Data management device, data management method, and computer-readable recording medium on which computer program for executing data management method in computer is stored
The data management system addresses the challenges of interpreting complex data packets and log data in ERP systems by implementing protocol-specific analysis and personal information extraction, enhancing data security and efficiency in log management.
Patent Information
- Application Number
- PCT/KR2025/001185
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-08
- Filing Date
- 2025-01-22
- Publication Date
- 2025-10-16
AI Technical Summary
Existing data management systems, particularly in ERP systems like SAP, struggle to effectively interpret and analyze complex data packets and log data, leading to challenges in understanding packet meaning, processing large volumes of log data, and ensuring data security and personal information extraction.
A data management method and device that includes packet collection, analysis, and monitoring, featuring protocol-specific analysis, XML data generation, and audit log storage, with capabilities for personal information extraction, encryption, and access control, utilizing a data management platform with modules for collection, analysis, key management, personal information protection, and AI-driven insights.
Enhances data security, improves personal information extraction accuracy, enables real-time decryption and encryption, facilitates user-friendly regular expression assistance, and accelerates search and export processes, while ensuring stability and accuracy of log records.
Smart Images

Figure KR2025001185_16102025_PF_FP_ABST
Abstract
Description
A computer-readable recording medium storing a data management device, a data management method, and a computer program for executing the data management method on a computer
[0001] The present invention relates to a data management device, a data management method, and a computer-readable recording medium storing a computer program for executing the data management method on a computer.
[0002]
[0003] As technological advancements increase the volume and variety of data, the importance of data management is becoming increasingly apparent. Data management refers to how businesses and organizations effectively collect, store, analyze, and utilize data.
[0004] Enterprise Resource Planning (ERP) systems, which comprehensively manage a company's core functions, are widely used as tools for efficiently managing critical data within the company. They integrate key corporate functions, such as budget management, production management, inventory management, and purchasing management, allowing for effective operation within a single system. SAP products are a prime example of such ERP systems.
[0005] However, in existing systems, it can be difficult to directly understand the meaning of packets generated during server communication using standard analysis methods. This is especially true in systems like SAP, which exchange data using complex data structures and specific protocols. Therefore, extracting or interpreting meaningful values from packets becomes even more challenging. Therefore, a more specific approach to packet analysis is needed.
[0006] Additionally, log data comes from a variety of sources. For example, log data is recorded to monitor the operation of a system or application, used to monitor the security status of a system and track user activity, and used to track and debug errors occurring in an application.
[0007] Additionally, log data is utilized in business analytics to aid decision-making. For example, it can be used to analyze customer behavior, marketing effectiveness, and quality control. This generates large amounts of log data, and efficiently processing and analyzing this data becomes a critical task.
[0008]
[0009] Accordingly, the present invention aims to provide a data management device, a data management method, and a computer-readable recording medium storing a computer program for executing the data management method on a computer to solve the problems of the existing technology.
[0010]
[0011] An embodiment of the present invention provides a data management method, comprising: a step of collecting packets; a step of analyzing the collected packets; and a step of monitoring the analyzed packets; wherein the step of analyzing comprises: a step of receiving data; a step of analyzing a TCP packet of the received data; a step of analyzing the data based on a protocol of the data to generate XML data for at least one of a request screen and a response screen and storing the XML data in an audit log; and a step of analyzing a code included in the XML data and outputting the code to a user screen when there is a request to view the stored audit log.
[0012] The analyzing step includes: receiving first data from a proxy server that processes data transmitted and received via one of the HTTP protocol, the SAP GUI protocol, and the RFC protocol; analyzing a protocol of the received first data; and generating a log from the analyzed first data; wherein the proxy server is characterized in that, when data is received via the SAP GUI protocol and the RFC protocol, it processes the NI (Network Interface) protocol to transmit and receive a request from a client.
[0013] The analyzing step includes a step of decompressing packets collected from at least one agent installed on a cloud server; and a step of analyzing the decompressed packets based on a protocol of the packets; wherein the packets collected from the at least one agent are loaded into a netfilter queue and then distributed to a transmission queue, and the packets distributed to the transmission queue are merged into a first unit and compressed.
[0014] The analyzing step includes: receiving first data; analyzing a protocol of the received first data; filtering the first data using an HTTP processing script when the protocol of the first data is an HTTP protocol; and deleting third data included in second data corresponding to WEBGUI among HTTP data that is not filtered using the HTTP processing script from the first data to generate fourth data; wherein the third data is a value that can be extracted according to a preset condition.
[0015] The above analyzing step is characterized by including: a step of detecting access to a user's computing system in a data management platform that controls at least one engine or module included in a data management software package; and a step of transmitting an access control request for blocking the user's access to an application server for the computing system based on pre-stored access control information.
[0016] One embodiment of the disclosure provides a data management device comprising: a database for storing data; and a processor for processing the data, wherein the processor receives data, analyzes a TCP packet of the received data, analyzes the data based on a protocol of the data, generates XML data for at least one of a request screen and a response screen, and stores the XML data in an audit log; and, when there is a request to view the stored audit log, analyzes a code included in the XML data and outputs the analyzed code to a user screen.
[0017] An embodiment of the present invention provides a computer-readable recording medium storing a computer program for executing a data management method on a computer, the method comprising: collecting packets; analyzing the collected packets; and monitoring the analyzed packets, wherein the analyzing step comprises: receiving data; analyzing a TCP packet of the received data; analyzing the data based on a protocol of the data to generate XML data for at least one of a request screen and a response screen and storing the XML data in an audit log; and, when a request for viewing the stored audit log is received, analyzing a code included in the XML data and outputting the code to a user screen.
[0018]
[0019] According to one embodiment of the present invention, an innovative technology for data management in an ERP system can be provided to satisfy the needs of enterprises for data security and monitoring.
[0020] In addition, according to one embodiment of the present invention, there is an advantage in that all access records to the server are created as logs, thereby ensuring stability of log records.
[0021] In addition, according to one embodiment of the present invention, there is an advantage in that the accuracy of personal information extraction can be increased through a multidimensional extraction method using personal information metadata and an exception handling list.
[0022] Additionally, according to one embodiment of the present invention, there is an advantage in that user actions can be mapped to all log data containing personal information.
[0023] Additionally, according to one embodiment of the present invention, there is an advantage in that a large amount of personal information data can be decrypted and re-encrypted in real time.
[0024] In addition, according to one embodiment of the present invention, it is possible to provide convenience to users who have difficulty entering regular expressions by partially assisting them in entering regular expressions and completing the entire regular expression.
[0025] In addition, according to one embodiment of the present invention, a convenient function for scanning a pre-registered parser can be provided so as to increase the reusability of the registered parser.
[0026] In addition, according to one embodiment of the present invention, there is an advantage in that a large amount of data can be searched simultaneously and the results can be confirmed in real time.
[0027] Additionally, only blocks containing at least one log data requested by a user / client among the entire compressed log data can be decompressed.
[0028] In addition, according to one embodiment of the present invention, the export / import process can be greatly shortened by enabling the entire log data to be searched without decompression by using compression information and block offset information.
[0029]
[0030] FIG. 1 is a drawing disclosing hardware for explaining a data management device of the present invention.
[0031] FIG. 2 is a drawing disclosing one embodiment of a data management device of the present invention.
[0032] FIG. 3 is a diagram disclosing one embodiment of the data management platform of the present invention.
[0033] FIG. 4 is a drawing disclosing one embodiment of a data management method of the present invention.
[0034] FIG. 5 is a diagram disclosing an embodiment of extracting personal information from data included in an analyzed packet of the present invention.
[0035] FIG. 6 is a diagram disclosing an embodiment of visualizing data included in an analyzed packet of the present invention.
[0036] FIG. 7 is a diagram disclosing one embodiment of searching data included in an analyzed packet of the present invention.
[0037] FIG. 8 is a diagram illustrating an embodiment in which the data management platform of the present invention stores and monitors audit logs.
[0038] FIG. 9 is a drawing illustrating an embodiment of a data management method of the present invention for distributing collected packets.
[0039] FIG. 10 is a diagram illustrating an embodiment in which the data management platform of the present invention analyzes HTTPS-based packets.
[0040] FIG. 11 is a diagram illustrating an embodiment of a data management method of the present invention analyzing HTTPS-based packets.
[0041] Figure 12 is a drawing illustrating an embodiment of extracting and storing personal information in the data management platform of the present invention.
[0042] Figure 13 is a diagram illustrating an example of personal information metadata defined in the data management platform of the present invention.
[0043] Figure 14 is a drawing illustrating an example of extracting personal information by distinguishing architecture types in the data management platform of the present invention.
[0044] FIG. 15 is a diagram illustrating an example of creating a personal information extraction rule in the data management platform of the present invention.
[0045] FIG. 16 is a diagram illustrating an example of creating a personal information exception processing list in the data management platform of the present invention.
[0046] FIG. 17 is a diagram illustrating an embodiment of creating an exception filter of the data management platform of the present invention.
[0047] FIG. 18 is a diagram illustrating another embodiment of the data management method of the present invention for extracting and storing personal information.
[0048] FIG. 19 is a diagram illustrating an embodiment of collecting and mapping user behavior in the data management platform of the present invention.
[0049] FIG. 20 is a diagram illustrating an embodiment of generating user behavior metadata in the data management platform of the present invention.
[0050] FIG. 21 is a diagram illustrating an embodiment of mapping user behavior metadata and log data in the data management platform of the present invention.
[0051] Figure 22 is a drawing illustrating an embodiment of encrypting personal information in the data management platform of the present invention.
[0052] Figure 23 is a drawing illustrating an embodiment of encrypting personal information in the data management platform of the present invention.
[0053] Figure 24 is a drawing explaining the mapping information table and work table of the present invention.
[0054] FIG. 25 is a diagram illustrating an embodiment of generating a new encryption key in the data management platform of the present invention.
[0055] FIG. 26 is a drawing illustrating an embodiment of adding new business data to the data management platform of the present invention.
[0056] Figure 27 is a diagram illustrating an embodiment in which the data management platform of the present invention normalizes log data.
[0057] FIG. 28 is a drawing illustrating an embodiment of a data management method of the present invention for generating a parser.
[0058] Figure 29 is a drawing illustrating one embodiment of a parser generation screen of the present invention.
[0059] FIG. 30 is a drawing illustrating an embodiment of a data management method of the present invention for generating a conversion rule.
[0060] FIG. 31 is a diagram illustrating an embodiment of a data management method of the present invention for generating a collection path rule.
[0061] FIG. 32 is a drawing illustrating an embodiment of a data management method of the present invention for searching an event log.
[0062] FIG. 33 is a diagram illustrating an embodiment of searching a log in a data management platform of the present invention.
[0063] Figure 34 is a drawing illustrating an embodiment of the external merge sort algorithm of the present invention.
[0064] Figure 35 is a drawing illustrating an example of analyzing data in the data management platform of the present invention.
[0065] Figure 36 is a drawing illustrating a user interface of an analysis task editor provided in the data management platform of the present invention.
[0066] Figure 37 is a drawing illustrating a user interface of an analysis task editor provided in the data management platform of the present invention.
[0067] Figure 38 is a drawing illustrating a user interface of an analysis task editor provided in the data management platform of the present invention.
[0068] Figure 39 is a drawing illustrating an embodiment of a data management platform of the present invention storing and retrieving log data.
[0069] FIG. 40 is a diagram illustrating another embodiment of a data management platform of the present invention storing and retrieving log data.
[0070] Figure 41 is a conceptual diagram disclosing layer-by-layer elements for a data management device according to an embodiment.
[0071] FIG. 42 is a diagram illustrating an embodiment in which a data management device according to an embodiment monitors an agent.
[0072] Figure 43 is a flowchart of a data management method according to an embodiment.
[0073] FIG. 44 is a diagram illustrating an embodiment in which a proxy server according to one embodiment is connected to another cloud service.
[0074] Figure 45 is a diagram illustrating the function of a proxy server according to one embodiment.
[0075] FIG. 46 is a drawing illustrating another function of a proxy server according to one embodiment.
[0076] FIG. 47 is a diagram illustrating an embodiment of separating services within a proxy server according to one embodiment.
[0077] FIG. 48 is a diagram illustrating an example of scaling out a proxy server according to one embodiment.
[0078] FIG. 49 is a diagram illustrating an embodiment in which a proxy server processes the NI protocol according to one embodiment.
[0079] FIG. 50 is a diagram illustrating a proxy data collection process of a data management device according to one embodiment.
[0080] FIG. 51 is a diagram illustrating an embodiment in which a proxy server according to one embodiment is connected to another cloud service.
[0081] Figure 52 is a flowchart illustrating a data management method according to one embodiment.
[0082] Figure 53 is a drawing illustrating a data management device according to an embodiment.
[0083] Figure 54 is a drawing illustrating an example of the structure of WEBGUI data according to an embodiment.
[0084] Figure 55 is a diagram showing the HTML analysis results in WEBGUI data according to an embodiment.
[0085] Figure 56 is a diagram showing the HTML analysis results in WEBGUI data according to an embodiment.
[0086] Figure 57 is a diagram showing the original text of WEBGUI data according to an embodiment.
[0087] Figure 58 is a diagram showing XML data with unnecessary information removed according to an embodiment.
[0088] Figure 59 is a drawing explaining a data management method according to an embodiment.
[0089] FIG. 60 is a diagram disclosing an example of a data management platform according to an embodiment performing access control to a computing system.
[0090] FIG. 61 is a diagram disclosing another example of a data management platform according to an embodiment performing access control to a computing system.
[0091] Figure 62 is a drawing disclosing an example of an access control information input screen according to an embodiment.
[0092] Figure 63 is a drawing disclosing an example of an event processing rule screen according to an embodiment.
[0093] Figure 64 is a drawing disclosing an example of a correlation rule input screen according to an embodiment.
[0094] Figure 65 is a drawing disclosing an example of a correlation rule activation screen according to an embodiment.
[0095] Figure 66 is a drawing disclosing an example of a control data setting screen according to an embodiment.
[0096] Figure 67 is a flowchart showing an example of a data management method according to an embodiment of the present invention converting a data format.
[0097] Figure 68 is a drawing illustrating an embodiment in which a data management device according to an embodiment reproduces a screen.
[0098] Figure 69 is a drawing illustrating an example of reproducing a screen from data according to an embodiment.
[0099] FIG. 70 is a drawing illustrating an example of reproducing a screen from data according to an embodiment.
[0100] Figure 71 is a drawing illustrating an example of reproducing a screen from data according to an embodiment.
[0101] Figure 72 is a drawing illustrating an example of reproducing a screen from data according to an embodiment.
[0102] Figure 73 is a drawing illustrating a user screen reproduced by a data management device according to an embodiment.
[0103] Figure 74 is a drawing illustrating a user screen reproduced by a data management device according to an embodiment.
[0104] Figure 75 is a drawing illustrating a user screen reproduced by a data management device according to an embodiment.
[0105] FIG. 76 is a drawing illustrating an embodiment in which a data management device according to an embodiment reproduces a user screen.
[0106] Figure 77 is a drawing illustrating an embodiment in which a data management device according to an embodiment manages events and alarms.
[0107] FIG. 78 is a drawing illustrating an embodiment in which a data management device according to an embodiment searches for logs by event type or warning type and reproduces a user screen.
[0108] Figure 79 is a flowchart illustrating a data management method according to an embodiment.
[0109]
[0110] Hereinafter, various embodiments will be described in detail with reference to the drawings. The embodiments described below may be modified and implemented in various different forms. In order to more clearly explain the features of the embodiments, detailed descriptions of matters widely known to those of ordinary skill in the art to which the embodiments pertain below are omitted.
[0111] Meanwhile, when a component is said to be "connected" to another component in this specification, this includes not only cases where it is "directly connected" but also cases where it is "connected with another component in between." Furthermore, when a component is said to "include" another component, this does not mean that it excludes other components, but rather that it may include other components, unless otherwise specifically stated.
[0112] Additionally, terms including ordinal numbers, such as “first” or “second,” used herein may be used to describe various components, but the components should not be limited by the terms. The terms are used only for the purpose of distinguishing one component from another.
[0113] Furthermore, since the functional units included in each module are a logical structure for describing the function performed by the module, it goes without saying that the module can perform the function performed by each functional unit. In other words, each module need not include all the functional units included within the module, and can include at least one functional unit for performing the function.
[0114] Hereinafter, embodiments will be described in detail with reference to the attached drawings. In the embodiments, the framework, modules, application program interfaces, etc. may be implemented as physical devices combined with each other or as software. If the embodiments are implemented as software, they may be stored on a storage medium, installed on a computer, etc., and executed by a processor.
[0115]
[0116] FIG. 1 is a drawing disclosing hardware for explaining a data management device of the present invention.
[0117] This drawing illustrates an embodiment of data transmission and reception between hardware components related to the data management platform described below.
[0118] The present invention can be provided to users through a platform. To this end, a user / client (1000) can access a network device (1001) via a web browser or the like and utilize data and applications stored in a separate storage / database (1003) under the control of a computing server (1004).
[0119] More specifically, a user / client (1000) may request a service (e.g., data search, modification, deletion, etc.) through a client terminal, and may output data calculated through a computing server (1004) and received through a network device (1001) on a screen. In one embodiment, the user / client (1000) may include all objects that access the data management platform of the present invention. That is, in this drawing, the user / client (1000) may access the data management platform using the network device (1001), and is not limited by the network device (1001).
[0120] A network device (1001) mediates data transmission between a user / client (1000) and a computing server (1004). Here, the network device (1001) may include a router, a tap-to-access point (TAP), a switch, etc. The router transmits data using an IP address, and the switch transmits data using a MAC address. Here, a network device (1001), such as a router, can use a SPAN (Switched Port Analyzer) mode to mirror only a specific port and transmit packets to a data management platform (10000). This will be described in detail below.
