作者: Pancrazio De Mauro , Francesco Bergadano
DOI:
关键词:
摘要: A method and apparatus for verifying the correctness of server access logs. The is required to transfer relevant log information each client request to, an authentication device. In a preferred embodiment, device has be tamper-evident responds with Message Authentication Code (MAC) binary digit B. MAC stored on accessible medium by server. If B=0, processed normally. B=1 (this happens small probability), issue “redirect” response client, instructing it connect different server, controlled certification agency. agency's logs this redirects back original where eventually serviced. agency periodically verifies checks whether requests correspond associated entry its does not happen in high number cases, file could denied, based policy. embodiment invention HTTP protocol, auditing Web site popularity.