Rethinking Tamper-Evident Logging: A High-Performance, Co-Designed Auditing System

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhao, Rui, Shoaib, Muhammad, Hoang, Viet Tung, Hassan, Wajih Ul
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915482716602368
author Zhao, Rui
Shoaib, Muhammad
Hoang, Viet Tung
Hassan, Wajih Ul
author_facet Zhao, Rui
Shoaib, Muhammad
Hoang, Viet Tung
Hassan, Wajih Ul
contents Existing tamper-evident logging systems suffer from high overhead and severe data loss in high-load settings, yet only provide coarse-grained tamper detection. Moreover, installing such systems requires recompiling kernel code. To address these challenges, we present Nitro, a high-performance, tamper-evident audit logging system that supports fine-grained detection of log tampering. Even better, our system avoids kernel recompilation by using the eBPF technology. To formally justify the security of Nitro, we provide a new definitional framework for logging systems, and give a practical cryptographic construction meeting this new goal. Unlike prior work that focus only on the cryptographic processing, we codesign the cryptographic part with the pre- and post-processing of the logs to exploit all system-level optimizations. Our evaluations demonstrate Nitro's superior performance, achieving 10X-25X improvements in high-stress conditions and 2X-10X in real-world scenarios while maintaining near-zero data loss. We also provide an advanced variant, Nitro-R that introduces in-kernel log reduction techniques to reduce runtime overhead even further.
format Preprint
id arxiv_https___arxiv_org_abs_2509_03821
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Rethinking Tamper-Evident Logging: A High-Performance, Co-Designed Auditing System
Zhao, Rui
Shoaib, Muhammad
Hoang, Viet Tung
Hassan, Wajih Ul
Cryptography and Security
Existing tamper-evident logging systems suffer from high overhead and severe data loss in high-load settings, yet only provide coarse-grained tamper detection. Moreover, installing such systems requires recompiling kernel code. To address these challenges, we present Nitro, a high-performance, tamper-evident audit logging system that supports fine-grained detection of log tampering. Even better, our system avoids kernel recompilation by using the eBPF technology. To formally justify the security of Nitro, we provide a new definitional framework for logging systems, and give a practical cryptographic construction meeting this new goal. Unlike prior work that focus only on the cryptographic processing, we codesign the cryptographic part with the pre- and post-processing of the logs to exploit all system-level optimizations. Our evaluations demonstrate Nitro's superior performance, achieving 10X-25X improvements in high-stress conditions and 2X-10X in real-world scenarios while maintaining near-zero data loss. We also provide an advanced variant, Nitro-R that introduces in-kernel log reduction techniques to reduce runtime overhead even further.
title Rethinking Tamper-Evident Logging: A High-Performance, Co-Designed Auditing System
topic Cryptography and Security
url https://arxiv.org/abs/2509.03821