[0121] A Test Access Point (TAP) can be used to collect data on a network. More specifically, a TAP is a network device (1001) that is added to the network backbone line and corresponds to a device that specializes in mirroring. In other words, packets can be transmitted to the data management platform (10000) of the present invention through a Network Test Access Point (TAP, hereinafter referred to as "TAP"). Accordingly, packets can be copied and transmitted to the data management platform without affecting the flow of data packets transmitted and received on the network.
[0122] Storage / database (1003) can store and manage data. Storage primarily uses hard disks or SSDs to store data, while the database manages structured data and can perform tasks such as searching and modifying it.
[0123] The computing server (1004) is responsible for data processing. It processes tasks requested from the client (1000) and returns the processing results to the client (10000). To this end, it can perform computational tasks using hardware such as a central processing unit (CPU) and RAM. Furthermore, the computing server (1004) controls the input / output of various data and can store data processed by the data management platform (10000) in a storage / database (1003). At this time, the functions performed by the data management platform (10000) of the present invention can be performed by the processor of the computing server (1004). Furthermore, the computing server (1004) may include a system manager that monitors and controls the status of hardware components or modules within the data management platform.
[0124] Hereinafter, the hardware components of this drawing can be used to implement the present invention, and of course, a data processing method between the hardware components is included.
[0125]
[0126] FIG. 2 is a drawing disclosing one embodiment of a data management device of the present invention.
[0127] An embodiment of this drawing illustrates a data management device, including physical components and logical components for describing the data management device.
[0128] In one embodiment, the present invention may be provided to users via a Software as a Service (SaaS) platform. A SaaS platform refers to software provided as a service to users via a network using cloud computing technology. To this end, a storage / database (1003), a computing server (1004), and a container platform (1005) may support users / clients (1000) to utilize a data management platform (10000) and a data management software package (20000) in the cloud.
[0129] The present invention can use a user / client (1000), a storage / database (1003), an application server (1002), a computing server (1004), a container platform (1005), a data management platform (10000), and a data management software package (20000) for data processing.
[0130] At this time, the storage / database (1003) and computing server (1004) may be hardware, and the application server (1002), container platform (1005), data management platform (10000), and data management software package (20000) may correspond to software. For hardware, refer to the above-described content, and with reference to this drawing, an embodiment of the data management device will be described as follows.
[0131] A user / client (1000) can access data management software (20000) for data processing.
[0132] The container platform (1005) can provide a virtual environment for data processing by being composed of an operating system (OS), a container, and docker.
[0133] The data management platform (10000) can control at least one engine or module included in the data management software package (20000). To this end, the data management platform (10000) can manage data using technologies such as an internal database (here, the database refers to the internal database within the data management software package (20000), storage, and a distributed file system. In addition, the data management platform (10000) can include a system manager or management console for managing at least one engine or module included in the data management software package (20000).
[0134] The data management software package (20000) may include at least one of a collection module (20001), an analysis module (20002), a key management module (20003), a personal information management module (20004), a monitoring module (20005), and an AI engine (20006). However, the modules and engines included in the data management software package (20000) are not essential components and are elements for explaining the present invention. Therefore, it is understood that modules with different names may be included to perform the data implementation examples.
[0135] The collection module (20001) can collect data from various sources and transmit the data to a processing pipeline. The collection module (20001) can collect data (e.g., packets) from various sources, such as logs, events, sensors, and web servers. In particular, the collection module (20001) can centrally manage agents when using agents for log collection.
[0136] The analysis module (20002) can be used to analyze data and derive valuable insights. The analysis module (20002) can analyze collected packets to extract data. If the data contained herein contains personal information, the personal information management module (20004) can provide functions related to personal information protection. Furthermore, the data contained herein can be mapped to previously collected behavioral information (e.g., including search, deletion, addition, modification, and output).
[0137] The key management module (20003) can generate, store, and manage keys for data encryption and decryption. The key management module (20003) can manage keys using technologies such as tokens, symmetric keys, public keys, and digital certificates. If the data contains personal information, the key management module (20003) can generate, store, and manage keys for encrypting and decrypting the personal information. In addition, the key management module (20003) can use technologies such as tokens, symmetric keys, public keys, and digital certificates to ensure data security even if the data does not contain personal information.
[0138] The personal information management module (20004) can provide functions related to personal information protection. If the data contains personal information, the personal information management module (20004) can control the collection, extraction, encryption, storage, processing, retrieval, and deletion of such personal information.
[0139] The monitoring module (20005) can perform data retrieval and detection. It can monitor data processing and the data processing environment and identify issues. Furthermore, it can monitor logs, performance indicators, events, and generate alerts.
[0140] The AI engine (20006) can perform data processing and analysis tasks using artificial intelligence technology (including machine learning). Specifically, if the collected and stored logs contain text, the AI engine (20006) can classify the collected text into actions based on artificial intelligence.
[0141]
[0142] FIG. 3 is a diagram disclosing one embodiment of the data management platform of the present invention.
[0143] The embodiment of this drawing illustrates a data management platform (10000), which includes a physical device and a logical component. In particular, the data management platform (10000) in this drawing can correspond to a wider range than the data management platform described above. For example, the data management platform (10000) can include at least one of the modules implemented in the data management software package (20000) described above, and can include an application programming interface (API) that runs on a physical device. For the physical device, refer to the above description.
[0144] The data management platform (10000) can perform the functions of the modules included in the data management platform (10000) by utilizing the resources of the computing server (1004) and the storage / database (1003). At this time, the system manager can control at least one of the modules or engines within the data management platform (10000), and the system manager can be located within the computing server (1004) or located separately to control the data management platform (10000).
[0145] The data management platform (10000) may include at least one of a collection module (20001), an analysis module (20002), a key management module (20003), a personal information management module (20004), a monitoring module (20005), and an AI engine (20006). The description of each module is as described above.
[0146] The data management platform (10000) transmits and receives data with a user / client (1000), and can apply at least one function performed by a collection module (20001), an analysis module (20002), a key management module (20003), a personal information management module (20004), a monitoring module (20005), and an AI engine (20006) to the transmitted and received data. At this time, the data management platform (10000) can independently use individual modules included in the data management platform (10000) at the request of the user / client (1000). For example, the user / client (1000) can selectively use only the functions of the key management module (20003) or the personal information management module (20004) within the data management platform (10000).
[0147] Additionally, although not shown in the drawing, the data management platform (10000) may use an internal database different from the external storage / database (1003) to perform the functions of the modules included therein.
[0148]
[0149] FIG. 4 is a drawing disclosing one embodiment of a data management method of the present invention.
[0150] In step (S1010), packets can be collected. In one embodiment, the method for collecting packets may utilize an agent-based, cloud-based packet collection method or a packet mirror-based packet collection method. A detailed description will be provided below.
[0151] In step (S1020), a filter may be applied to the collected packets. More specifically, the data management method of the present invention can reassemble and filter the collected packets and distribute them to an analysis process.
[0152] In step (S1030), packets to which a filter is applied can be analyzed.
[0153] Here, packets can be analyzed differently depending on the type of protocol they are based on. More specifically, in step (S1031), packets based on the RFC (Remote Function Call) protocol can be analyzed, in step (S1032), packets based on the GUI protocol can be analyzed, and in step (S1033), packets based on HTTP / HTTPS can be analyzed.
[0154] In step (S1031), packet analysis based on the RFC protocol refers to the process of analyzing packets using the RFC protocol on a network. RFC is a protocol and mechanism for performing function calls between different systems or computers in a distributed environment. RFC operates based on a client-server model, allowing a client to call a function on a server in a remote system and execute it remotely. In other words, since the RFC protocol is a communication protocol for remote function calls, packets using the RFC protocol contain information about these remote function calls.
[0155] In step (S1032), packet analysis based on the GUI protocol collects packets based on the GUI protocol that communicate between the client and the application server, and extracts the client IP or Port, server IP or Port, packet data (byte stream), etc. included in the packets.
[0156] In step (S1033), HTTP / HTTPS-based packet analysis is a method of extracting data contained in packets by mirroring or SSL processing packets transmitted and received between a web browser and a server.
[0157] Detailed analysis methods for each will be described later.
[0158] In step (S1040), personal information can be extracted from the analyzed packets using personal information metadata. In one embodiment, to determine whether the analyzed packets contain personal information, the personal information can be extracted using stored personal information metadata. This will be described later.
[0159] In step S1050, a log can be stored. At this time, meaningful information contained in the analyzed packets can be stored as a log. In one embodiment, the data management method can determine whether to store the analyzed information in an audit log. Additionally, if personal information is included, the personal information can be patterned and stored in a database. Finally, the data management method operates in a multithreaded manner to increase the log storage speed, and can perform memory queuing and file queuing in case the database is temporarily unavailable.
[0160] In step (S1060), abnormal behavior can be detected using the stored log. At this time, if abnormal behavior is detected, a new log recording information about the abnormal behavior detection can be created and the log can be saved again through step (S1050). In addition, the data management method can re-implement the screen of the collected data when an audit log is requested from the user. More specifically, the GUI protocol is a protocol used to display and interact with a graphical user interface. By analyzing such protocol, the user's work flow, input, output, etc. can be visually understood, and the operating status of the system can be identified and problems can be diagnosed. This will be described in detail in the drawings below.
[0161]
[0162] FIG. 5 is a diagram disclosing an embodiment of extracting personal information from data included in an analyzed packet of the present invention.
[0163] In one embodiment, the data management platform (10000) can extract personal information from an audit log (1033) including log data and an index using personal information metadata.
[0164] More specifically, the audit log (1033) is a collection of logs that record events occurring on a network and may include log data and an index. Here, the audit log (1033) may be a collection of log data for which index processing has been completed.
[0165] The data management platform (10000) can use personal information metadata to extract personal information from audit logs. Here, personal information metadata defines the format in which personal information is stored, the fields in which it is stored, and the regular expression patterns and masking patterns used for each type of personal information. For example, metadata can be configured for personal information types such as name, address, and phone number. Accordingly, the analysis module can identify and extract personal information from log data based on the personal information metadata.
[0166] In one embodiment, the extracted personal information may be encrypted according to a preset method for each type of personal information and stored again in an audit log (1033) or an internal database of the data management platform (10000). Further details will be provided below.
[0167] In one embodiment, the data management platform (10000) can use the extracted personal information to search log data for a specific period of time, and allow administrators or users to search or check the searched log data when necessary. This will be described later.
[0168]
[0169] FIG. 6 is a diagram disclosing an embodiment of visualizing data included in an analyzed packet of the present invention.
[0170] The data included in the packet analyzed through the above-described example is as follows.
[0171] (1) Session information: Start time, Duration Time, Log ID, Session ID, Context ID
[0172] (2) Connection information: Server IP, Server Port, Server Mac, Client IP, Client Port, Client Mac
[0173] (3) SAP information: SID, protocol, SAP instance, client
[0174]
[0175] *94
[0176] *(4) Program information: OK Code, T-code, Title App, Title Main
[0177] (5) CUA (Central User Administration) information: CUA Name, CUA Status
[0178] (6) User information: User ID, User UID, User name
[0179] (7) Event information: event category, event code, event name, event description, event value, notification level
[0180] (8) User-defined information: events, alerts, event types, number of events, number of alerts, architecture, presence of personal information, number of personal information types, number of personal information
[0181] In one embodiment, the data management platform can extract data, such as the above, from analyzed packets. If the data extracted from the packets contains personal information, the data management platform can encrypt and store the personal information. In particular, the data management platform can display the personal information on a separate screen.
[0182] Through this, all information required by law and certification (account information, access date and time, access location information, information on the subject processed, and tasks performed) can be collected. More specifically, account information can be determined through the user ID, employee number, and organization name in the user information; access date and time can be determined through the start time in the session information; access location information can be determined through the client IP or port in the access information; processed information can be determined through user-defined information (such as the presence of personal information, number of personal information, resident registration number, alien registration number, passport information, and card information); and tasks performed can be determined through program information and user-defined information.
[0183]
[0184] FIG. 7 is a diagram disclosing one embodiment of searching data included in an analyzed packet of the present invention.
[0185] In one embodiment, the data management platform can search the data described above and provide search results to the user.
[0186] To this end, the data management platform can provide a search interface, as shown in (a) of the drawing, to enable users to easily search. The data management platform can search data based on fields of the analyzed data. For example, data fields may include protocol, system, account, employee number, server IP, server port, client IP, client port, instance name, transaction name, program name, etc. In this case, the data management platform can search data based on at least one of the fields input by the user and output the search results.
[0187] In another embodiment, the data management platform may provide a query search function, as illustrated in (b) of the present drawing. For example, if a user inputs protocol_type=GUI as a first query and server_ip=175.117.145.125 as a second query, the data management platform may search for data based on the first and second queries.
[0188] In one embodiment, the search results may be output in the form of a “screen reproduction” or “data” as described above.
[0189]
[0190] FIG. 8 is a diagram illustrating an embodiment in which the data management platform of the present invention stores and monitors audit logs.
[0191] In one embodiment, the data management platform (10000) may convert and process the original data extracted according to the above-described embodiment according to defined field rules to generate an audit log (1033). Here, the generated audit log (1033) may be stored in a database (20007).
[0192] Additionally, the data management platform (10000) can extract personal information from processed data using personal information metadata. Accordingly, the data management platform (10000) can store audit logs (1033) and personal information in a database (20007), respectively. To this end, the analysis module (20002) may further include an audit log storage unit (2008).
[0193] In addition, the analysis module (20003) may further include a correlation analysis rule generation unit (2009). The data management platform (10000) may generate correlation analysis rules through the analysis module (20002). Here, the correlation rule may represent a rule for determining abnormal behavior. For example, the data management platform (10000) may determine that a case in which 1-2 data are input per second is normal behavior, and may determine that a case in which 10 or more data are input per second is abnormal behavior. Here, the expression “correlation” may represent a correlation between logs. At this time, the data management platform (10000) may generate another event (log) based on the correlation rule. The log at this time may be defined as an incident. That is, a subject who wants to monitor through the data management platform (10000) can create a correlation rule, and the data management platform (10000) can analyze logs based on the correlation rule and generate another login incident.
[0194] Additionally, correlation analysis rules can correspond to rules predefined by other platforms. Accordingly, the data management platform (10000) can analyze audit logs (1033) using the generated correlation analysis rules to generate abnormal behavior events. At this time, information about the generated correlation analysis rules and the abnormal behavior events can be stored in the database (20007).
[0195] The monitoring module (20005) of the data management platform (10000) may further include an abnormal behavior monitoring unit (2010). The abnormal behavior monitoring unit (2010) may search or monitor stored audit logs (1033), personal information, etc. based on generated abnormal behavior events.
[0196] Accordingly, the data management platform (10000) can extract personal information from the collected, analyzed, and stored data and use the extracted personal information to compile statistics on user behavior. If a violation occurs among the collected user behavior, the data management platform (10000) can block the user or issue a warning to the administrator.
[0197]
[0198] FIG. 9 is a drawing illustrating an embodiment of a data management method of the present invention for distributing collected packets.
[0199] In step (S10010), the data management method may collect packets and apply a filter. At this time, the data management method may collect packets via network equipment such as a NIC. Thereafter, the data management method may reassemble the collected packets and combine each network packet into an analyzable packet format.
[0200] In one embodiment, the data management method can determine whether to analyze packets based on filtering rules. Here, the filtering rules can be determined by the data management platform. More specifically, the data management method can collect packets through network devices, such as the aforementioned NIC or router. At this time, analyzing all collected packets may result in performance issues, so the packets to be analyzed can be filtered based on filtering rules. For example, packets based on HTTP or SAP GUI protocols may need to be analyzed, but packets collected using other protocols may not. In this case, the data management method can filter the collected packets to analyze only packets based on the desired protocol, by port or IP. At this time, the user can directly configure filtering rules using the data management method.
[0201] In step (S10020), the data management method can distinguish protocols based on TCP session information. As described above, the data management method can analyze collected packets by distinguishing them based on the protocol.
[0202] The data management method can analyze packets in different ways based on the protocols identified in step (S10020). The analysis methods for each are as described above.
[0203] In step (S10030), the data management method can analyze a packet based on the RFC protocol.
[0204] In step (S10040), the data management method can analyze a GUI / SNC protocol-based packet.
[0205] In step (S10050), the data management method can analyze HTTP / HTTPS-based packets.
[0206] In steps (S10030) to (S10050), the data management method may execute processing rules for analysis after parsing the packet. At this time, the data management method may analyze the binary data of the packet to extract various data (account data, SID, screen input data, screen output data, etc.). In addition, the processing rules may indicate settings for processing whether to store data included in the analyzed packet in an audit log (1033), whether to process or log data included in the analyzed packet, and whether to generate events and warnings. In addition, the data management method may further execute filter rules for filtering unnecessary logs and load rules for loading data for processing the processing rules.
[0207] In step (S10060), the data management method may generate an audit log (1033) based on the analyzed packet. At this time, the data management method may operate in a multi-threading manner to increase the log storage speed, and may perform memory queuing and file queuing in preparation for cases where database access is temporarily unavailable.
[0208] In step (S10070), the data management method can extract personal information using personal information metadata for the generated audit log (1033).
[0209] In step (S10080), the data management method can store an audit log (1033). At this time, the data management method can store the audit log (1033) and personal information, respectively.
[0210] In step (S10090), the data management method can monitor abnormal behavior.
[0211]
[0212] FIG. 10 is a diagram illustrating an embodiment in which the data management platform of the present invention analyzes HTTPS-based packets.
[0213] User activity in web browsers protected by HTTPS (SSL) cannot be logged using existing network traffic mirroring technologies. In particular, logging is impossible when the Diffie-Hellman algorithm is used for key exchange during HTTPS connections. The Diffie-Hellman algorithm, one of the algorithms used in symmetric key cryptography, represents a method for securely performing key exchange protocols.
[0214] However, to monitor for abnormal behavior and misuse of personal information within a company, there is a need to record and monitor logs of user behavior in web browsers.
[0215] According to one embodiment of the present invention, even when the Diffie-Hellman algorithm is used for key exchange, logs of user actions in a web browser can be recorded to monitor abnormal behavior and abuse of personal information within a company.
