Web Proxy Logs Analysis
The web proxy is one of the most critical network security controls deployed in the network as it is necessary to manage and control communications between internal users and web servers. To do so, the web proxy gets visibility of web communication aspects such as the accessed domain and web resources, web category, and user agent, which allows the proxy to generate useful logs to allow cybersecurity professionals to detect and investigate several threats, such as access to malicious websites and C&C communications. As a SOC analyst, you should be aware and take advantage of the logs provided by the web proxy and be able to analyze them to investigate cyber incidents.
The objective of this chapter is to learn the value of the web proxy logs and the provided information in the proxy logs and understand the valuable fields of the proxy logs, such as the log timestamp, source IP, source port, destination IP, destination port, response status code, username...