lt;br /&gt;
June 30, 2009 - Project Begins &lt;br /&gt;
&lt;br /&gt;
July 10, 2009 – Requirements Analysis: Functional Requirements Document (FRD) &lt;br /&gt;
&lt;br /&gt;
July 16, 2009 – Requirements Analysis: SAR (System Architectural Requirements) &lt;br /&gt;
&lt;br /&gt;
July 20, 2009 – Identify vulnerabilities and exploitation methods. &lt;br /&gt;
&lt;br /&gt;
July 24, 2009 - Defining rules set for selected vulnerabilities &lt;br /&gt;
&lt;br /&gt;
July 28 2 2009 - Create thresholds for generating security alerts &lt;br /&gt;
&lt;br /&gt;
Aug 3 2009 - Define parsing source code actions in response to security alerts &lt;br /&gt;
&lt;br /&gt;
Aug 6 2009 - Development &lt;br /&gt;
&lt;br /&gt;
Aug 18 2009 – Test and debugging &lt;br /&gt;
&lt;br /&gt;
Aug 28, 2009 - Peer Review &amp;amp;amp; Revisions &lt;br /&gt;
&lt;br /&gt;
Aug 31, 2009 – Deliver of Prototype (Project Completion) &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Other Questions &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;amp;#124;} &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Application 2  ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 95%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: white none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; colspan=&amp;quot;2&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Applicant's Identification/Project Release Leader&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Marc Chisinevski&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Designation/Name &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Asset management (asset identification, valuation and risk assessment based on ISO27005)&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | First (proposed) Reviewer&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Paulo Coimbra&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Security Issue Addressed &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
'''Prelude''' &lt;br /&gt;
&lt;br /&gt;
Asset management (asset identification, valuation and risk assessment based on ISO27005): integration with opensource Security Information Management systems is currently being discussed.&lt;br /&gt;
&lt;br /&gt;
Party management (clients, providers) &lt;br /&gt;
&lt;br /&gt;
Contract and license management -  integration with opensource tools such as OCS Inventory needs to be investigated, assetmng offering complementary functionalities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Problem to be addressed''' &lt;br /&gt;
integration of different asset valuation and risk assessment models;&lt;br /&gt;
integration with opensource Security Information Management systems &lt;br /&gt;
&lt;br /&gt;
'''Proposal''' &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
1/ managers/business analysts use the interface in order to:&lt;br /&gt;
&lt;br /&gt;
  - define assets and business process and their intrinsic values;&lt;br /&gt;
  &lt;br /&gt;
  - classify these assets according to ISO27005 guidelines&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
2/ the application calculates asset values taking into an account:&lt;br /&gt;
&lt;br /&gt;
  - the intrinsic value of the asset defined in step 1;&lt;br /&gt;
  &lt;br /&gt;
  - the values of other assets depending on this asset;&lt;br /&gt;
  &lt;br /&gt;
  - the values of business processes using the asset.&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
The concept of an “asset” derived from ISO 27005&lt;br /&gt;
=================================================&lt;br /&gt;
An asset can be a :&lt;br /&gt;
&lt;br /&gt;
- a business process or activity;&lt;br /&gt;
&lt;br /&gt;
- information;&lt;br /&gt;
&lt;br /&gt;
- a supporting asset such as a server or a network device. &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Prioritized area&amp;lt;br&amp;gt;(''Please choose from'' [[OWASP Season of Code 2009#HOW_TO_PARTICIPATE_.28TO_DEVELOPERS.29|''here'']]) &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Enterprise usability of OWASP projects&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Project Release Roadmap &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
'''Milestones''': &lt;br /&gt;
&lt;br /&gt;
July 16th, 2009 - Sources and documentation published at http://sourceforge.net/projects/assetmng&lt;br /&gt;
&lt;br /&gt;
August 1st, 2009 – Identify improvements, new functionalities and integration options&lt;br /&gt;
&lt;br /&gt;
Aug 10th, 2009 - Development &lt;br /&gt;
&lt;br /&gt;
Aug 18th, 2009 – Test and debugging &lt;br /&gt;
&lt;br /&gt;
Aug 28, 2009 - Peer Review &amp;amp;amp; Revisions &lt;br /&gt;
&lt;br /&gt;
Aug 31, 2009 – Deliver of Prototype (Project Completion) &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Other Questions &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;amp;#124;} &lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Season_of_Code_2009_-_Applications_-_Proposal_Type&amp;diff=66119</id>
		<title>OWASP Season of Code 2009 - Applications - Proposal Type</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Season_of_Code_2009_-_Applications_-_Proposal_Type&amp;diff=66119"/>
				<updated>2009-07-16T11:15:00Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Suggested Proposal Type  =&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 95%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(64, 88, 160) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Suggested Proposal Type'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Description''' &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''To be filled in below'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Applicant's Identification/Project Release Leader&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Marc Chisinevski&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Designation/Name &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | assetmng&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | First (proposed) Reviewer&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Kate Hartmann&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Security Issue Addressed &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Asset identification, valuation and risk assessment (ISO 27005)&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Prioritized area&amp;lt;br&amp;gt;(''Please choose from'' [[OWASP Season of Code 2009#HOW_TO_PARTICIPATE_.28TO_DEVELOPERS.29|''here'']]) &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Enterprise usability&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