[0216] To this end, the data management platform (10000) enables monitoring of user behavior even when using the Diffie-Hellman algorithm.
[0217] More specifically, the analysis module (20002) of the data management platform (10000) may further include a proxy server configuration unit (2011), an SSL configuration unit (2012), an HTTP request / response data analysis unit (2013), and a message data generation unit (2014).
[0218] Here, the proxy server configuration unit (2011) can configure a proxy server (1031) between a web browser (1030) and a web server (1034). Here, the proxy server (1031) is a server that mediates network communication between a client and a server, and when the client uses the proxy server (1031), it can communicate indirectly through the proxy server (1031) without directly communicating with the web server (1034).
[0219] The SSL configuration unit (2012) can configure SSL in the proxy server (1031). More specifically, the SSL configuration unit (2012) can configure the proxy server (1031) and use the client SSL configuration to configure an SSL environment between the web browser (1030) and the proxy server (1031) to process HTTPS requests / responses. In one embodiment, the SSL configuration unit (2012) can use an SSL certificate for SSL configuration. Here, the SSL certificate may correspond to a certificate different from the certificate for analyzing the packet described above. That is, the SSL certificate at this time corresponds to one for supporting SSL configuration.
[0220] The proxy server (1031) that receives HTTPS request data can temporarily suspend the SSL connection, process the HTTP request / response data through the HTTP request / response analysis unit (2013), and perform the SSL connection again.
[0221] Accordingly, the message data generation unit (2014) can generate message data (1035) by combining HTTP request / response data and store the generated message data (1035) in a queue (1032). Here, the queue (1032) can include a memory queue and a file queue.
[0222] Afterwards, the data management platform (10000) can transmit message data (1035) stored in the queue (1032) to the outside.
[0223] Finally, the data management platform (10000) can configure an SSL environment between a proxy server (1031) and a web server (1034) using server SSL settings to process HTTPS requests / responses and transmit HTTPS response data.
[0224] This allows logging of user actions in web browsers even when using the Diffie-Hellman algorithm.
[0225]
[0226] FIG. 11 is a diagram illustrating an embodiment of a data management method of the present invention analyzing HTTPS-based packets.
[0227] In step (S20010), the data management method may configure a proxy server and set up client SSL to collect HTTPS-based packets, and in step (S20020), configure a proxy server and set up server SSL. That is, the data management method may configure a proxy server, configure an SSL environment between the proxy server and a web server using server SSL settings, perform processing for HTTPS requests / responses, and transmit HTTPS response data.
[0228] When a proxy server is configured and SSL is set up, the data management method can collect HTTPS packets at step (S20030). Unlike the above, the data management method of this drawing will be described as an example of collecting HTTPS packets.
[0229] In the case of HTTPS connections, the Diffie-Hellman algorithm is used for key exchange. Since the existing network traffic mirror technology cannot record logs of user actions when encrypting packets using the Diffie-Hellman algorithm, the present invention proposes the following method.
[0230] In step (S20040), the data management method can process HTTPS requests / responses. That is, the data management method can configure a proxy server and use client SSL settings to configure an SSL environment between a web browser and the proxy server to process HTTPS requests / responses. Thereafter, the proxy server, upon receiving the HTTPS request data, can terminate the SSL connection, process the HTTP request / response data, and then re-establish the SSL connection.
[0231] In step (S20050), the data management method may generate message data (1035) by combining HTTP request / response data. At this time, the data management method may filter out unnecessary data. More specifically, the data management method may generate message data (1035) by combining HTTP request / response data, and may not transmit unnecessary data (e.g., image data) when logging.
[0232] In step (S20060), the data management method can load the generated message data (1035) into at least one of a memory queue and a file queue. More specifically, the data management method can use a memory queue and a file queue as queues for storing the message data (1035). At this time, if only a file queue is used to store the message data (1035), there is a risk of performance degradation, and if only a memory queue is used, data loss may occur. Therefore, the two queues can be used in combination.
[0233] In step (S20070), the data management method can transfer message data (1035) loaded into a queue to a storage and store it. Here, the storage corresponds to a database included in the data management platform described above.
[0234]
[0235] Figure 12 is a drawing illustrating an embodiment of extracting and storing personal information in the data management platform of the present invention.
[0236] Regular expressions are the most commonly used method for extracting personal information. However, there is a risk of incorrect extraction using regular expressions.
[0237] To compensate for these points, the present invention can increase the accuracy of personal information extraction through a multidimensional extraction method using personal information metadata and an exception handling list as well as a regular expression method to extract personal information.
[0238] The personal information management module (20004) included in the data management platform (10000) of the present invention can define personal information types to extract personal information from the audit log (1033). Here, the audit log (1033) may include log data that has undergone index processing. Furthermore, the personal information types may include, for example, types of personal information such as resident registration numbers, credit card numbers, and account numbers.
[0239] More specifically, the personal information type analysis unit (2019) of the personal information management module (20004) can analyze the personal information type and extraction method used in the stored audit log (1033) to generate personal information metadata (1036) for personal information extraction. The analysis result can be stored in the personal information metadata (1036). At this time, the personal information management module (20004) can define the fields included in the personal information metadata (1036) based on the architecture type (here, the architecture includes an application development environment and a screen user interface (UI)). Here, the architecture type corresponds to information that distinguishes a parser that analyzes variables and values of log data. In one embodiment, the personal information management module (20004) can distinguish the architecture type based on the protocol type and URL for field information in the log data, and generate field information of the index accordingly. Additionally, personal information metadata (1036) may include architecture type (screen type), screen information (level 1, level 2), and personal information extraction rules.
[0240] To this end, the personal information pattern storage unit (2020) of the personal information management module (20004) can store patterns used for each personal information type. The personal information management module (20004) can define personal information types and store regular expression patterns and masking patterns used for each personal information type. Here, the reason the personal information management module (20004) defines personal information types and stores regular expression patterns used for each personal information type is to generate information included in the personal information metadata (1036).
[0241] In conclusion, the data management platform (10000) can create personal information metadata (1036) by defining personal information types and storing regular expression patterns used for each personal information type, and can create personal information extraction rules using the personal information metadata (1036) and the personal information exception processing list (1037) described below, and can extract personal information using the personal information extraction rules.
[0242] In addition, the personal information exception processing list generation unit (2021) of the personal information management module (20004) can generate a personal information exception processing list (1037), and the personal information extraction rule generation unit (2022) can generate personal information extraction rules to be extracted. At this time, the personal information management module (20004) can use personal information metadata (1036) to confirm personal information items virtually extracted from the audit log (1033) in order to generate the personal information exception processing list (1037), and can define exception processing rules included in the exception processing list (1037) based on the extracted values or analyzed variables.
[0243] In another embodiment, the personal information hash value collection unit (2023) of the personal information management module (20004) can collect hash values for each personal information type and generate a value filter for each personal information type. Here, the value filter corresponds to a filter created using a Bloom-filter data structure for the hash values of the personal information values. The present invention has the advantage of being able to quickly check whether a comparison value is included in a large data set through the value filter.
[0244] More specifically, the personal information management module (20004) can collect hash values for personal information values by type and store them by personal information type. The personal information value filter generation unit (2024) of the personal information management module (20004) can generate a personal information type-specific value filter file based on the collected personal information data.
[0245] Thereafter, the personal information extraction unit (2025) of the personal information management module (20004) can extract personal information, the personal information encryption unit (2026) can encrypt the extracted personal information, and the personal information storage unit (2027) can store the encrypted personal information. More specifically, the personal information management module (20004) can analyze the log data included in the audit log (1033) by architecture type to extract variables and values, and extract personal information using personal information metadata (1036) that includes personal information (extraction) rules in the extracted values.
[0246] In one embodiment, the personal information management module (20004) can verify whether the hash value of the extracted personal information value is included in the value filter. If the hash value is included in the value filter, the personal information management module (20004) can store the extracted personal information in the index of the audit log (1033). On the other hand, if the hash value is not included in the value filter, the personal information management module (20004) can determine that the extracted personal information has been extracted incorrectly and remove the extracted personal information.
[0247] Afterwards, when searching for encrypted personal information, the personal information management module (20004) can decrypt the encrypted personal information and then output the personal information processed by the masking rule.
[0248] Hereinafter, the function performed by the personal information management module (20004) may be referred to as that performed by the data management platform (10000).
[0249] Through this, the accuracy of personal information extraction can be improved. The present invention will be described in detail below with reference to the accompanying drawings.
[0250]
[0251] Figure 13 is a drawing illustrating an example of personal information metadata (1036) defined in the data management platform of the present invention.
[0252] In one embodiment, the data management platform can extract personal information contained in audit logs using personal information metadata (1036). To this end, the data management platform can generate and store personal information metadata (1036).
[0253] The data management platform can define the types and methods of personal information to be extracted for each architecture type and store them in personal information metadata (1036). Here, the architecture type can indicate whether it is GUI data, JSON data, or WEBGUI. In other words, the data management platform can define the types and methods of personal information to be extracted for each GUI data and store them in personal information metadata (1036), and can also define the types and methods of personal information to be extracted for each JSON data.
[0254] More specifically, personal information metadata (1036) may include architecture type, screen information (level 1), screen information (level 2), and personal information extraction rules.
[0255] Here, the architecture type corresponds to the screen type as described above. It contains information about the screen that is actually output. In one embodiment, personal information extraction rules can be determined based on the architecture type. Additionally, personal information metadata (1036) can include level 1 screen information and level 2 screen information corresponding to the architecture type.
[0256] Personal information extraction rules can include extraction methods and values. Examples of extraction methods include value extraction, variable extraction, value content extraction, specialized regular expression extraction, and complex personal information extraction. The following describes the extraction methods.
[0257] The value extraction method extracts personal information based on the extracted personal information's value. In this case, the data management platform of the present invention can utilize a list of personal information types for the values of the value extraction method.
[0258] The variable extraction method extracts personal information based on variables included in an architecture type. At this time, the data management platform of the present invention can utilize both a personal information type list and a variable name list for the variable extraction method values. Here, the variable name list corresponds to a variable name list according to the personal information type. For example, on Screen A (Type A), "Resident" may be included in the variable name list, and on Screen B (Type B), "SSN" may be included in the variable name list.
[0259] The specialized regular expression extraction method extracts personal information based on full text that cannot be parsed in the absence of variables. In this case, the data management platform of the present invention can utilize both a personal information type list and a pattern list for the values of the specialized regular expression extraction method. The pattern list can include not only the regular expression for the value, but also patterns added before or after the regular expression. For example, if the resident registration number is a regular expression, the data management platform can include cases where a ":" is placed before the resident registration number in the pattern list.
[0260] Composite personal information extraction is a method of extracting personal information based on two or more pieces of information, rather than a single piece of information. In one embodiment, the data management platform can only determine that information is personal information if both "name" and "resident registration number" are present, depending on the architecture type. Conversely, if only "name" or "resident registration number" is present, the data management platform can determine that information is not personal information, depending on the architecture type.
[0261] In this way, the data management platform of the present invention can extract personal information based on information included in personal information metadata (1036).
[0262]
[0263] Figure 14 is a drawing illustrating an example of extracting personal information by distinguishing architecture types in the data management platform of the present invention.
[0264] In one embodiment, the architecture type analysis unit (2029) of the data management platform (10000) can distinguish the architecture type from the audit log (1033) and then extract personal information using personal information metadata (1036) defined for each architecture type through the personal information extraction unit (2025).
[0265] More specifically, the data management platform (10000) can define fields included in the personal information metadata (1036) based on the architecture type. Here, the architecture type corresponds to information that identifies the parser that analyzes the variables and values of the log data. In other words, the parsing method for analyzing the variables and values varies depending on the architecture type. Therefore, the data management platform (10000) must define fields included in the personal information metadata (1036) based on the architecture type.
[0266] In one embodiment, the architecture type analysis unit (2029) of the data management platform (10000) can distinguish the architecture type based on the protocol type and URL for field information in the log data included in the audit log (1033), and can generate field information of the index accordingly.
[0267] Accordingly, the personal information extraction unit (2025) of the data management platform (10000) can extract personal information by utilizing at least one of the personal information metadata (1036) defined for each architecture type and the above-described exception handling list (1037).
[0268] Afterwards, the data management platform can encrypt the extracted personal information and store the encrypted personal information.
[0269]
[0270] FIG. 15 is a diagram illustrating an example of creating a personal information extraction rule in the data management platform of the present invention.
[0271] In one embodiment, the data management platform can create personal information extraction rules. To this end, this drawing describes a user interface for creating personal information extraction rules. To create personal information extraction rules, the user interface may include at least one of basic information, value regular expression extraction information, and variable-based extraction information.
[0272] More specifically, the basic information indicates the target to which the personal information extraction rule will be applied. Here, the basic information may include at least one of the following: log type, level 1 (screen, transaction), or level 2 (program, service). Accordingly, the user can input at least one of the following: log type (e.g., SAP GUI log), level 1, or level 2, as the target to which the personal information extraction rule will be applied.
[0273] Additionally, the value regular expression extraction information may include personal information to be extracted according to the personal information extraction method. More specifically, the entire personal information exists, and the data management platform can request the user to select the personal information to be extracted. Accordingly, the data management platform can extract values from the log according to the personal information extraction method and compare them with the regular expression pattern to determine the personal information. To this end, the data management platform can utilize the regular expression pattern file stored by personal information type, as described in the above-described embodiment.
[0274] Additionally, the data management platform can create personal information extraction rules using the values of variables analyzed by log type. To this end, the data management platform can receive variable-based extraction information from users.
[0275]
[0276] FIG. 16 is a diagram illustrating an example of creating a personal information exception processing list in the data management platform of the present invention.
[0277] In one embodiment, the data management platform can generate a personal information exception processing list (1037). More specifically, the data management platform can identify personal information items virtually extracted using personal information metadata (1036) from the audit log (1033). That is, the data management platform can virtually extract personal information using items included in the personal information metadata (1036) (e.g., the aforementioned key / value, screen name / field name, etc.). Here, the virtually extracted personal information items correspond to candidate data output based on the items of personal information metadata (1036) generated according to an embodiment of the present invention from the original log data.
[0278] The data management platform can generate an exception handling list (1037) based on extracted values or analyzed variables. More specifically, the data management platform can generate an exception handling list (1037) based on items included in personal information metadata (1036).
[0279] At this time, the data management platform can create an exception handling list (1037) including at least one of the architecture type, screen information, and personal information extraction rules included in the personal information metadata (1036). For example, when creating the exception handling list, the data management platform can register something like, “In the first architecture (UI) type, the corresponding key is not extracted because it is not personal information” or “In the second architecture (UI) type, the corresponding value is not extracted because it is not personal information.”
[0280] For example, the data management platform can extract "account number" as virtual personal information from the audit log (1033). Here, "account number" corresponds to candidate data. Additionally, the screen name / field name of the personal information metadata (1036) may include Product A / serial number. Here, it is assumed that the serial number of Product A does not correspond to personal information. In this case, if the serial number for Product A is identical to the "account number" (personal information), the data management platform may determine that the extracted "account number" is not personal information and register it in the exception handling list (1037).
[0281] That is, the data management platform can verify virtually extracted personal information by referencing the personal information metadata (1036) defined according to the above-described embodiment. Since the personal information in this case is candidate data rather than exact personal information, an exception handling list (1037) can be created for the candidate data based on the items included in the personal information metadata (1036).
[0282] In one embodiment, when extracting personal information from an audit log (1033), the data management platform may extract personal information excluding items included in the exception handling list (1037).
[0283] Accordingly, it has the advantage of reducing the probability of extracting incorrect personal information.
[0284]
[0285] FIG. 17 is a diagram illustrating an embodiment of creating an exception filter of the data management platform of the present invention.
[0286] In one embodiment, the data management platform can generate an exception handling list using the method described above. This drawing illustrates an exception filter user interface for generating an exception handling list. The exception filter user interface may include at least one personal information item.
[0287] In one embodiment, the data management platform may receive exception filter information for personal information items from a user. The exception filter information may include at least one of an architecture type (UI type), level 1 (screen, transaction), value, level 2 (program, service), and variable.
[0288] For example, in this drawing, the data management platform can receive “Architecture Type=SAP GUI”, “Level 1=SE16”, “Level 2=SAPMF02D-7230”, “Variable=RDTMS_VAL2”, “Value=8201301037329” as exception filter information from the user.
[0289] Accordingly, the data management platform can create an exception handling list using exception filter information input by the user.
[0290]
[0291] FIG. 18 is a diagram illustrating another embodiment of the data management method of the present invention for extracting and storing personal information.
[0292] Furthermore, there is a risk of personal information being extracted using regular expression patterns being mis-extracted. Therefore, in addition to the aforementioned embodiments, the present invention can also Bloom-filter personal information actually present in the log to reduce the risk of mis-extracting personal information. In other words, Bloom-filtering is applied to extracted personal information, allowing extraction only of information determined to be personal information, thereby increasing the accuracy of personal information extraction. This will be explained in detail below.
[0293] In step S50010, the data management method may collect hash values for personal information. More specifically, the data management method may collect hash values for various types of personal information from a system / platform that manages personal information, such as a personal information encryption solution. The system / platform that manages personal information may reside on an external server. In one embodiment, the data management method may store the collected hash values by personal information type.
[0294] In step (S50020), the data management method can generate a value filter for each personal information type. Here, the value filter corresponds to a filter created using a bloom filter data structure for the hash value of the personal information value.
[0295] In step (S50030), the data management method can extract personal information. In one embodiment, log data within the audit log can be analyzed by architecture type to extract variables and values, and personal information can be extracted by applying personal information extraction rules to the extracted values. This is as described above.
[0296] In step (S50040), the data management method can verify personal information values. That is, in addition to the above-described content, a value filter can be used to verify the extracted personal information values.
