skip to content

An executive reads empty border firewall logs after an internal intrusion as proof the controls held - how do you answer, and what would have to be in the path before a record could exist?

level: seniorimportance: nice to knowfreq 30%

answer

  1. off the path means no evidence
  2. not weak evidence - none
  3. four reasons a log is empty
  4. flow records carry counts, not payload
  5. the gap is a budget line

basics

~20 s

Empty border logs prove only that the traffic did not cross the border. A control that is not on the path produces no evidence in either direction. A record of interior movement exists only once you fund a routed hop and a device that inspects it.

solid answer

~60 s

The border firewall did its job and reported honestly: nothing crossed it during the window. That is a different claim from the intruder being contained. Lateral movement inside one office subnet is forwarded by access switches and never presented to a layer-3 device, so no rule could match, no log line could be written, and the silence carries no information about what happened. Even flow export from the core only covers what the core routed, and a flow record carries the five-tuple, counts and timestamps but no payload - it can show that bytes moved, never what they were. The correction to offer is not more tuning at the edge: for interior movement to leave a record at all, the populations have to be in different subnets with the traffic routed through a device that inspects and logs it. That is a purchase, a redundant pair and a re-addressing project, and until it is funded, `we saw nothing` is a fact about the topology rather than about the adversary.

code

text · 10 lines
text
# exported flow record (routed traffic only)
sourceIPv4Address=10.20.4.31   destinationIPv4Address=198.51.100.20
sourceTransportPort=51221      destinationTransportPort=443
protocolIdentifier=6
octetDeltaCount=8214           packetDeltaCount=41
flowStartMilliseconds=...      flowEndMilliseconds=...
...
# 10.20.4.31 -> 10.20.4.87 (same subnet, forwarded by the access switch):
#   no record here at all
# and for the flows that ARE present, no field carries payload

go deeper

for a junior

Remember that a log only records what a device actually handled, so a quiet border log during an internal incident is expected rather than surprising.

for a middle

Be able to list the reasons a log can be empty - off the path, no rule, collection failure, nothing happened - and say which one applies here and why.

for a senior

Show you can defend the claim in a review: credit the control, state the topology as a fact, and immediately name what an interior record would cost to produce.

for a principal

Own the reframe that the gap is an unfunded design decision, and force an explicit choice between paying for an interior chokepoint and accepting unobserved interior movement in writing.

## The claim being made, and the claim the evidence supports The executive's inference is: no alerts, no log entries, therefore the controls worked. What the evidence actually supports is much narrower: **during the window, nothing the border firewall handled matched a rule that would have logged it.** The border only handles traffic crossing between the campus and the outside. An intruder moving between two workstations in the same office subnet generates traffic that is forwarded host-to-host by access switches and never handed to a layer-3 device at all. The general form is worth stating plainly in the room, because it recurs everywhere: **the absence of a record from a control that is not on the path proves nothing.** It is not weak evidence; it is no evidence. Distinguish that carefully from the other three things silence can mean, because the responses differ completely: | Why the log is empty | What it means | What you do | |---|---|---| | The control is not on the path | No evidence either way | Change the topology, or accept the gap knowingly | | The control is on the path but has no rule for it | A coverage gap | Write the rule | | The control is on the path and the record never arrived | A collection failure | Fix the pipeline and check for other silent sources | | The control is on the path and the traffic did not occur | Genuine negative evidence | Trust it, within that control's visibility | Only the last is reassurance, and this case is the first. ## What the campus core can and cannot tell you A reasonable next question is whether flow export from the core fills the gap. Partly, and it is worth being precise: - The core exports records for traffic it forwarded. Same-subnet conversations handled entirely by an access switch and its uplinks are not in that set. - A flow record carries source and destination addresses, ports, protocol, byte and packet counts and start and end timestamps. It carries **no payload**. It can establish that bytes moved between two endpoints; it cannot establish what was sent, whether it succeeded, or whether the session was authorised. So flow data can sometimes show a workstation talking to hosts it never talked to before - genuinely useful - but it is not a substitute for an enforcement point and it does not exist for the intra-subnet portion of the movement. ## Saying it without sounding defensive The conversation goes badly if it sounds like excuse-making. Three moves keep it straight: 1. **Credit the control for what it did.** The border performed correctly. It is not broken and it does not need tuning. 2. **State the topology as a fact, not a failure.** The traffic in question was structurally incapable of reaching it. Nobody made a mistake operating it; the estate has no interior enforcement point because none was ever built. 3. **Name the price of the alternative immediately.** A record of interior movement requires a routed hop between the populations and a device on that hop that inspects and logs. That means re-addressing, a device sized for east-west volume, and a redundant partner so that an interior control failure does not stop the office. Bring the number, not the grievance. ## The reframe that lands `We saw nothing` and `nothing happened` are different sentences, and the gap between them is a budget line that has never been approved. Presenting it that way turns a post-incident argument into a design decision with an owner: either the organisation funds an interior chokepoint where it matters most, or it accepts, explicitly and in writing, that interior movement is unobserved. Both are defensible positions. Believing the empty log is not.

  • Distinguish the two readings of an empty log that lead to completely different responses.
    If the control was on the path and simply had nothing to report, the silence is real negative evidence within that control's visibility. If the control was never on the path, the silence is uninformative and tuning it wastes effort. The first question to answer after any quiet window is therefore whether the traffic could physically have reached the device.
  • Does flow export from the core close this gap?
    Only partially. The core exports what it routed, so intra-subnet conversations handled by access switches are absent, and a flow record carries the five-tuple, counts and timestamps but no payload. It can show that a workstation suddenly talked to hosts it never touched before, which is useful, but it is not an enforcement point and it cannot say what was sent.
  • What do you actually ask the executive to decide?
    Whether to fund an interior chokepoint at a named boundary, with the sizing and redundancy that implies, or to accept in writing that interior movement is unobserved. Framing it as a choice with a price puts an owner on the gap; framing it as a failure of the security team leaves the gap exactly where it is.

A camera pointed at the front gate that recorded nothing tells you the gate was quiet. It is not a statement about the corridor it has never been able to see.

saying these in an interview costs you the question

  • Treats an empty log from an off-path control as assurance
  • Promises to tune the border after an interior incident
  • Claims flow records show what was sent
  • Says the intruder evaded the perimeter
  • Confuses no detection with no activity

context