Project Release Roadmap &lt;br /&gt;
&lt;br /&gt;
Asset management (asset identification, valuation and risk assessment based on ISO27005): integration with opensource Security Information Management systems such as OSSIM is currently being discussed.&lt;br /&gt;
&lt;br /&gt;
Party management (clients, providers)&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Contract and license management - integration with opensource tools such as OCS Inventory needs to be investigated, assetmng offering complementary functionalities.&lt;br /&gt;
&lt;br /&gt;
The assetmng app is database-independent thanks to the Django framework and functions on Windows and Linux. &lt;br /&gt;
&lt;br /&gt;
Please provide feedback.&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Other Questions &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Please see: http://sourceforge.net/projects/assetmng/&amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Season_of_Code_2009_-_Applications_-_Proposal_Type&amp;diff=66118</id>
		<title>OWASP Season of Code 2009 - Applications - Proposal Type</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Season_of_Code_2009_-_Applications_-_Proposal_Type&amp;diff=66118"/>
				<updated>2009-07-16T11:12:52Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: Asset management (asset identification, valuation and risk assessment based on ISO27005): integration with opensource Security Information Management systems is currently being discussed.  Party manag&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Suggested Proposal Type  =&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 95%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; style=&amp;quot;background: rgb(64, 88, 160) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | '''Suggested Proposal Type'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Description''' &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''To be filled in below'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Applicant's Identification/Project Release Leader&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Marc Chisinevski&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Designation/Name &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | assetmng&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | First (proposed) Reviewer&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Kate Hartmann&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Security Issue Addressed &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Asset identification, valuation and risk assessment (ISO 27005)&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Prioritized area&amp;lt;br&amp;gt;(''Please choose from'' [[OWASP Season of Code 2009#HOW_TO_PARTICIPATE_.28TO_DEVELOPERS.29|''here'']]) &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Enterprise usability&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Project Release Roadmap&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Other Questions &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Please see: http://sourceforge.net/projects/assetmng/&amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Season_of_Code_2009_-_Applications_-_Proposal_Type&amp;diff=66117</id>
		<title>OWASP Season of Code 2009 - Applications - Proposal Type</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Season_of_Code_2009_-_Applications_-_Proposal_Type&amp;diff=66117"/>
				<updated>2009-07-16T11:12:24Z</updated>
		
		<summary type="html">&lt;p&gt;Marc Chisinevski: Asset management (asset identification, valuation and risk assessment based on ISO27005): integration with opensource Security Information Management systems is currently being discussed.  Party manag&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Suggested Proposal Type  =&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 95%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(64, 88, 160) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Suggested Proposal Type'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Description''' &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''To be filled in below'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Applicant's Identification/Project Release Leader&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Marc Chisinevski&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Designation/Name &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | assetmng&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | First (proposed) Reviewer&amp;lt;br&amp;gt; &lt;br /&gt;
([[OWASP Season of Code 2009 - Applications - Proposal Type Applicant's Identification|''Please see specifications'']]) &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Kate Hartmann&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Application Security Issue Addressed &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Asset identification, valuation and risk assessment (ISO 27005)&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Prioritized area&amp;lt;br&amp;gt;(''Please choose from'' [[OWASP Season of Code 2009#HOW_TO_PARTICIPATE_.28TO_DEVELOPERS.29|''here'']]) &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Enterprise usability&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Project Release Roadmap&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(179, 179, 179) none repeat scroll 0% 0%; width: 30%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Other Questions &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(194, 194, 194) none repeat scroll 0% 0%; width: 70%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Please see: http://sourceforge.net/projects/assetmng/&amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Marc Chisinevski</name></author>	</entry>

	</feed>