[0297] In step (S50050), if the hash value for the personal information is included in the value filter, in step (S50060), the data management method can store the extracted personal information in an index. More specifically, if the hash value for the extracted personal information is included in the value filter created using the Bloom-filter data structure, the data management method can determine that the extracted personal information is real personal information. Accordingly, the data management method can store an index indicating real personal information for the extracted personal information in the audit log.
[0298] In step (S50070), if the hash value for the personal information is not included in the value filter, the data management method may remove the extracted personal information in step (S50080). More specifically, if the hash value for the extracted personal information is not included in the value filter created using the Bloom-filter data structure, the data management method may determine that the extracted personal information is fake. Accordingly, the data management method may determine that the extracted personal information was extracted incorrectly and remove the extracted personal information. Here, removing the extracted personal information may not mean removing the data itself, but rather losing its value as personal information.
[0299] Accordingly, the present invention utilizes a Bloom-filter data structure to quickly compare personal information managed in bulk with values extracted from the personal information. Furthermore, errors in types of personal information whose values are difficult to verify can be eliminated.
[0300]
[0301] FIG. 19 is a diagram illustrating an embodiment of collecting and mapping user behavior in the data management platform of the present invention.
[0302] User actions performed within an application are expressed differently depending on the developer's preferences and development standards. That is, the present invention aims to facilitate the distinction between user actions, such as "search, delete, add, modify, and print," based on the user's actions.
[0303] Accordingly, the present invention collects texts of menus and icons of an application, automatically classifies them based on artificial intelligence, and can provide detailed classification of user actions as legally required.
[0304] Additionally, the audit log is a log that records information such as events occurring in the system and user activities, and can be used for security and audit tracking. Here, the audit log may include log data and an index corresponding to the log data.
[0305] Log data is generally distinguished by information such as time, event / action, user / subject, target / object, and result, and each log data forms one record, and multiple records can be recorded continuously.
[0306] Additionally, audit log data is typically indexed and managed in databases and other systems. To facilitate efficient log data retrieval and analysis, an index for each log record may also be maintained. Here, the index typically includes fields used for searches and keys to improve search speed.
[0307] For example, to search for records of users deleting specific files in audit logs with fields such as time, event / action, user / subject, and target / object, an index can be created by combining the time and target fields. Utilizing this index has the advantage of significantly reducing search times.
[0308] In addition, mapping user behavior to an index has the advantage of allowing log data to be classified based on user behavior, making it easy to conduct security analysis or monitor.
[0309] The data management platform of the present invention indexes log data contained in audit logs based on user behavior classified using artificial intelligence, enabling users to search log data based on user behavior. The present invention is described in detail below.
[0310] The data management platform (10000) of the present invention can collect user behavior using a collection module (20001), an analysis module (20002), a monitoring module (20005), and an AI engine (20006), map the user behavior to log data, index the data, and then provide the log data indexed with the user behavior in response to a log data query request.
[0311] More specifically, the collection module (20001) can be used to collect keys and text corresponding to user actions. At this time, the collection module (20001) can be connected to an application development environment to collect user actions. The application development environment stores keys and text for menus and icons used to select user actions. Accordingly, the collection module (20001) included in the data management platform (10000) of the present invention can collect keys and text corresponding to such user actions.
[0312] The AI engine (20006) can classify collected text into user actions based on artificial intelligence (AI). For example, user actions may include user tasks such as searching, deleting, adding, modifying, and printing. To this end, the AI engine (20006) can utilize methods such as machine learning, deep learning, natural language processing (NLP), and a rule-based approach.
[0313] The analysis module (20002) can generate user action metadata (1038) by dividing data on classified user actions into keys and user actions. At this time, the user action metadata (1038) can be stored in the internal database (20007) of the data management platform (10000).
[0314] The analysis module (20002) can map the stored user behavior metadata (1038) and the log data contained in the audit log (1033). At this time, in order to map the log data and the user behavior metadata (1038), the analysis module (20002) can map the key information in the user behavior metadata (1038) to a field that can be used as a key for each application development environment type when indexing the log data and store it in the user behavior field of the index.
[0315] Here, key information represents identification information that indicates a user action. In one embodiment, the data management platform (10000) may store the user action as an abbreviated ID (Identification) for identifying the user action, rather than storing it as text. For example, if the user action is “search,” the data management platform (10000) may store “R” as key information, if the user action is “delete,” the data management platform (10000) may store “D” as key information, if the user action is “modify,” the data management platform (10000) may store “U” as key information, and if the user action is “print,” the data management platform (10000) may store “P” as key information.
[0316] A user can view logs through the monitoring module (20005). In one embodiment, the monitoring module (20005) may provide information to the user by referencing the user action field of the index when providing log data included in the audit log (1033) within the database (20007).
[0317] Hereinafter, the functions performed in each module within the data management platform (10000) are described as being performed by the data management platform (10000).
[0318]
[0319] FIG. 20 is a diagram illustrating an embodiment of generating user behavior metadata in the data management platform of the present invention.
[0320]
[0321] *239
[0322] *In one embodiment, the data management platform (10000) can collect keys and text corresponding to user actions through the aforementioned AI engine, and classify the collected text into user actions based on artificial intelligence. Accordingly, the data management platform (10000) can generate user action metadata (1038) for the keys and text corresponding to the collected user actions.
[0323] More specifically, the data management platform (10000) can map application development environment type-specific keys and user action keys to generate user action metadata (1038). That is, the user action metadata (1038) can have application development environment type-specific keys, user action keys, and user actions as fields.
[0324] Here, the application development environment type may include the aforementioned architecture type and screen user interface type. That is, the application development environment type represents information fields that can be used for user actions within the application development environment. For example, it may include menu icons, OK icons, and cancel icons present on the screen. Additionally, the user action key represents an ID for identifying the aforementioned user actions. Accordingly, the data management platform (10000) may map application development environment type-specific keys and user action keys within the user action metadata (1038).
[0325] For example, if the key by application development environment type is “del key in the first application”, the data management platform (10000) can generate user action metadata (1038) by mapping it with the user action key “D” through the AI engine and analysis module described above. At this time, the data management platform (10000) can store in the user action metadata (1038) that the user action of the “del key in the first application” which is the key by application development environment type and the user action key “D” is “delete”.
[0326]
[0327] FIG. 21 is a diagram illustrating an embodiment of mapping user behavior metadata and log data in the data management platform of the present invention.
[0328] In one embodiment, the data management platform (10000) can map stored user behavior metadata (1038) and log data included in an audit log (1033).
[0329] More specifically, the data management platform (10000) can index log data to map log data and user behavior metadata (1038). Specifically, the data management platform (10000) can map key fields for each application development environment type within the user behavior metadata (1038) and user behavior key fields through the above-described embodiment. Furthermore, in one embodiment, the data management platform (10000) can store user behaviors of the user behavior metadata (1038) in the user behavior field of the index.
[0330] Accordingly, if the first log data stored in the audit log (1033) indicates a log in which a user presses the del key on the first application screen, the data management platform (10000) can immediately provide the mapped user action “delete” when receiving a request to view the first log data.
[0331] Mapping user behavior to an index in this way has the advantage of allowing log data to be classified based on user behavior, making it easy to conduct security analysis or monitor.
[0332]
[0333] Figure 22 is a drawing illustrating an embodiment of encrypting personal information in the data management platform of the present invention.
[0334] Personal information encryption keys must be changed periodically to comply with legal standards. Changing the encryption key requires decrypting the existing key and re-encrypting it with the new key. Changing the key requires decrypting and re-encrypting tens or hundreds of millions of data items, which requires significant time. Therefore, most companies often fail to change their encryption keys despite their legal obligations.
[0335] The present invention proposes a method for separately storing a token (replacement value) for an encrypted value and a key ID for the encrypted value. This allows for real-time encryption with a newly generated key value, and provides the ability to decrypt and re-encrypt data without affecting the operating server.
[0336] In addition to the above, encrypted data must be processed according to the application server's requirements. When using database encryption, data is decrypted and transmitted in its original form when loaded, which can lead to the original text being leaked through various means. Therefore, encrypted data must be processed within server memory and decrypted only when necessary.
[0337] The data management platform of the present invention has the advantage of preventing leakage of original text because data decryption and re-encryption occur internally even if the encryption key is changed.
[0338] The present invention will be described in detail below.
[0339] In one embodiment of the present invention, the data management platform (10000) can generate an encryption key and a key ID through a key management module (20003), encrypt personal information using the generated encryption key, and generate a token value corresponding to the encrypted personal information.
[0340] To this end, the key management module (20003) of the data management platform (10000) may include an encryption key and key ID generation unit (2015), a personal information encryption unit (2016), a token value generation unit (2017), and a mapping information storage unit (2018). Here, the key management module (20003) may use Java and RFC, and may be responsible for encryption and decryption of personal information.
[0341] Here, the encryption key and key ID generation unit (2015) can generate and manage encryption keys and key IDs for personal information encryption. In one embodiment, the encryption key and key ID generation unit (2015) can generate new encryption keys and key IDs based on user control. At this time, the encryption key can be changed by issuing a new key ID.
[0342] For example, a user may select a batch encryption key change function provided by the data management platform (10000), and accordingly, the encryption key and key ID generation unit (2015) may generate the encryption key and key ID with new values. In addition, in another embodiment, the encryption key and key ID generation unit (2015) may update the encryption key and key ID based on a preset cycle even without user control.
[0343] The personal information encryption unit (2016) can encrypt personal information using an encryption key. The personal information encryption unit (2016) can encrypt personal information using the most recent encryption key stored within the data management platform (10000).
[0344] The token value generation unit (2017) can generate a token value (replacement value) corresponding to encrypted personal information.
[0345] The information storage unit (2018) can store the generated token value, the encrypted personal information corresponding to the encrypted password, and the key ID in the mapping information table (1039). In addition, the information storage unit (2018) can separately store the token value in the business table (1040).
[0346] That is, even if the encryption key is changed through the encryption key and key ID generation unit (2015), the value stored in the work table (1040) does not change, so the encryption key can be changed without stopping system operation.
[0347]
[0348] Figure 23 is a drawing illustrating an embodiment of encrypting personal information in the data management platform of the present invention.
[0349] In one embodiment, the data management platform may collect personal information. The data management platform may extract personal information from data analyzed from collected packets or directly received data. Additionally, the data management platform may receive the personal information itself (e.g., resident registration number "730101-1088123").
[0350] In one embodiment, the data management platform can encrypt personal information using an encryption key and key ID generated through the encryption key and key ID generation unit described above.
[0351] For example, using this drawing, the data management platform can encrypt personal information using the generated first encryption key and key ID “KEY001.” Here, the encryption key can be generated in binary format. For example, the first encryption key can correspond to “01001010 00110001 00110001 00110011 00111000 00110000 00110001 01011010 00111101 00111101.” Using the above example, the personal information, resident registration number “730101-1088123,” can be encrypted using the generated encryption key.
[0352] In one embodiment, encryption may be performed by encrypting all or part of the personal information. In particular, the present invention is characterized by encrypting a part of the personal information. At this time, the key ID is mapped to an encryption algorithm. In one embodiment, available encryption algorithms include SEED, ARIA128, ARIS192, ARIA256, AES128, AES192, DES, and TDES as two-way algorithms, and SHA-256 as a one-way algorithm. At this time, the encryption algorithm may be determined based on the key ID.
[0353] After personal information is encrypted, the data management platform can generate a token value corresponding to the encrypted personal information. In the example shown in this diagram, the token value corresponds to "abcxxf." In this case, the token value can maintain the number of digits and format of the encrypted personal information. For example, if the last six digits of the resident registration number "730101-1088123" are partially encrypted, the token value replacing it can correspond to "abcxxf," which has the same number of digits and format.
[0354] In one embodiment, the data management platform may store the generated token value, the encrypted private information corresponding to the encrypted private information, and the key ID in a mapping information table, and store the token value in a business table. The mapping information table and business table are described below.
[0355]
[0356] Figure 24 is a drawing explaining the mapping information table and work table of the present invention.
[0357] This drawing is a drawing illustrating a mapping information table (1039) and a business table (1040). In this drawing, the mapping information table (1039) and the business table (1040) only show fields related to the present invention, and of course, they may include additional fields.
[0358] In one embodiment, the mapping information table (1039) may include a token value, a ciphertext, and a key ID. The token value, ciphertext, and key ID are each composed of fields, and the mapping information table (1039) may include mapping values corresponding to each field. For example, in the above-described embodiment, if personal information can be encrypted using the key ID “KEY001”, and the ciphertext corresponding to the encrypted personal information is “HJ113801Z==”, and the corresponding token value is “abcxxf”, the mapping information table (1039) may store the token value, ciphertext, and key ID by mapping them in the same row.
[0359] In one embodiment, the business table (1040) may include a token value. Here, since the business table (1040) cannot directly store a password or key ID because the field length is fixed, the data management platform may separately store the password and key ID mapped to the token in the mapping information table (1039).
[0360] At this time, in order for an authorized user to verify personal information, the encrypted text included in the mapping information table (1039) can be used. For example, if an authorized user requests the data management platform to decrypt personal information, the data management platform can extract the encrypted text “HJ113801Z==” in the mapping information table (1039) using the token value “abcxxf” included in the work table (1040), and decrypt the personal information using the encrypted text. In particular, the present invention is characterized in that the storage in which the mapping information table (1039) and the work table (1040) are stored and the storage in which the encryption key and key ID are stored are separately distinguished. In addition, the data management platform of the present invention can separately have a system in which the mapping information table (1039) and the work table (1040) are stored and a system in which the encryption key and key ID are stored. Through this, legal security requirements can be satisfied.
[0361] According to the above-described embodiment, the data management platform can store the token value in the business table (1040). Here, the data management platform can maintain the token value unchanged even if the key ID or personal information encryption value is changed.
[0362] Through this, the encryption key and key ID can be changed while the token value remains unchanged.
[0363]
[0364] FIG. 25 is a diagram illustrating an embodiment of generating a new encryption key in the data management platform of the present invention.
[0365] In one embodiment, the encryption key and key ID generation unit (2015) can generate a new encryption key and key ID. For example, the encryption key and key ID generation unit (2015) can generate a second encryption key and key ID “KEY002.” Here, the second encryption key can be expressed in binary, similar to the embodiment described above.
[0366] Accordingly, the data management platform can update the password and key ID included in the existing mapping information table (1039) with a new password and key ID.
[0367] More specifically, the data management platform can determine an encryption algorithm based on the newly generated key ID and use the new encryption key to change the encrypted value of the personal information. To do this, the data management platform can decrypt the personal information using the existing ciphertext and key ID, and then re-encrypt the personal information using the newly generated encryption key and key ID.
[0368] Accordingly, the token value included in the mapping information table (1039) is maintained, but the personal information encryption value and key ID are changed to newly generated values. At this time, the token value included in the business table (1040) remains unchanged.
[0369]
[0370] FIG. 26 is a drawing illustrating an embodiment of adding new business data to the data management platform of the present invention.
[0371] This diagram illustrates an example where new personal information is added to the data management platform. When the data management platform collects or receives new business data (e.g., personal information), it can encrypt the new personal information using the most recent encryption key and key ID.
[0372] For example, if new personal information, such as account number "114-910224-12345," is received, the data management platform can encrypt the personal information using the second encryption key and key ID "KEY002," which is the most recent encryption key. The data management platform can then generate a token value corresponding to the personal information. For example, the token value corresponds to "hijklm."
[0373] The data management platform can store the token value, password, and key ID in a mapping information table (1039), and store the token value in a business table (1040).
[0374] Before new personal information is added, the mapping information table (1039), which reflects the most recent encryption key and key ID, stores the token value “abcxxf,” the password “29AB3801Z==,” and the key ID “KEY002” in the first row. When new personal information is added, the mapping information table (1039) may further include the token value “hijklm,” the password “AQ348701Z==,” and the key ID “KEY002” in the second row.
[0375] Similarly, before new personal information is added, the business table (1040) may store “abcxxf” in the first row, and when new personal information is added, “hijklm” may be stored in the second row.
[0376] That is, the data management platform of the present invention can update information included in the mapping information table (1039) based on the most recent encryption key and key ID, and can change tens of millions of data in real time because it performs decryption and re-encryption of personal information by changing only the key ID.
[0377]
[0378] Figure 27 is a diagram illustrating an embodiment in which the data management platform of the present invention normalizes log data.
[0379] Some users may find it difficult to input regular expressions to extract necessary information from log data. The present invention aims to address this issue by normalizing log data. This allows for the easy creation of a parser containing regular expressions for extracting meaningful portions of data from log data, thereby increasing user convenience.
[0380] The data management platform (10000) of the present invention can normalize log data through a collection module (20001), an analysis module (20002), and a monitoring module (20005), and can search log data according to an event log search request from a user / client (1000).
[0381] Specifically, the collection module (20001) may include a log collection unit (2040). The log collection unit (2040) may obtain at least one log data transmitted from the outside.
[0382] The analysis module (20002) may include a parser generation unit (2043), a conversion rule generation unit (2044), and a collection rule generation unit (2045). The parser generation unit (2043) may extract matching blocks for regular expression patterns that are used with a certain frequency or more in the selected text. Here, the regular expression patterns may include regular expression patterns that are frequently used with a certain frequency or more, such as dates, times, and strings. In addition, the matching blocks may represent text information that matches the regular expression patterns.
[0383] The parser generation unit (2043) may generate a parser including a regular expression for extracting text from log data based on a matching block selected by user input from among a plurality of extracted matching blocks. In one embodiment, the parser may include field names based on user input.
[0384] In one embodiment, the parser generation unit (2043) can verify regular expressions by testing them on log data. That is, the parser generation unit (2043) can test whether field values corresponding to each field are properly extracted from log data using regular expressions.
[0385] The conversion rule generation unit (2044) can generate a conversion rule including a parser based on regular expressions and an event type corresponding to the parser. The conversion rule generation unit (2044) can scan a parser based on regular expressions that matches log data based on user input among the previously generated parsers. The conversion rule generation unit (2044) can apply a parser based on user input among the available parsers for the corresponding log data to the conversion rule and store it. In other words, the conversion rule can indicate a rule on how to process and store the extracted fields when storing the log data.
