Session-level application auditing method and system

A session-level, application-specific technology, applied in transmission systems, digital transmission systems, electrical components, etc., can solve the problems of high construction costs, affecting the normal communication between operation and maintenance terminals and operation and maintenance hosts, and high system maintenance costs, achieving easy maintenance. Effect

Active Publication Date: 2014-10-29
北京华夏威科软件技术有限公司
View PDF4 Cites 10 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0010] (1) It is necessary to change the user's existing network structure and deploy additional physical network nodes. However, because the user's network structure varies greatly and the complexity is high, it is difficult to deploy additional physical network nodes and the construction cost is high , in special cases, it is not even possible to deploy physical network nodes; therefore, it has great limitations in use;
[0011] (2) Since the communication messages between the operation and maintenance terminal and the operation and maintenance host need to go through the proxy host, the reliability of the proxy host is extremely high; once the proxy host itself fails, it will directly affect the operation and maintenance

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Session-level application auditing method and system
  • Session-level application auditing method and system

Examples

Experimental program
Comparison scheme
Effect test

Embodiment 1

[0110] The session-level application auditing system provided by the present invention is deployed on a certain target operation and maintenance server, and the target operation and maintenance server is a server running a linux or unix operating system.

[0111] Build a Windows system operation and maintenance springboard machine, which is the operation and maintenance terminal; then open the maintenance software on the springboard machine, such as SecureCRT.exe or PUTTY.exe. The springboard machine sends operation behavior data to the target operation and maintenance server through the operation and maintenance software. The session-level application audit system arranged on the operation and maintenance server realizes the audit work on the target operation and maintenance servers of linux and unix by recording the operation behavior data of applications such as SecureCRT.exe and PUTTY.exe in windows sessions.

[0112]Specifically, the session-level application audit system...

Embodiment 2

[0115] Open the SSH terminal to maintain the operation and maintenance server of the linux host. The operation and maintenance terminal opens the SecureCRT or PUTTY.exe operation and maintenance software on Windows, and then connects to the target operation and maintenance server; it has been verified that no matter what version the operation and maintenance terminal sends to the operation and maintenance server Behavior data can be accurately recorded by the session-level application audit system arranged on the operation and maintenance server. The recorded audit data includes: account name, time stamp, application name, application title, screen video frame and operation behavior data. Retrieve audit data, and can automatically play to the screen video frame when the operation behavior occurred.

[0116] In summary, a session-level application auditing method and system provided by the present invention has the following advantages:

[0117] (1) The session-level applicatio...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention provides a session-level application auditing method and system. The system comprises an auditing strategy definition module, a session monitoring module, a capturing module, an acquiring module, a performing module and a mapping relation allocation table, wherein the auditing strategy definition module and the session monitoring module are used to a session layer for monitoring the progress of each application running in an operation maintenance server; the capturing module is used for capturing operation behavior data on real time; the performing module is used for acquiring various auditing data; the mapping relation allocation table is used for storing a mapping relation between the storage operation behavior data and the auditing information. The system is arranged at a target server suffering from auditing and used for monitoring the application progress at the session layer of the operation system; the specific session production protocol is irrelevant, no change is performed for the existing network structure, and the maintenance is easily carried out; the operation behavior data, screen video frames, account names, timestamps, and corresponding relation of the application program names can be quickly and conveniently found out without connecting with any third-party account system; in addition, the video frames produced as the operation behavior appears can be displayed, and thus the operation scene of the time can be recovered truly.

Description

technical field [0001] The invention belongs to the technical field of server operation behavior auditing, and in particular relates to a session-level application auditing method and system. Background technique [0002] At present, the IT system of an enterprise is complex, often including a large number of operation and maintenance hosts and a large number of operation and maintenance terminals. Each operation and maintenance terminal sends operation instructions to the operation and maintenance host, and then remotely operates and controls each operation and maintenance host. Therefore, effectively monitoring the operation behavior of each operation and maintenance terminal on the operation and maintenance host is an important means for enterprises to control internal risks. [0003] In the prior art, mainstream fine-grained to operational behavior, non-log event audit products generally adopt a proxy login mode. That is: deploy a proxy host on a certain communication n...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
IPC IPC(8): H04L29/08H04L12/24H04L29/06
Inventor 李小龙郭晓东
Owner 北京华夏威科软件技术有限公司
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products