{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,6]],"date-time":"2026-06-06T09:02:19Z","timestamp":1780736539236,"version":"3.54.1"},"reference-count":31,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2026,6,6]],"date-time":"2026-06-06T00:00:00Z","timestamp":1780704000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Digital Threats"],"published-print":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>Log messages can play a significant role in different activities, including debugging, monitoring, and security analysis. Yet, they are often placed only for the convenience of development rather than for security relevance. For reliable logging to support security and forensic investigations, logs should be positioned along all execution paths that lead to critical operations that process untrusted user input. This placement ensures that any such operation leaves a reliable and observable trace for forensic trail. In this article, we present BlindSpot, an automated static analysis tool to extract inter-procedural paths where the parameters of critical calls appear within a log statement. Our approach incorporates dataflow and control-flow analysis to precisely capture the relationships between program nodes and model those log elements that are consistently encountered from input to untrusted critical calls (pre-execution), as well as those that always follow afterward (post-execution). We tested our approach on 10 desktop applications, containing 124 sensitive operations that process untrusted input. Our tool revealed significant inconsistencies in logging practices: only 37 of these actions (29.8%) have any associated log statements, and just 8 are logged prior to execution. This reliance on post-execution logging presents a risk because if a critical operation is exploited or causes a crash or failure, the log statements that follow may never execute, leaving no trace for forensic analysis. We also find that log statements are very often conditional and executed only along specific paths. In our analysis, we found that only 5 out of 124 critical operations (4%) are associated with an unconditional log. Through BlindSpot, we demonstrate how the inconsistency, conditionality, and absence of logs around critical operations raise concerns about the reliability of logs as a source of evidence.<\/jats:p>","DOI":"10.1145\/3812653","type":"journal-article","created":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T13:49:14Z","timestamp":1778161754000},"page":"1-16","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["An Automated Approach to Reveal Missing Logs around Sensitive Operations"],"prefix":"10.1145","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-3499-7913","authenticated-orcid":false,"given":"Afiqah","family":"M. Azahari","sequence":"first","affiliation":[{"name":"Security Department, EURECOM, Sophia Antipolis, France and Cyber Security Center, National Defence University of Malaysia, Kuala Lumpur, Malaysia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5957-6213","authenticated-orcid":false,"given":"Davide","family":"Balzarotti","sequence":"additional","affiliation":[{"name":"Security Department, EURECOM, Sophia Antipolis, France"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,6]]},"reference":[{"key":"e_1_3_1_2_2","first-page":"125","volume-title":"Proceedings of the 2019 IEEE International Conference on Software Maintenance and Evolution","author":"Anu Han","year":"2019","unstructured":"Han Anu, Jie Chen, Wenchang Shi, Jianwei Hou, Bin Liang, and Bo Qin. 2019. An approach to recommendation of verbosity log levels based on logging intention. In Proceedings of the 2019 IEEE International Conference on Software Maintenance and Evolution. IEEE, 125\u2013134."},{"key":"e_1_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.fsidi.2024.301750"},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/2591062.2591175"},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24270"},{"key":"e_1_3_1_6_2","unstructured":"Joern Project. 2025. Joern: Open-source code analysis platform. Retrieved May 23 2025 from https:\/\/github.com\/joernio\/joern"},{"key":"e_1_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1145\/2746194.2746200"},{"key":"e_1_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-016-9449-1"},{"key":"e_1_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.5555\/2696523.2696527"},{"key":"e_1_3_1_10_2","volume-title":"Proceedings of the 20th Annual Network and Distributed System Security Symposium","author":"Lee Kyu Hyung","year":"2013","unstructured":"Kyu Hyung Lee, Xiangyu Zhang, and Dongyan Xu. 2013. High accuracy attack provenance via binary-based execution partition. In Proceedings of the 20th Annual Network and Distributed System Security Symposium. Internet Society."},{"key":"e_1_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-018-9595-8"},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2020.2970422"},{"key":"e_1_3_1_13_2","doi-asserted-by":"publisher","DOI":"10.3390\/app10051692"},{"key":"e_1_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/3643754"},{"key":"e_1_3_1_15_2","first-page":"129","volume-title":"Proceedings of the 2023 38th IEEE\/ACM International Conference on Automated Software Engineering","author":"Li Zhenhao","year":"2023","unstructured":"Zhenhao Li, An Ran Chen, Xing Hu, Xin Xia, Tse-Hsun Chen, and Weiyi Shang. 2023. Are they all good? Studying practitioners\u2019 expectations on the readability of log messages. In Proceedings of the 2023 38th IEEE\/ACM International Conference on Automated Software Engineering. IEEE, 129\u2013140."},{"key":"e_1_3_1_16_2","doi-asserted-by":"publisher","DOI":"10.1145\/3324884.3416636"},{"key":"e_1_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/3533767.3534379"},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23350"},{"key":"e_1_3_1_19_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.fsidi.2025.301877"},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/REW.2019.00033"},{"key":"e_1_3_1_21_2","doi-asserted-by":"publisher","DOI":"10.1145\/3407023.3407081"},{"key":"e_1_3_1_22_2","first-page":"171","volume-title":"Proceedings of the 2018 25th Australasian Software Engineering Conference (ASWEC)","author":"Rong Guoping","year":"2018","unstructured":"Guoping Rong, Shenghui Gu, He Zhang, Dong Shao, and Wanggen Liu. 2018. How is logging practice implemented in open source software projects? A preliminary exploration. In Proceedings of the 2018 25th Australasian Software Engineering Conference (ASWEC). IEEE, 171\u2013180."},{"key":"e_1_3_1_23_2","unstructured":"Nyyti Saarim\u00e4ki Donghwan Shin and Domenico Bianculli. 2024. Taxonomy of software log smells. arXiv:2412.09284. Retrieved from https:\/\/arxiv.org\/abs\/2412.09284"},{"key":"e_1_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.1145\/3634737.3637647"},{"key":"e_1_3_1_25_2","doi-asserted-by":"publisher","DOI":"10.5555\/3620237.3620261"},{"key":"e_1_3_1_26_2","volume-title":"Proceedings of the 10th USENIX Symposium on Operating Systems Design and Implementation","author":"Yuan Ding","year":"2012","unstructured":"Ding Yuan, Soyeon Park, Peng Huang, Yang Liu, Michael M. Lee, Xiaoming Tang, Yuanyuan Zhou, and Stefan Savage. 2012. Be conservative: Enhancing failure diagnosis with proactive logging. In Proceedings of the 10th USENIX Symposium on Operating Systems Design and Implementation."},{"key":"e_1_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/2110356.2110360"},{"key":"e_1_3_1_28_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24549"},{"key":"e_1_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-019-09687-9"},{"key":"e_1_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.3390\/app11073201"},{"key":"e_1_3_1_31_2","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132778"},{"key":"e_1_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2015.60"}],"container-title":["Digital Threats: Research and Practice"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3812653","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,6]],"date-time":"2026-06-06T08:38:09Z","timestamp":1780735089000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3812653"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,6]]},"references-count":31,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2026,6,30]]}},"alternative-id":["10.1145\/3812653"],"URL":"https:\/\/doi.org\/10.1145\/3812653","relation":{},"ISSN":["2692-1626","2576-5337"],"issn-type":[{"value":"2692-1626","type":"print"},{"value":"2576-5337","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,6]]},"assertion":[{"value":"2025-09-25","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-04-07","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-06-06","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}