[0386] Therefore, the present invention provides convenience to users who struggle with regular expression input by partially assisting them with entering regular expressions, allowing them to complete the entire regular expression. Furthermore, the present invention provides convenience in scanning previously created parsers, thereby increasing the reusability of registered parsers.
[0387] The collection rule generation unit (2045) can generate a collection path rule by selecting a conversion rule to be used for log data of a log collection device.
[0388] The monitoring module (20005) may include a search request processing unit (2041), a user input processing unit (2042), and an event log search unit (2046).
[0389] The search request processing unit (2041) may receive an event search request for an event type from a user / client (1000). Thereafter, the search request processing unit (2041) may transmit search results extracted from at least one pre-stored log data to the user / client (1000). In this case, the transmitted search results may be displayed on the screen of the user / client (1000).
[0390] The user input processing unit (2042) can obtain information based on user input from the user / client (1000). That is, the user input processing unit (2042) can obtain information selected by user input through the user / client (1000).
[0391] In one embodiment, the information based on user input may include at least one of log data for generating and testing regular expressions, text included in the log data, a matching block selected from a plurality of matching blocks representing text information, a field for the text, an event type for a parser, registration information for a log collection device, and a collection path rule.
[0392] The event log search unit (2046) may, in response to receiving an event search request for an event type, output a search result extracted from at least one pre-stored log data based on at least one of a parser, a collection path rule, and a conversion rule.
[0393]
[0394] FIG. 28 is a drawing illustrating an embodiment of a data management method of the present invention for generating a parser.
[0395] In step (S18010), the data management method can obtain log data. In one embodiment, the data management method can obtain log data input by a user through a user / client (1000).
[0396]
[0397] *314
[0398] *In step (S18020), the data management method can obtain text contained in log data based on user input. That is, the data management method can obtain text selected by the user to be converted into a regular expression from the original log data. In one embodiment, the regular expression may be referred to as a "regular expression" or a term having an equivalent technical meaning.
[0399] In step (S18030), the data management method can generate a matching block representing text information for the text. For example, the text information can represent various text information, such as a number, one or more numbers excluding spaces, one letter, one or more letters excluding spaces, and all letters between double quotation marks.
[0400] In step (S18040), the data management method may generate a regular expression for extracting text from log data based on a matching block. In one embodiment, a regular expression may be generated for each text contained in the log data, and an entire regular expression including each regular expression may be generated.
[0401] In step (S18050), the data management method can obtain a field for text based on user input. That is, the data management method can obtain field name information for setting a field name for the corresponding text.
[0402] In step (S18060), the data management method can generate a parser including a regular expression and a field.
[0403]
[0404] Figure 29 is a drawing illustrating one embodiment of a parser generation screen of the present invention.
[0405]
[0406] *In one embodiment, a parser generation screen may be displayed by a user / client (1000). The parser generation screen may include log data (1042), text (1043), matching blocks (1044), regular expressions (1045), and fields (1046).
[0407] Log data (1042) may be input by a user, and text (1043) included in the log data (1042) may be selected and input. For example, the text may be composed of a string and may represent 16.
[0408] When the input log data (1042) and text (1043) are transmitted to the data management platform (10000), a plurality of matching blocks corresponding to the text (1043) generated by the data management platform (10000) can be displayed on the parser generation screen of the user / client (1000).
[0409] In this case, each of the plurality of matching blocks can be distinguished by color, and each matching block can represent different text information. Thereafter, when one matching block (1044) representing text information of text (1043) is selected from among the plurality of matching blocks by user input, a regular expression (1045) corresponding to the selected matching block (1044) can be automatically generated. For example, the regular expression (1045) is (? <replacegroupname> / d+) can be expressed as.
[0410] Additionally, a field (1046) corresponding to the text (1043) can be input by the user, and a parser including the entire regular expression and field can be generated.
[0411]
[0412] FIG. 30 is a drawing illustrating an embodiment of a data management method of the present invention for generating a conversion rule.
[0413] In step (S19010), the data management method can obtain log data. In one embodiment, the data management method can obtain log data input by a user through a user / client (1000).
[0414] In step (S19020), the data management method can determine a parser corresponding to the log data. That is, a parser corresponding to the log data can be determined by scanning the log data input by the user, and the parser name, version, and parser type for the corresponding parser can be determined. In this case, if the parser is based on a regular expression as described above, the parser type can indicate a regular expression.
[0415] In step (S19030), the data management method can determine an event type for the parser based on user input. For example, the event type may include, but is not limited to, personal information search logs and firewall logs, and may be comprised of various types.
[0416] In step (S19040), the data management method may determine at least one field corresponding to the parser and event type. In one embodiment, the data management method may perform batch registration of fields of each parser of the conversion rule. For example, during batch registration, the field, field name, field type (number or string), and data type may be determined.
[0417] In step (S19050), the data management method can generate a conversion rule including a parser, an event type, and at least one field. That is, according to the present invention, the data management method can determine whether to store field values actually extracted through the conversion rule, distinguishing between those to be stored and those not to be stored. In other words, the data management method can extract field values from log data using a parser including a regular expression, and determine which of the extracted field values to store and how through the conversion rule.
[0418]
[0419] FIG. 31 is a diagram illustrating an embodiment of a data management method of the present invention for generating a collection path rule.
[0420] In step (S11110), the data management method may register a log collection device for collecting log data. In one embodiment, when registering a log collection device, the device name, device IP, device type, operating system (OS), and collection type for the log collection device may be set by a user / client (1000) through user input.
[0421] In step (S11120), the data management method may generate a collection path rule by selecting a conversion rule to be used for log data of a log collection device based on user input. In one embodiment, the collection path rule may include at least one of a collection path, a collection type, and an equipment name.
[0422] In one embodiment, the collection type may include an agent method and a system log method. Here, the agent method includes a method of installing an agent program on a system and equipment to transmit necessary log data, and the system log method may include a method of collecting logs from various supplementary equipment and network equipment such as switches, routers, and firewalls.
[0423] In step (S11130), the data management method can apply a transformation rule to the collection path rule.
[0424]
[0425] FIG. 32 is a drawing illustrating an embodiment of a data management method of the present invention for searching an event log.
[0426] In step (S12110), the data management method may receive an event log search request for an event type from a user / client (1000). In one embodiment, an event log search request for an event type selected by the user among multiple event types may be received.
[0427] In step (S12120), the data management method may, in response to an event log search request, output a search result extracted from at least one pre-stored log data based on a collection path rule, a conversion rule, and a parser. In one embodiment, the at least one log data may correspond to an event type and may include log data collected and pre-stored over a certain period of time.
[0428] That is, according to the present invention, by parsing and distinguishing information (i.e., field values) contained in log data using regular expressions, a user can more easily confirm information inherent in the distinguished log data when analyzing the log data.
[0429] In step (S12130), the data management method may transmit search results to the user / client (1000). In this case, the search results may include field values parsed from log data, and in response to an event log search request by the user, the field values parsed by the parser may be displayed in the form of a dashboard on the screen of the user / client (1000).
[0430]
[0431] FIG. 33 is a diagram illustrating an embodiment of searching a log in a data management platform of the present invention.
[0432] For high-volume log searches, a technology is needed to retrieve sorted and filtered results in real time without loading the entire search result into memory. Furthermore, it is also necessary to be able to view some results in real time during the search.
[0433] The data management platform of the present invention efficiently processes large amounts of data and enables real-time query of only necessary results.
[0434] The monitoring module (20005) of the data management platform (10000) of the present invention may further include a coordinator control unit (2047) to support log search.
[0435] Here, the coordinator control unit (2047) can control the coordinator (2048) of the server (1002) based on the log search request of the user (1000).
[0436] Here, the coordinator (2048) can manage a list of available instances (2049a, 2049b, 2049c) among multiple instances (2049a, 2049b, 2049c) in a distributed system and distribute search requests.
[0437] Additionally, instances (2049a, 2049b, 2049c) are independent units that run in a computing environment and can operate by being allocated resources such as processors, memory, and disks through hardware or virtualization technology. Instances (2049a, 2049b, 2049c) can be run through specific operating systems and applications, and can generally be implemented in the form of servers, virtual machines, containers, etc.
[0438] The present invention will be described in detail below.
[0439]
[0440] Figure 34 is a drawing illustrating an embodiment of the external merge sort algorithm of the present invention.
[0441] The External Merge Sort algorithm is used to sort large amounts of data, and is particularly efficient when sorting data that exceeds memory capacity. The External Merge Sort algorithm can primarily utilize auxiliary memory, such as disks or external storage devices, to sort data.
[0442] In step (S16110), an index file storing offset information of data can be generated based on the value of a sort field. Here, the value of the sort field can represent an item included in the data. For example, the item included in the data can include a user name, an email address, a time, etc. Accordingly, the external merge sort algorithm can sort the data based on the item included in the data. In addition, the offset information can include a reference value of the sort field, a location within a data file (e.g., a location of a first log within a data file), and length information (e.g., length information of a first log within a data file). In addition, the index file is characterized in that it has a data order already sorted as an offset list in units of a specific number of cases (e.g., 1000 cases).
[0443] In step (S16120), if the number of data included in the sort result file for the merge sort is greater than or equal to the first number, the sort result file for the merge sort can be generated by merging.
[0444] More specifically, when generating an index file, if the number of files included in the index file is greater than or equal to a first number, a new index file may be generated. For example, if the number of files included in the first sort result file is greater than or equal to the nth number, a second sort result file may be generated.
[0445] In step (S16130), if the search is terminated or the number of files included in the merge sort file is greater than or equal to n, the newly generated second sort result files can be merged to generate a new third sort result file.
[0446] In other words, the external merge sort algorithm has the advantage of optimizing overall performance because it performs sorting operations by repeating the process of dividing and merging data.
[0447]
[0448] Figure 35 is a drawing illustrating an example of analyzing data in the data management platform of the present invention.
[0449] Systems that analyze log data require a user interface (UI) to process stored data. However, for users seeking diverse analyses, the UIs provided by developers are limited. Therefore, a user interface is needed to perform more complex data analysis or searches, or to input query commands in script form to manipulate data and derive meaningful results. To achieve this, the present invention aims to provide a function that allows data manipulation without the need for UI development programs, using scripts within the UI.
[0450] The present invention enables a user to perform various data analyses and data manipulations using scripts through an analysis task editor (2056).
[0451] To this end, the analysis module (20002) of the data management platform (10000) of the present invention may include an analysis task execution unit (2054) and an analysis task management unit (2055).
[0452] Here, the analysis task execution unit (2054) may include an analysis engine that executes information entered in the analysis task editor (2056). In one embodiment, the analysis task execution unit (2054) may execute an analysis task based on a command to execute a first analysis task entered by a user through the analysis task editor (2056). Specifically, when a user executes a code cell within the analysis task editor (2056), a Lua script is transmitted to the analysis engine within the analysis task execution unit (2054), and the Lua script may be interpreted and executed within the analysis engine and a result may be returned. For this purpose, the analysis task execution unit (2054) may utilize log data and statistical data of the database (20007).
[0453] The analysis task editor (2056) may include at least one cell as an executable editor via an application, software, or web browser. The cell may include a markdown cell for adding descriptive data for an execution script and a code cell for adding Lua script information for analysis.
[0454] The analysis task management unit (2055) can register a written Lua script. More specifically, a user can add a Lua script through the analysis task editor (2056) and register the added Lua script in the analysis task management unit (2055). The registered Lua script can be periodically executed by the analysis task scheduler included in the analysis task management unit (2055).
[0455] Afterwards, the monitoring module (20005) can output the results of periodically executing analysis tasks managed through the analysis task management unit (2055).
[0456] This allows users to analyze desired data without using the user interface provided by the developer.
[0457]
[0458] Figure 36 is a drawing illustrating a user interface of an analysis task editor provided in the data management platform of the present invention.
[0459] The analysis task editor (2056) of the present invention may include a Markdown cell (2057) and a code cell (2058). The analysis task editor (2056) may correspond to a unit that stores multiple scripts and text blocks.
[0460] Here, the markdown cell (2057) corresponds to a description block, and the code cell (2058) corresponds to a script block.
[0461] In one embodiment, a user may enter text into at least one of a Markdown cell (2057) and a code cell (2058). For example, the user may enter a description of the code cell (2058) in the Markdown cell (2057). Additionally, the user may enter code to be executed in the code cell (2058). Accordingly, the analysis task editor (2056) may execute the code contained in the code cell (2058).
[0462] In one embodiment, when a user presses the “button (2059)” provided in the analysis task editor (2056), the analysis task editor (2056) may additionally output an add markdown cell button and an add code cell button (2060a, 2060b). In one embodiment, the analysis task editor (2056) may output a + button (2059) both above and below the markdown cell (2057), thereby allowing the user to determine the location of the markdown cell (2057) or code cell (2058) to be added.
[0463] Accordingly, the user can add multiple markdown cells (2057) and similarly request multiple code cells (2058) from the analysis task editor (2056).
[0464]
[0465] Figure 37 is a drawing illustrating a user interface of an analysis task editor provided in the data management platform of the present invention.
[0466] In one embodiment, when a user requests execution of an output code cell (2058), the analysis job editor can execute the analysis job contained in the code cell (2058) through the analysis job execution unit.
[0467] For example, a user may enter “Query statistical data and visualize it as a line chart” in the first Markdown cell (2057) and enter a Lua script corresponding to this description block in the first code cell (2058).
[0468] Thereafter, when the user requests execution of the first code cell (2058) output, the analysis task editor can visualize the first line chart (2061) as shown in the drawing.
[0469] As another example, a user could type "Query a resource usage table in an external database and visualize it as a line chart" in a second Markdown cell, and then enter a Lua script corresponding to this description block in a second code cell.
[0470] Afterwards, when the user requests execution of the second code cell output, the analysis task editor can visualize the second line chart as shown in the drawing.
[0471]
[0472] Figure 38 is a drawing illustrating a user interface of an analysis task editor provided in the data management platform of the present invention.
[0473] Thereafter, referring to (a) of FIG. 95, the user can save the first analysis task including the first markdown cell, the first code cell, the second markdown cell, and the second code cell. At this time, the user can set a name for the first analysis task for distinction.
[0474] Additionally, referring to (b) of FIG. 95, the saved first analysis task can be loaded by the same user or a different user. When the user executes the analysis task editor for the loaded first analysis task, the first analysis task can be executed. To this end, the data management platform of the present invention can provide at least one previously stored analysis task list (2062).
[0475]
[0476] Figure 39 is a drawing illustrating an embodiment of a data management platform of the present invention storing and retrieving log data.
[0477] In one embodiment, the data management platform (10000) can compress log data through a collection module (20001), an analysis module (20002), and a monitoring module (20005) and store the compressed log data in at least one of a database (20007) and an archive storage (20009), and can retrieve the log data in response to a log query request from a user / client (1000).
[0478] Specifically, the collection module (20001) may include a data collection unit (2035). The data collection unit (2035) may collect new log data when new log data is input. In one embodiment, the data collection unit (2035) may transmit the collected log data to the analysis module (20002) when log data is input and accumulated for a certain period of time. The analysis module (20002) may include a compression processing unit (2036) and an archiving performing unit (2037). That is, the analysis module (20002) may analyze the log data received from the collection module (20001).
[0479] More specifically, the compression processing unit (2036) can store a plurality of input log data as segments of a predefined period unit (e.g., day unit). In addition, the compression processing unit (2036) can store the stored segments as chunk units of a predefined first size. That is, according to the present invention, by storing a file containing a plurality of log data as multiple files in chunk units, the log data can be compressed as quickly as possible (Near Real-time), and the reason why the log data is not compressed in units of blocks may be because the compression efficiency is greatly reduced if the log data is compressed in units of blocks.
[0480] Additionally, the compression processing unit (2036) can compress the stored chunks into blocks of a predefined second size. That is, according to the present invention, by dividing the chunks into block units and performing compression, the query performance can be improved when decompressing to extract actual log data without reducing compression efficiency. In this case, the block size may be smaller than the chunk size.
[0481] In one embodiment, segments containing compressed blocks may be stored in a database (20007). In this case, the database (20007) may include storage for storing segments that can be retrieved online.
[0482] The archiving unit (2037) can determine segments to be archived among the segments stored in the database (20007) to be stored in the archive storage (20009). The process of determining segments to be archived will be described in detail below. Thereafter, the archiving unit (2037) can transfer and store the segments to be archived in the archive storage (20009).
[0483] The monitoring module (20005) may include a decompression unit (2038) and a log query unit (2039). The decompression unit (2038) may decompress only a block containing at least one log data requested by a user / client (1000) among the entire compressed log data contained in at least one of the segments stored in the database (20007) and the archiving target segments stored in the archive storage (20009). The details of decompressing the corresponding block will be described in detail below.
[0484] The log query unit (2039) can receive a log query request for log data from a user / client (1000), and can transmit the decompressed log data to the user / client (1000) through the monitoring module (20005) below according to the log query request among a plurality of log data.
[0485]
[0486] FIG. 40 is a diagram illustrating another embodiment of a data management platform of the present invention storing and retrieving log data.
[0487] In one embodiment, the compression processing unit (2036) stores a plurality of newly input log data as segments of a predefined period unit, and when storing new log data, checks whether segment access information of the segment exists, and if not, generates segment access information of the segment. Here, the segment access information may include metadata about the segment. For example, the segment access information may include at least one of information indicating whether the segment is storable, information indicating whether the segment is archived, and information on the location where the segment is archived within the archive storage (20009).
[0488] The compression processing unit (2036) may store segments in chunk units of a predefined first size. In one embodiment, the compression processing unit (2036) may generate an index for each chunk based on the stored offset. This may be to indicate where each chunk is located within the compressed file, since the chunks are generated in a compressed file format.
[0489] The compression processing unit (2036) can compress the stored chunks into block units of a predefined second size at a point in time when there is no change in the log data, and generate block offset information and compression information.
[0490] Here, the compressed block may include compressed data, which is a file that compresses chunks into blocks. Furthermore, block offset information may include information about the position of the compressed block within the chunk and compressed length information. Furthermore, the compressed information may include information about the size of the compressed block and the size of the original file before compression.
[0491] The archiving execution unit (2037) can distinguish the archive target segments when performing archiving, transfer and store the distinguished archive target segments to the archive storage (20009), and generate access information for the archive target segments for the archive storage (20009).
[0492] When a log inquiry request for at least one log data among a plurality of log data is received from a user / client (1000), the decompression unit (2038) decompresses only the block in which at least one requested log data is located among the entire compressed log data by using at least one of segment access information, block offset information, and compression information of at least one of the segments and archive target segments, so that at least one log data can be queried by the user / client (1000).
[0493] To store log data stored in a general database for a long period of time, archiving can be performed in a separate location (e.g., archive storage (20009)). At this time, an export process for the log data is required, and to retrieve the archived log data again, an import process for the database is required. During these export and import processes, compression and decompression can consume a significant amount of time. Therefore, according to the present invention, the export / import process can be significantly shortened by enabling retrieval of the entire log data without decompression using compression information and block offset information.
[0494]
[0495] Figure 41 is a conceptual diagram disclosing layer-by-layer elements for a data management device according to an embodiment.
[0496] When collecting network packets, it's common to use network mirroring to copy network traffic and transmit it to monitoring equipment in typical intranet environments. However, in cloud environments where packet collection equipment (e.g., network taps or switches) cannot be installed, collecting packets through network mirroring presents challenges.
[0497] In other words, the nature of cloud environments makes it difficult to use traditional network mirroring methods due to physically separated network topologies and the use of virtualized network infrastructure. This can lead to increased packet loss rates and difficulties in accurately monitoring network traffic.
[0498] The present invention utilizes the Netfilter mechanism of the Linux kernel layer to solve this problem.
[0499]
[0500] *416
[0501] *The agent installation server may include an OS kernel area and an OS user area. In addition, the kernel area may include a packet filtering unit (1051) and a packet loading unit (1052), and the user area may include a transmission distribution unit (1053), a compression processing unit (1054), and a message transmission unit (1055).
[0502] In one embodiment, the agent installation server is characterized by being a cloud server. Accordingly, the agent can be installed directly on a cloud server where packet collection equipment cannot be installed to enable packet collection. The method for executing the agent on the cloud server can set connection information and processing options of the data management device and execute the agent based on the options. At this time, the agent execution options can include the IP address and receiving port information of the data management device, whether to perform compressed transmission, the number of retransmission attempts, the maximum queue load, the maximum number of packets per transmission to the engine, the receive buffer size of the netfilter queue, the maximum kernel queue length of the netfilter queue, the number of engine transmission queues (the number of channels), the log level, the log path, the rolling log size, etc.
[0503] As in the above-described embodiment, the network management device of the present invention can collect packets through network equipment (1001) such as a NIC (Network Interface Card).
[0504] The packet filtering unit (1051) can distinguish target packets collected through the network equipment (1001) using packet filter rules configured based on IP / Port, and can then forward them to the packet loading unit. In one embodiment, the packet filtering unit (1051) can forward or ignore network packets based on packet filter rules. At this time, the packet filter rules can be changed according to user definition.
[0505] The packet loading unit (1052) can load packets received through the packet filtering unit (1051) into a packet queue. Here, the packet queue corresponds to a netfilter queue.
[0506] In one embodiment, the netfilter queue configuration method can install a netfilter queue and configure a netfilter for the target port. The netfilter configuration can then be verified using the iptables -list command. Because the netfilter queue allows packet processing in OS user space, it can handle user-defined packets.
[0507] The transmission distribution unit (1053) can distribute packets to the transmission queue based on IP in order to transmit packet data loaded in the packet queue in parallel to the data management device.
[0508] The compression processing unit (1054) can bundle multiple packet data loaded in the transmission queue into a single large transmission unit, compress it, and then transmit it to the message transmission unit (1055). At this time, if the packet data is merged and compressed, the compression efficiency can be improved.
[0509] In one embodiment, the compression processing unit (1054) may compress packets using the LZ4 algorithm to increase compression efficiency. At this time, the compression processing unit (1054) may compress packets using the LZ4 algorithm, and then a compression or not field may be added to the protocol to decompress the packets in the decompression unit (1056). Specifically, when transmitting data, the header and body of the protocol may be separated, and the length of the body data, whether it is compressed, and the original length may be included in the header for transmission, and the merged packet data may be compressed and transmitted in the body using the LZ4 algorithm. At this time, when receiving data, the body data may be decompressed according to the compression or not field, and then compared with the original length for verification to decompress the data.
[0510] Through this, the compression ratio can be increased to 2.101, and the compression speed can be benchmarked at 780MB / s and the decompression speed can be benchmarked at 4970BM / s.
[0511] The message transmission unit (1055) can transmit message information received from the compression processing unit (1054) to the decompression unit (1056) of the data management device using transmission information and TCP communication.
[0512] The decompression unit (1056) can receive compressed data using TCP communication from a cloud server on which at least one agent is installed. The decompression unit (1056) can load packet data into a dispatcher queue based on IP / Port to analyze the received data in TCP stream units after decompressing the data.
[0513] In one embodiment, in order to decompress a packet compressed with the LZ4 algorithm, a compression or not field may be added to the protocol between the agent installed on the cloud server of the present invention and the decompression unit (1056) to decompress the packet. This is as described above.
[0514] The packet transmission unit (1057) can transmit packet data loaded in the dispatcher queue to the TCP packet analysis process via a pipe or TCP communication. Here, the TCP packet analysis process corresponds to a process that reassembles fragmented TCP data and performs analysis processing for each protocol. The process that performs analysis processing for each protocol is described in the above-described embodiment.
[0515] This provides the advantage of enabling packet collection even in situations where mirroring is difficult. Furthermore, to increase packet collection efficiency, only targeted packets can be collected, rather than all packets.
[0516]
[0517] FIG. 42 is a diagram illustrating an embodiment in which a data management device according to an embodiment monitors an agent.
[0518] In one embodiment, the data management device may include a console (10001), a collection module (20001), and a controller (20011).
[0519] The console (10001) can perform the functions of a user interface module of a data management device. In one embodiment, the console (10001) can be configured to collect agent status. If the console (10001) is configured to collect agent status, the console can collect agent status and monitor agent status through a collection module and a controller. At this time, the console (10001) can provide a user interface for monitoring agent status. Here, the user interface for monitoring agent status can include information such as agent IP, agent connection status (on / off), number of receptions, and number of receptions per second.
[0520] When the agent status is set to be collected through the console (10001), the controller (20011) can process a command that controls the collection module (20001) to collect the status of at least one agent. At this time, communication between the controller (20011) and the collection module (20001) can be based on commands. The controller (20011) can instruct the collection module (20001) to perform a specific task through a command, and the collection module (20001) can transmit the status information of the collected agent to the controller (20011) as a command response.
[0521] In one embodiment, the collection module (20001) can process a status inquiry command based on the control of the controller (20011). Accordingly, the collection module (20001) can collect the transmission status for each agent. The transmission status for each agent can include the agent IP, agent connection status (on / off), total received count, received count per second, etc.
[0522] More specifically, the collection module (20001) can collect the status of the agents (1011, 1012).
[0523] For example, if the first agent (1011) is operating normally, the collection module (20001) can collect the transmission status of the first agent (1011) and transmit it to the controller (20011).
[0524] For another example, if the connection of the second agent (1012) is terminated, the collection module (20001) can update the connection status of the second agent. The collection module (20001) can update the connection termination status of the second agent and transmit it to the controller (20011). For other functions of the collection module (20001), refer to the above-described embodiment.
[0525] The controller (20011) can provide information collected from the agents (1011, 1012) by the collection module (20001) to the client through the console (10001).
[0526] Accordingly, the client can monitor the connection status of the agent installed on the cloud server through the console (10001) of the data management device of the present invention.
[0527]
[0528] Figure 43 is a flowchart of a data management method according to an embodiment.
[0529] Packets collected from at least one agent installed on a cloud server can be decompressed (S101).
[0530] In one embodiment, packets collected from at least one agent are loaded into a netfilter queue, and then merged and compressed into a first unit. Here, merging into a first unit may mean bundling multiple previously loaded packet data into a single large transmission unit. In other words, the first unit corresponds to a larger transmission unit than the previously loaded packet data.
[0531] In one embodiment, packets collected from at least one agent may be loaded into a netfilter queue and then distributed to a transmission queue, and packet data distributed to the transmission queue may be merged and compressed as a first unit.
[0532] Additionally, the collected packets are compressed by separating the header and body of the packet protocol, and the header includes the length of the body data, whether it is compressed, and the original length, and the body may include the merged packet data. For this, please refer to the contents described above in Fig. 41.
[0533] The decompressed packet can be analyzed based on the packet's protocol (S103). For this, refer to the contents described above in FIGS. 1 to 11.
[0534] In one embodiment, the status of at least one agent can be collected. Furthermore, the collected agent status can be provided through a user interface. The agent status can include at least one of the following information: agent IP address, agent connection status (on / off), number of receptions, and number of receptions per second. For more information, please refer to the details described above in Figure 42.
[0535]
[0536] FIG. 44 is a diagram illustrating an embodiment in which a proxy server according to one embodiment is connected to another cloud service.
[0537] Clients can access SAP systems via HTTP, RFC, and SAP GUI protocols.
[0538] The present invention seeks to collect and analyze packet data transmitted and received via HTTP, RFC, and SAP GUI protocols by configuring a proxy server (200) between a client and an SAP system.
[0539] More specifically, a client can access a web server corresponding to the SAP system via a user web browser. At this time, a proxy server (200) can be configured between the user web browser and the web server to collect packet data and then transmit it to an analysis system for logging purposes. If the packet data is received via the HTTPS protocol, SSL can be released with reference to the above-described embodiment, and the HTTP request / response can be extracted and transmitted to the analysis system.
[0540] In particular, the present invention provides a method by which the above-described proxy server (200) can analyze and extract meaningful packet data not only based on HTTP / HTTPS protocols but also based on SAP GUI protocols. That is, the proxy server (200) of the present invention can perform the functions of both HTTP proxy and SAP GUI proxy within a single proxy server (200).
[0541] In one embodiment, the proxy server (200) may include a proxy client communication unit (210), a proxy data extraction unit (220), a proxy server communication unit (230), and a proxy data transmission unit (240).
[0542] The proxy client communication unit (210) can configure a proxy service with proxy settings, perform processing according to the communication type (e.g., HTTP, GUI, RFC, etc.) between the accessing client and the proxy server (200), and transmit request data to the proxy data extraction unit (220). At this time, the proxy settings can include proxy service port information, OS service file location, transmission queue length, etc.
[0543] In addition, the proxy client communication unit (210) can analyze the NI protocol (Network Interface protocol) and extract and transmit packets of units processed by the SAP system when the protocol is the SAP GUI or RFC protocol. Here, an embodiment of analyzing and transmitting the NI protocol will be described in detail later.
[0544] The proxy data extraction unit (220) can load request / response data received from the proxy client communication unit (210) and the proxy server communication unit (230) into a transmission queue based on packets in the case of SAP GUI and RFC protocols. In addition, the proxy data extraction unit (220) can combine request / response data received from the proxy client communication unit (210) and the proxy server communication unit (230) into a transmission queue based on request / response in the case of HTTP protocols.
[0545] The proxy server communication unit (230) can forward a client request to a target system (e.g., an SAP system) within the proxy settings for each proxy service. In one embodiment, in the case of the SAP GUI and RFC protocols, the proxy server communication unit (230) can forward a client request to the service port of the SAP system by identifying the service port with the corresponding string in the OS service file, since the service port for connection within the NI protocol is forwarded as a string based on the target SAP system. For this purpose, the OS service file can include a list of string information indicating port information.
[0546] Additionally, the proxy server communication unit (230) can process requests / responses according to the communication type between the proxy server and the target system and transmit response data to the proxy data extraction unit (220).
[0547] The proxy data transmission unit (240) can transmit proxy data loaded in the transmission queue to the proxy data reception unit (250) of the data management device by referring to the transmission information. Here, the transmission information can include proxy setting information. For example, the proxy setting information can include the data management device IP, proxy data reception unit (250) port information, the number of threads to be used for transmission, the number of proxy data items per transmission, the size of the transmission queue, and the number of retries during transmission.
[0548] In one embodiment, the data management device (100) of the present invention may include a packet data collection and filter unit (110), a TCP packet reassembly unit (120), a proxy data receiving unit (250), a protocol analysis unit (130), an audit log generation and transmission unit (140), an RFC information request unit (150), and a certificate management unit (160).
[0549] At this time, the packet data collection and filter unit (110) can collect packets from the NIC and agent, filter the packets, and transmit them to the TCP packet reassembly unit (120).
[0550] The TCP packet reassembly unit (120) can reassemble fragmented TCP packets and transmit them to the protocol analysis unit (130).
[0551] The proxy data receiving unit (250) can receive data from a proxy server. The proxy data receiving unit (250) can receive and distribute the received data based on the configuration information of the engine server of the data management device (100). For example, the configuration information of the engine server can include the number of analyzers capable of processing the SAP GUI protocol, the number of analyzers capable of processing the SAP RFC protocol, analyzer port information, etc.
[0552] The protocol analysis unit (130) analyzes the received data according to the SAP GUI, RFC, and HTTP protocols, and if the received data is encrypted with SNC / SSL, the data can be decrypted using a certificate. In addition, the protocol analysis unit (130) can generate an RFC information request file if there is no RFC structure information for analyzing data based on the RFC protocol. If there is RFC structure information, the protocol analysis unit (130) can analyze data based on the RFC protocol based on the RFC structure information. For this purpose, the protocol analysis unit (130) can include at least one analyzer.
[0553] The audit log generation and transmission unit (140) can generate an audit log by converting and processing data analyzed by protocol according to defined field rules. The audit log generation and transmission unit (140) can transmit the generated audit log to an analysis system. Here, the analysis system refers to a process of storing the audit log, extracting personal information from the audit log, and performing correlation analysis. At this time, the process of storing the audit log, extracting personal information from the audit log, and performing correlation analysis will refer to the above-described embodiment. Here, it goes without saying that the analysis system can be performed through some module of the data management device (100) rather than a separate system.
[0554] When the RFC information request unit (150) detects an RFC information request file, it can request RFC structure information from the target system.
[0555] The certificate management unit (160) can manage certificate information by the operator of the data management device and synchronize the registered certificates so that they can be used in the protocol analysis unit (130).
[0556] This has the advantage of being able to collect logs from users accessing the SAP system via HTTP, RFC, and SAP GUI protocols without installing a separate program.
[0557] Additionally, there is an advantage in that data can be collected and monitored through HTTP, RFC, and SAP GUI protocols using a proxy server (200).
[0558]
[0559] Figure 45 is a diagram illustrating the function of a proxy server according to one embodiment.
[0560] In one embodiment, a proxy server (200) having the above-described functionality may be used when Client A utilizes a target system. Here, Client A may be, for example, a user utilizing an SAP system. In this case, it goes without saying that Client A may utilize multiple proxy servers (200) to utilize multiple target systems, rather than utilizing one target system with one proxy server (200).
[0561] The proxy server (200) of the present invention may include at least one proxy worker (Proxy Worker, 201) and a proxy watchdog (Proxy Watchdog, 202) that manages at least one proxy worker (201).
[0562] The proxy worker (201) can act as an intermediary between client A and the target system. The proxy worker (201) can collect data between client A and the target system and transmit the data to the proxy data collection unit (250) of the data management device (100).
[0563] The proxy watchdog (202) can receive configuration data of proxy workers (201) from the proxy manager (170) of the console of the data management device (100), and manage and control the proxy workers (201). In addition, the proxy watchdog (202) can collect and monitor the status and performance matrix of the proxy workers (201). At this time, the proxy manager (170) can manage the settings of each proxy worker (201) through the proxy watchdog (202) and monitor the status of the proxy worker (201).
[0564] In one embodiment, the proxy data receiving unit (250) of the data management device (100) may receive data collected from proxy workers (201), analyze the data through the protocol analysis unit (130) within the same engine, and transmit the data to client B. Here, client B corresponds to a system administrator as a user using the data management device (100). At this time, the data may be transmitted to client B through a console via a database manager. In addition, client B may check the status of proxy workers (201) through the proxy manager (170) via the console.
[0565]
[0566] FIG. 46 is a drawing illustrating another function of a proxy server according to one embodiment.
[0567] In one embodiment, a proxy server (200) having the above-described functionality may support a bypass mode. Here, the bypass mode may only perform basic proxy functions (e.g., relaying network traffic). Additional functions, such as data collection, analysis, and recording, are disabled.
[0568] (a) of this drawing describes the automatic bypass mode, and (b) describes the manual by manager mode.
[0569] In automatic forwarding mode, the proxy watchdog (202) can check the status of the proxy worker (201) and inform the proxy manager (170) of the status of the proxy worker (201). In addition, the proxy watchdog (202) can automatically switch the proxy worker (201) to forwarding mode when a problem that may threaten the system's authenticity occurs in the proxy worker (201).
[0570] On the other hand, in manual forwarding mode, the proxy worker (201) can be restarted in forwarding mode through the proxy manager (170).
[0571] This ensures the stability of the system and protects it from potential errors.
[0572]
[0573] FIG. 47 is a diagram illustrating an embodiment of separating services within a proxy server according to one embodiment.
[0574] In one embodiment, a proxy server (200) having the above-described function can operate by separating service processes within the proxy server (200).
[0575] In one embodiment, the proxy server (200) of the present invention can be operated by (a) separation by proxy itself, (b) separation by service port, and (c) separation by service type.
[0576] More specifically, in the separation of the proxy itself, each proxy server (e.g., 200a, 200b, etc.) operates independently, and each proxy server (e.g., 200a, 200b, etc.) may include an SAP GUI / HTTP proxy. In this case, the SAP GUI / HTTP proxy may receive packet data based on the SAP GUI protocol and packet data based on the HTTP protocol, but may collect and analyze them using different methods. This is as described above.
[0577] Additionally, in separation by service port, traffic can be separated based on the service port number. For example, the proxy server (200) includes a first SAP GUI / HTTP proxy and a second SAP GUI / HTTP proxy, and different proxy settings or router rules can be applied to services using different port numbers.
[0578] Finally, in the separation by service type, traffic can be separated based on the service type (e.g., SAP GUI or HTTP). For example, the proxy server (200) may each include a SAP GUI proxy and an HTTP proxy.
[0579] Separating processes in this way has the advantage of maintaining system-wide availability by ensuring that even if a problem occurs in one process, it does not affect other processes, and making it easy to identify and isolate the process in question.
[0580]
[0581] FIG. 48 is a diagram illustrating an example of scaling out a proxy server according to one embodiment.
[0582] You can scale your proxy server up or down by using the platform's scalability features.
[0583] In one embodiment, the platform load balancer can distribute network traffic or requests to multiple proxy servers (200a, 200b, 200c) within the system. The platform load balancer provides a function that distributes packets of traffic received at specific addresses to proxy servers to distribute load across cloud platforms.
[0584] For example, the platform load balancer can distribute and transmit received data to the first proxy server (200a), the second proxy server (200b), and the third proxy server (200c). In addition, the platform load balancer can scale out the proxy servers based on the amount of received data and the load of the proxy servers (200a, 200b, 200c) by using the services provided by each platform.
[0585] At this time, the proxy manager (170) can manage the proxy watchdog (202a) of the first proxy server (200a), the proxy watchdog (202b) of the second proxy server (200b), and the proxy watchdog (202c) of the third proxy server (200c).
[0586] Through this, it is possible to manage proxy servers (200a, 200b, 200c) that flexibly respond to the load of the system and expand in a scale-out manner.
[0587]
[0588] *503
[0589] *
[0590] FIG. 49 is a diagram illustrating an embodiment in which a proxy server processes the NI protocol according to one embodiment.
[0591] This diagram illustrates the NI protocol processing and client request / transmit / receive process of the above-described proxy server.
[0592] The proxy server can collect service-specific port information based on OS service port information and proxy configuration information. Using this service-specific port information, the proxy server can process the NI protocol and send and receive client requests.
[0593] More specifically, the proxy server can process the NI protocol to send and receive client requests when the protocol the client is accessing is the SAP GUI or RFC protocol.
[0594] When a SAP GUI / RFC client sends or receives data with an SAP system, the proxy server can analyze the client's request within the NI protocol, including the IP address and port information of the system to which the request should be forwarded, and identify and forward the request to the target SAP system.
[0595] At this time, the port information for each OS service is transmitted as a string set in the client's OS service file, and the proxy server can identify and transmit the port information of the target system, the SAP system, by mapping the port information for each OS service loaded in the proxy server and the string information.
[0596] Additionally, the proxy server can return NI PONG when NI PING is sent to the SAP GUI / RFC client to indicate that the network connection is operating normally.
[0597] Additionally, the proxy data extraction unit can extract NI protocol request / response data transmitted and received via SAP GUI or RFC protocols and load it into a transmission queue with a threshold set based on data size. Since data from the same session must be processed in the same process, the proxy data extraction unit can load it into the transmission queue based on the client IP and port information connected to the proxy server.
[0598]
[0599] FIG. 50 is a diagram illustrating a proxy data collection process of a data management device according to one embodiment.
[0600] The data management device of the present invention can initiate a process for collecting proxy data. At this time, the proxy data receiving unit (250) and the protocol analysis unit (130) can be implemented so that the proxy data collection process is executed and parameters are transmitted by a controller within the data management device.
[0601] In one embodiment, the controller may execute the proxy data collection process based on configuration information of the server of the data management device. Once the proxy data collection process begins, the proxy server may collect data generated by the client's relationship with the target system. In particular, data transmitted from the proxy server can be directly transmitted to the protocol analysis unit (130) via socket communication without the need for a TCP reassembly process. For further details, please refer to the above-described embodiment.
[0602] In one embodiment, the proxy data transmission unit (240) may transmit proxy data loaded in the transmission queue to the proxy data reception unit (250) by referring to proxy setting information. In one embodiment, the proxy data transmission unit (240) may retransmit the proxy data N times if transmission fails. For a detailed description of the proxy data transmission unit (240), refer to the above-described embodiment.
[0603] The proxy data receiving unit (250) can load data received from the proxy data transmitting unit (240) into an analysis queue. The proxy data receiving unit (250) can transmit the data loaded into the analysis queue to the protocol analysis unit (130).
[0604] More specifically, the proxy data receiving unit (250) can distribute NI protocol data for each TCP stream according to the analysis queue quantity by adding the values obtained by replacing the IP and port with numbers and calculating the remainder. Thereafter, the NI protocol data distributed to the analysis queue can be transmitted to the protocol analysis unit (130). For example, if the value obtained by replacing the IP with a number is 15, the value obtained by replacing the port is 13, and the number of analysis queues is 4, the proxy data receiving unit (250) can distribute the NI protocol data for the corresponding TCP stream to the protocol analysis unit (130) as analysis queue number 0 by calculating the remainder of 4, which is 28, which is the sum of 15 and 13.
[0605] The protocol analysis unit (130) can distribute data according to the number of processes by combining IP / Port and calculating the remainder. For example, data with destination ports 3200 to 3299 can be distributed to the SAP GUI protocol analyzer, and data with destination ports 3300 to 3399 can be distributed to the RFC analyzer.
[0606] In addition, the proxy data format transmitted by the proxy data transmission unit to the proxy data reception unit is as follows. [Table 1] shows the proxy data transmission format, [Table 2] shows the proxy data response format, and [Table 3] shows the message data format.
[0607] Item Length Remarks Total Length4Message Count4MessageN
[0608] Item Length Remarks Total Length 4 Type 10: SUCCESS, 1: FailedMessage N Failure Message
[0609] Item Length Remarks Time 8 Occurrence Time Direction 10: Request, 1: Response, 2: Close Source IP 8 IP address in long format Destination IP 8 IP address in long format Source Port 2 Destination Port 2 Source Mac Address 6 Destination Mac Address 6 Data Length 4 Data N Message data
[0610] Figure 51 is a diagram illustrating an embodiment in which a proxy server, according to one embodiment, connects to another cloud service. The proxy server of the present invention has the advantage of being easily expandable to other cloud services. For example, a load balancer from Company A, which provides another cloud service, can distribute network traffic or application requests across multiple servers for processing.
[0611] In one embodiment, a state probe of Company A's load balancer can check the status of a proxy server's service port. Here, a state probe is a mechanism that checks the status of a proxy server based on specific criteria. By sending a specific request and TCP connection request to the proxy server, it can determine whether the server is operating normally.
[0612] In one embodiment, the state probe may fail if the HTTP protocol responds with an HTTP status code other than 200. In another embodiment, the state probe may fail if there is no response within a preset time period (e.g., 30 seconds). Furthermore, if the TCP connection request and response failure time exceeds the time limit, the client connection may be terminated and a new TCP session may not be established. Afterwards, if the state is restored, new TCP session data may be transmitted.
[0613] In one embodiment, when the first proxy server does not operate properly, the data management device of the present invention can control to receive proxy packet data from a second proxy server and / or a third proxy server included in the same virtual machine cluster as the first proxy server. Accordingly, the data management device can receive packet data transmitted and received with a server (e.g., an SAP server) on which an ERP system is installed from the second proxy server and / or the third proxy server.
[0614] Additionally, the load balancer can distribute the 2-tuple configuration, which combines the source IP and destination IP in order, to maintain session persistence.
[0615] Additionally, the virtual machine cluster managing the proxy server of the present invention can set thresholds for each virtual machine (VM) on which the proxy server is installed. In this case, the virtual machine cluster needs to scale the virtual machine in / out when the virtual machine exceeds the threshold. In this case, the virtual machine cluster can define auto-scaling rules based on numerical information about memory, CPU, and NIC.
[0616] In one embodiment, the present invention can generate a VM image corresponding to the proxy server of the above-described embodiment and deploy the VM image to a virtual machine within a virtual machine cluster. In addition, the virtual machine cluster can manage the images and versions of the VM through a VM image gallery.
[0617]
[0618] Figure 52 is a flowchart illustrating a data management method according to one embodiment.
[0619] In one embodiment, the data management method may receive first data from a proxy server that processes data transmitted and received via one of the HTTP protocol, the SAP GUI protocol, and the RFC protocol (S105). For this, please refer to the description above in FIG. 44.
[0620] At this time, when data is received via the SAP GUI protocol and RFC protocol, the proxy server can process the NI (Network Interface) protocol to transmit and receive client requests. In addition, the proxy server collects service-specific port information based on OS service port information and proxy configuration information. The OS service port information includes string information set in the client's OS service file, and the proxy server processes the NI protocol using the service-specific port information. For this, please refer to the contents described above in Figure 49.
[0621] In one embodiment, the data management method may analyze the protocol of the received first data (S107). At this time, the data management method may add the values obtained by converting the IP and port of the received first data into numbers, and distribute the first data according to the number of analysis queues using the remainder operation. For details, please refer to the details described above in FIG. 50.
[0622] In one embodiment, the data management method may generate a log from the analyzed first data (S109). The generated log may be used to extract personal information or to generate user behavior metadata according to the above-described embodiment.
[0623]
[0624] Figure 53 is a drawing illustrating a data management device according to an embodiment.
[0625] When it comes to techniques for reducing the storage logs when recording user logs on a web server, removing unnecessary data (e.g., CSS, images, scripts, and patch files) and removing irrelevant areas from the HTML body is important for increasing the efficiency of data analysis and saving storage space.
[0626] Below, we propose a technique to reduce the size of the response body by approximately 95% through SAP WEB GUI data transformation.
[0627] This drawing illustrates an example of reducing the log capacity when analyzing and processing packets collected from the aforementioned data management platform. Here, the network device (1001), packet collection unit (1058), and packet analysis unit (1059) refer to the descriptions made in the aforementioned data management platform.
[0628] In one embodiment, the data management device may include an SSL protocol processing unit (1060), an HTTP protocol analysis unit (1061), an HTTP script processing unit (1062), a WEBGUI data conversion unit (1063), and an audit log storage confirmation unit (1064).
[0629] The SSL protocol processing unit (1060) can receive a reassembled packet through the packet analysis unit (1059). More specifically, the SSL protocol processing unit (1060) can receive a reassembled TCP packet through the packet analysis unit, extract the fingerprint information of the certificate transmitted during the SSL handshake process of the packet encrypted with the TLS (Transport Layer Security) protocol, distinguish the loaded SSL private certificate, and decrypt the packet encrypted in the RSA format using the fingerprint information. At this time, the RSA encryption method is an asymmetric key encryption method that uses a pair of a public key and a private key (private key). The SSL protocol processing unit (1060) can transmit the decrypted packet to the HTTP protocol analysis unit.
[0630] The HTTP protocol analysis unit (1061) analyzes the received packets based on the HTTP protocol, and analyzes the request line and status line for each request and response as commands, and can analyze each header and body. In one embodiment, the method of analyzing the HTTP protocol can be referred to the above-described content.
[0631] The HTTP script processing unit (1062) can remove unnecessary information by executing an HTTP processing script with HTTP data analyzed through the HTTP protocol analysis unit as input.
[0632] More specifically, the HTTP script processing unit (1062) can remove unnecessary information by using the content type of the header of the HTTP data. For example, if the content type of the header of the HTTP data is text / css or text / javascript, such data is data that is transmitted and received without user intervention on the screen and is fixedly displayed on the screen. If the content type of the header is application / octet-stream, such data is data for uploading / downloading a program file and can be determined as unnecessary information for the audit log. Therefore, the HTTP script processing unit (1062) can remove unnecessary information from the data according to the content type of the header.
[0633] Additionally, the HTTP script processing unit (1062) can extract the extension within the URL of HTTP data and perform filtering. For example, if the extension of a file within the URL included in the HTTP data is dll, cab, js, swf, or pdf, the extension can be extracted and filtered. Here, filtering means not storing the corresponding data in the audit log.
[0634] Additionally, the HTTP script processing unit (1062) may not store the HTTP data as an audit log if the HTTP data is for a system that is not a logging target.
[0635] In one embodiment, the HTTP script processing unit (1062) may periodically check for changes in the HTTP processing script and update it. At this time, the HTTP processing script may be updated by the user.
[0636] The WEBGUI data return unit (1063) can return the response body data input from the HTTP script processing unit (1062) as converted XML. At this time, in the case of WEBGUI data, since the response body capacity is large, only data on user actions can be extracted from the response body received as XML and converted into XML format.
[0637] At this time, the HTTP script processing unit (1062) can filter the entire log, and the WEBGUI data return unit (1063) can reduce the capacity by removing unnecessary information and storing only the information necessary for the audit log.
[0638] In one embodiment, the operation of the HTTP script processing unit (1062) filtering logs and the operation of the WEBGUI data return unit (1063) performing data conversion cannot occur simultaneously. That is, the WEBGUI data return unit (1063) may not perform WEBGUI data conversion on logs filtered by the HTTP script processing unit (1062) through processing as HTTP scripts. Accordingly, the WEBGUI data return unit (1063) may perform data conversion by distinguishing only logs corresponding to WEBGUI among HTTP data for which log filtering has not been performed by the HTTP script processing unit (1062).
[0639] More specifically, the WEBGUI data return unit (1063) can record a log of user searches while removing at least one of the parts related to the start script, the parts related to the properties of each control, and the parts related to the style from the converted XML. This will be described in detail with reference to the drawings described below.
[0640] The audit log storage confirmation unit (1064) can determine whether to store data in the audit log based on the result processed by the HTTP processing script.
[0641] This allows us to remove unnecessary data that is not needed during data analysis.
[0642]
[0643] Figure 54 is a drawing illustrating an example of the structure of WEBGUI data according to an embodiment.
[0644] This drawing shows, in a DOM tree structure, that content within control-update within the XML of WEBGUI response data contains HTML data related to the screen. The present invention is characterized by extracting only the control information that constitutes the screen from HTML and deleting the remaining data to reduce the size.
[0645] For example, start-script and initialized-ids typically do not contain information that can be extracted from audit logs. On the other hand, Control-update is divided into elements that compose the screen, such as the bottom message (msgarea) and main screen information (userpanel), and the content includes control information for displaying the screen, and each control can have its usage divided according to its attributes.
[0646] For example, a control-update element might contain the following:
[0647] (1) webguiPopups: HTML content for pop-up screens
[0648] (2) backpackCUA: HTML content for the context menu
[0649] (3) backpackUA: HTML content for the system information pop-up
[0650] (4) webguiKeys: HTML span tag containing shortcut key information
[0651] (5) cuaarea: HTML content corresponding to the upper part of the user interface
[0652] (6) msgarea: User interface used to output messages
[0653] (7) screenarea / userPanel: User interface of the main screen
[0654] In one embodiment, to reduce the data size of the audit log, only the data that constitutes the screen can be extracted from the HTML and the remaining data can be deleted. For example, among the control-update elements, "msgarea" and "screenarea / userPanel" can be extracted because they constitute the screen, and the remaining data can be deleted. However, this is merely an example, and it is of course possible to extract data that satisfies preset conditions and delete the remaining data to reduce the data size of the audit log.
[0655]
[0656] Figure 55 is a diagram showing the HTML analysis results in WEBGUI data according to an embodiment.
[0657] Typically, when an HTML element contains the ct (content type) or subct (sub content type) attribute, sub-elements are structured in the same pattern based on the attribute value. The Isdata attribute can be used to identify the ID and data to be displayed.
[0658] This drawing is an extract from the screen and response body of the portion displayed on the web browser where WEBGUI is displayed, and shows Isdata and Isevents when the ct value of the extracted data is R_standards. Here, R_standards refers to a radio button, the value of item 4 in Isdata refers to the label displayed on the screen, and the SID of item 13 refers to an ID value that can identify the control.
[0659] In one embodiment, the data management device can extract extractable values using the Isdata attribute based on ct or subct in an HTML document, and then delete the rest as unnecessary information.
[0660] At this time, the extractable values and examples for each ct (content type) / subct (sub content type) type are as follows.
[0661] In one embodiment, based on the example below, only extractable values can be extracted from the original data, and the remaining data can be removed. Furthermore, among the extractable values, "ID" can be excluded from extraction because it is an unused field, even though it can be extracted.
[0662] (1) If the ct / subct type is CO and the Type is Control, the extractable values are ID and Type, and examples of values are “wnd[0] / titl, FioriTitleBar”.
[0663] (2) If the ct / subct type is B and the Type is Button Control, the extractable values are ID and Type, and examples of values are “wnd[0] / tbar[1] / btn[7], GuiButton”.
[0664] (3) If the ct / subct type is PHT and the Type is Page Header Title, the extractable value is Title, and an example of the value is “HR / x20Master / x20Data / x20Query.”
[0665] (4) If the ct / subct type is T and the Type is Tool Bar, the extractable values are ID and Type, and examples of values are “wnd[0] / sbar, FioriStatusBar”.
[0666] (5) If the ct / subct type is LNC and the Type is Link Choice, the extractable value is Text and the value
[0667] An example is “S42 / x20 / x28100 / x29”.
[0668] (6) If the ct / subct type is CBS and the Type is Text Field, the extractable values are ID, Type, and value, and an example of a value is "wnd[0] / usr / ctxtRSRD1-TBMA_VAL, GuiCTextField, MARAX”.
[0669] (7) If the ct / subct type is RL and the Type is Raster Layout, the extractable values are ID, Type, and ModalNo, and an example of the value is "wnd[0] / usr, GuiUserArea, 0".
[0670] (8) When the ct / subct type is RLI and the Type is Raster Layout Item, the extractable values are X coordinate and Y coordinate, and an example of the value is “168, 8”.
[0671] (9) If the ct / subct type is R_standards and the Type is Radio Button, the extractable values are ID, Type, Text, and whether or not to check. An example of a value is "wnd[0] / usr / radRSRD1-TBMA, GuiRadioButton, Database / x20table, true.”
[0672] The above items are just some examples and the extractable values are not limited to the type of ct / subct type and the ct / subct type contained in the HTML document.
[0673]
[0674] Figure 56 is a diagram showing the HTML analysis results in WEBGUI data according to an embodiment.
[0675] The HTML analysis results within WEBGUI data may be displayed as shown in the above-described diagram. In one embodiment, the HTML analysis results may be displayed in a tree-like structure on the screen based on the ct or subct attribute.
[0676] For example, the left side of the diagram shows the WEBGUI SE11 screen. SE11 is a data dictionary transaction code in the SAP system, a tool that allows you to create, manage, and inspect data-related objects such as tables, views, data types, and structures. Accordingly, WEBGUI can provide an interface for accessing the SAP system via a web browser.
[0677] In one embodiment, when the response original text of the WEBGUI SE11 screen is analyzed according to the ct or subct attribute, a tree-shaped structure having the same structure as the data of the screen viewed by the user on the WEBGUI SE11 screen is output, as shown in the right drawing of this drawing.
[0678] Accordingly, even if the data volume is reduced by removing unnecessary information, it has the advantage of being structurally identical to the data on the screen viewed by the user, which can facilitate analysis when extracting personal information.
[0679]
[0680] Figure 57 is a diagram showing the original text of WEBGUI data according to an embodiment.
[0681] This drawing is an example of a drawing that outputs the aforementioned WEBGUI SE11 screen as an XML file. The XML data included in this drawing is only an example, and the actual original XML file may contain all the code required to configure the WEBGUI SE11 screen.
[0682] In one embodiment, the response body of the WEBGUI SE11 screen analyzed within the data management device may be encoded using the MIME (Multipurpose Internet Mail Extensions) format. In this case, an HTTP parser may be used to analyze the HTTP response body encoded in the MIME format.
[0683] Afterwards, the data management device can perform XML conversion tests based on the ct or subct attribute using a parser for analyzing the WEBGUI original text. At this time, the data management device can perform the conversion excluding the context menu or popover window.
[0684] In one embodiment, only cases where the content type is userpanel or msgarea among the XML conversion results of the WEBGUI SE11 screen can be extracted. This will be described later.
[0685]
[0686] Figure 58 is a diagram showing XML data with unnecessary information removed according to an embodiment.
[0687] Based on the above-described embodiment, the data management device can remove unnecessary information based on ct or subct among the converted xml data.
[0688] This drawing can remove the remaining information, except for cases where the content type (ct) of the converted XML data is userpanel or msgarea, as unnecessary information. In this case, msgarea is HTML representing the message output user interface part, and userpanel is HTML representing the main screen user interface part, so cases where the content type is msgarea or userpanel can be judged as data necessary for configuring the screen and can be stored in the audit log.
[0689] Based on the above-described embodiment, the XML sizes of the original data and converted data for each screen are compared as follows.
[0690] T CodeDynpro nameDynpro numberOriginal size (kb)Converted size (kb)SE11SAPLSD_ENTRY1000239.94.6SE11SAPLSD412000656.456.6SE11SAPLSLVC_PULLSCREEN05001141.356.6PA20SAPMP50A1100328.510.2
[0691]
[0692] Here, the T code (Transaction code) represents a short keyword or abbreviation for accessing a specific task or process in the SAP GUI. Additionally, the Dynpro (Dynamic Programming) Name represents the SAP GUI program name, and the Dynpro number represents the screen number within the SAP GUI program. Referring to the table, it can be seen that, according to one embodiment of the present invention, the size of XML data has been reduced by 8% to 1%.
[0693] In addition, since the elements that input and output data have ID information, if you implement a parser that can extract key / value based on ID information, you can extract personal information.
[0694] For example, the expression form of ID information can be expressed in the form of "wnd[0] / usr / radRSRD1-TBMA” or "wnd[0] / usr / ctxtRSRD1-TBMA_VAL - MARAX” or "wnd[0] / sbar_msg - MARAX is not present. Please check the name." In particular, when values with the same meaning are expressed repeatedly, they can be expressed in the form of an array. Accordingly, the present invention can extract personal information by analyzing the expression form of ID information.
[0695]
[0696] Figure 59 is a drawing explaining a data management method according to an embodiment.
[0697] In one embodiment, first data can be received (S111). The present invention can receive a packet containing first data via a network device. For this, refer to the contents described above in FIGS. 1 to 4 and FIG. 53.
[0698] In one embodiment, the protocol of the received first data can be analyzed (S113). The present invention can analyze the first data based on the protocol of the first data. For example, if the data is encrypted using the TLS protocol, the key can be decrypted using a certificate before analyzing the data. For this purpose, refer to FIG. 53.
[0699] In one embodiment, if the protocol is HTTP, the first data can be filtered using an HTTP processing script (S115). For example, an HTTP processing script can be executed with the analyzed HTTP data as input to remove unnecessary information. An example of an HTTP processing script is as disclosed in FIG. 53.
[0700] In one embodiment, fourth data may be generated by deleting third data included in second data corresponding to WEBGUI among unfiltered HTTP data using an HTTP processing script in first data (S117). That is, the third data included in the second data may be analyzed and unnecessary portions may be deleted to generate fourth data. Here, the third data is characterized in that it is a value that can be extracted according to preset conditions. In addition, the fourth data may include data necessary for configuring a screen corresponding to a protocol among the second data.
[0701] More specifically, the data management method can delete all data except for the msgarea or userPanel attributes, which are necessary for configuring the screen, contained in the control-update attribute of the third data. At this time, even if the control-update attribute in the third data is msgarea or userPanel, the data management method can delete the ID among the extractable values and generate an audit log using only the remaining data. For this, please refer to the contents described above in FIGS. 53 to 58.
[0702]
[0703] FIG. 60 is a diagram disclosing an example of a data management platform according to an embodiment performing access control to a computing system.
[0704] In the illustrated example, the data management platform (10000) can perform event-based access blocking and MAC address-based access blocking. In one embodiment, the data management platform (10000) can control a user's (1000) access to the computing system through a collection module (20001), an analysis module (20002), and a monitoring module (20005). For example, the computing system may include an SAP system.
[0705] In one embodiment, the collection module (20001) can collect packets. In one embodiment, the collection module (20001) can collect packets transmitted between the user (1000) and the application server (1002). For example, the application server (1002) can include an SAP server that provides an SAP system to the user (1000). In one embodiment, the collection module (20001) can collect packets based on at least one of an IP address and a MAC address through a switch. In one embodiment, the collection module (20001) can collect access information of the user (1000). For example, the access information can include at least one of an IP address and a MAC address of the user (1000).
[0706] The analysis module (20002) can perform access control by blocking a user's (1000) login to the computing system. In one embodiment, the analysis module (20002) can generate access control information for each user account on the computing system and generate an event processing rule based on the access control information. In addition, the analysis module (20002) can determine whether an access control event occurs based on the event processing rule. Here, the access control information can include reference information for controlling access to the computing system. In addition, the event processing rule can include rule information for controlling access based on the access control information.
[0707] In one embodiment, the analysis module (20002) may perform access control by analyzing the user behavior of the user (1000). The analysis module (20002) may generate a correlation analysis rule based on at least one event of the computing system of the user (1000). In addition, the analysis module (20002) may perform user behavior analysis based on the correlation analysis rule to determine whether an access control event occurs.
[0708] In one embodiment, the analysis module (20002) can collect access information of the user (1000) and perform access control based on the access information of the user (1000) for the application server (1002) on which a program for controlling based on the collected access information of the user (1000) is installed. The analysis module (20002) manages access control information for each user account for the computing system and synchronizes and reflects this information with the application server (1002) through the monitoring module (20005). The control program installed in the application server (1002) can compare the access information of the user (1000) based on this account-specific access control information to determine whether to control access.
[0709] The monitoring module (20005) may transmit an access control request to the application server (1002) via SAP RFC (Remote Function Call) communication when an access control event occurs based on at least one of an event processing rule and a correlation analysis rule. In one embodiment, the monitoring module (20005) may transmit an access control request to the application server (1002) when access control is determined based on access information.
[0710] In one embodiment, the application server (1002) may perform access control processing upon receiving an access control request as an RFC to block access of a user (1000) to the computing system. In one embodiment, the monitoring module (20005) requests synchronization in an RFC manner whenever access control information for each user account is changed, and the application server (1002) performs access control information synchronization processing upon receiving access control information for each user account, collects IP / MAC when the user (1000) accesses the computing system, and compares this information with the access control information for each user account to block access.
[0711]
[0712] FIG. 61 is a diagram disclosing another example of a data management platform according to an embodiment performing access control to a computing system.
[0713] In the illustrated example, the data management platform (10000) may include a collection module (20001), an analysis module (20002), and a monitoring module (20005). The application server (1002) may include a login information collection unit (30017) and an access control processing unit (30018).
[0714] The collection module (20001) of the data management platform (10000) may include a packet collection unit (30001) and an access information collection unit (30002).
[0715] The packet collection unit (30001) can collect packets transmitted between a user (1000) and an application server (1002) through a network switch or a network TAP (Test Access Point, hereinafter, TAP). The access information collection unit (30002) can analyze packets between the computing system and the user (1000) to collect IP and MAC address information of the user (1000) who is executing the computing system GUI. In addition, the login information collection unit (30017) can be installed in the computing system and collect the IP and MAC addresses of the user (1000) by utilizing OS commands when the user (1000) logs in.
[0716] The analysis module (20002) may include an event analysis unit (30003), a user behavior analysis unit (30004), and an access information analysis unit (30005). In one embodiment, the event analysis unit (30003) may generate access control information for each user account and generate event processing rules that can add events to an audit log based on the access control information. For example, the access control information may include at least one of an IP address, an IP range, a system, a day of the week, a time range, a rule validity period, and a blocking message. This is described in detail below.
[0717] The event analysis unit (30003) analyzes packets to generate audit logs, compares them against event rules, and, if access is deemed unauthorized, adds and stores an access control event to the audit log. For example, the audit log may include SAPGUI information. In one embodiment, the event analysis unit (30003) may query the audit log to add an access control event.
[0718] The user behavior analysis unit (30004) can accumulate events and generate correlation analysis rules to analyze unusual user behavior. For example, correlation analysis rules can include various user behaviors on various computing systems, such as downloading after viewing personal information.
[0719] The user behavior analysis unit (30004) can create incidents by searching audit logs and detecting abnormal user behavior according to correlation analysis rules.
[0720] The access information analysis unit (30005) can perform user access control based on the user's (1000) access information to the computing system. In one embodiment, the access information analysis unit (30005) manages IP address, MAC address, and expiration date information, stores them in a database, and synchronizes this information with the computing system (1002) through the access control request unit (30006), and performs user-specific access control through the access control processing unit (30018).
[0721] The access control processing unit (30018) controls user access by comparing the access control information for each user account synchronized through the access control request unit (30006) in the data management platform (10000) with the access information including at least one of the IP address and MAC address collected through the login information collection unit (30017).
[0722] The monitoring module (20005) may include an access control request unit (30006). In one embodiment, the access control request unit (30006) may, if it determines that there is an access control event, transmit context ID information and a blocking message contained in the audit log to the application server (1002) using SAP RFC.
[0723] In one embodiment, the access control request unit (30006) may transmit an access control request to the application server (1002) using Simple Mail Transfer Protocol (SMTP) and RFC for a generated incident. In one embodiment, when the SAP RFC function is called, the application server (1002) may search for and block a user session using the received context ID information and pop up a blocking message to the user (1000).
[0724] In one embodiment, the access control request unit (30006) may transmit the stored user-specific access control information to the application server (1002) using the RFC protocol. In one embodiment, the application server (1002) may store the access control information received as SAP RFC in a table within the computing system. In one embodiment, the login information collection unit (30017) may collect access information including at least one of the IP address and MAC address information of the user (1000) whose computing system GUI is executed when the user logs in to the computing system. In addition, the access control processing unit (30018) may compare the access control information with the collected access information and terminate the connection if the access is not permitted. In one embodiment, in the case of event-based access control, a MAC-based access control function may be used because the MAC address cannot be used when passing through multiple network switches.
[0725]
[0726] Figure 62 is a drawing disclosing an example of an access control information input screen according to an embodiment.
[0727] In the illustrated example, an access control information input screen (30007) of the present invention may be provided. Here, the access control information input screen (30007) may represent a screen for inputting access control information that controls login to a user's computing system.
[0728] In one embodiment, the access control information input screen (30007) may input access control information including at least one of a user account, an organization, a blocking message, an IP address, a MAC address, system information, a day of the week, a time range, and a validity period.
[0729] The blocking message can include a blocking message delivered to the user when access is blocked. For example, the blocking message can include a message such as "This IP address is unregistered and is blocked." The IP address can be set to restrict access to IP addresses, and can be a specific IP address or an IP range. The MAC address can be set to restrict access to MAC addresses, and can be set to all MAC addresses or a specific MAC address. The system can be set to restrict access to systems, and can be set to all systems or a specific system. The day of the week can be set to restrict access to days of the week, and can be set to at least one of the following: Monday, Tuesday, Wednesday, Thursday, Friday, Saturday, or Sunday. The time range can be set to restrict access to all times or a specific time. The validity period can be set to restrict access to all times or a specific time.
[0730]
[0731] Figure 63 is a drawing disclosing an example of an event processing rule screen according to an embodiment.
[0732] In the illustrated example, an event processing rule screen (30008) of the present invention may be provided. Here, the event processing rule screen (30008) may represent a screen for entering an event processing rule based on access control information.
[0733] In one embodiment, the event processing rule screen (30008) may include a rule ID, a rule type, a rule setting, and a rule code. Here, the rule code may include code defining conditions and rules for controlling access based on access control information.
[0734] For example, if new_login is true or transaction_code is WEBGUI_SERVICES, the user account (sap_userid) is PT_INSPIEN, the IP address does not include 10.1.1.100, the day of the week is not Mon, Tue, Wed, Thu, Fri, and the time range is not between 09000 and 18000, the rule code can be written to output a CON-MGT event saying "Unregistered IP is blocked." In other words, user login can be controlled according to the event processing rule based on this access control information.
[0735]
[0736] Figure 64 is a drawing disclosing an example of a correlation rule input screen according to an embodiment.
[0737] In the illustrated example, a correlation rule input screen (30009) of the present invention may be provided. Here, the correlation rule input screen (30009) may represent a screen for inputting a correlation rule for performing access control based on user behavior analysis.
[0738] In one embodiment, the correlation rule input screen (30009) can input a correlation rule that includes at least one of a correlation rule ID, a rule type, a rule name, an applicable event, a common target item, and an accumulated item. Here, the rule type may include an accumulated excess type that restricts access when a specific event accumulates a certain number of times. For example, access may be restricted when the accumulated personal information exceeds 100.
[0739] The applicable event can select at least one event to which access control will be applied. For example, the resident registration number search, alien registration number search, driver's license number search, and passport number search events can be selected as events entered into the correlation rule and subject to access control.
[0740] For the same target item, you can select criteria for which access control will be applied. For example, events can be accumulated based on employee number, system, protocol name, and organization. These can be selected as criteria for applying access control.
[0741] An accumulation item can include an accumulation time, an accumulation item, and an exceedance count. For example, an accumulation time can indicate the time at which events accumulate. An accumulation item can include a field representing a numeric value among the event fields. For example, it can include the number of events (n or more). Additionally, the exceedance count can set a threshold (e.g., 100) for the values that accumulate over the accumulation time.
[0742]
[0743] Figure 65 is a drawing disclosing an example of a correlation rule activation screen according to an embodiment.
[0744] In the illustrated example, a correlation rule activation screen (30010) of the present invention may be provided. Here, the correlation rule activation screen (30010) may represent a screen for entering a rule that generates an incident by analyzing the correlation between received events in real time.
[0745] In one embodiment, the correlation rule activation screen (30010) can input whether to activate a correlation rule entered in the correlation rule input screen (30009) in the correlation rule application area. In one embodiment, whether to activate a rule exceeding 100 accumulated personal information cases and information on correlation analysis rules can be input. Here, the correlation rule application area can include a rule ID, rule name, analysis interval, and activation status.
[0746] Additionally, a correlation rule application area can include multiple rules, each of which can include a security score, a security score calculation rule, a risk assessment, a notification rule, and incident storage. For example, if the accumulated personal information exceeds 100, a security score of 30 points, a user access blocking notification rule, and incident storage can be enabled (ON).
[0747]
[0748] Figure 66 is a drawing disclosing an example of a control data setting screen according to an embodiment.
[0749] In the illustrated example, a control data setting screen (30011) of the present invention may be provided. Here, the control data setting screen (30011) may represent a screen for entering control data settings for performing MAC-based access control.
[0750] In one embodiment, the control data setup screen (30011) may set at least one of an account group, an account group manager, and a control per account group for a computing system (e.g., SAP).
[0751] In one embodiment, an account group may include an account group code and a corresponding account group name. For example, the account group name for the account group code FI may be set to "Financial Accounting." Furthermore, an account group administrator may include system users and account groups. For example, a system administrator may be set to "administrator," and an account group may be set to "ALL." Furthermore, account group-specific controls may include accounts, account groups, and account names for computing systems.
[0752]
[0753] Figure 67 is a flowchart showing an example of a data management method according to an embodiment of the present invention converting a data format.
[0754] In a data management platform controlling at least one engine or module included in a data management software package, access to a user's computing system is detected (S30101). In one embodiment, access to the user's computing system may be detected based on at least one of a network switch, a TAP, and a MAC address. For further details, please refer to the details described above in FIGS. 60 and 61.
[0755] Based on pre-stored access control information, an access control request blocking the user's access is transmitted to the application server for the computing system (S30103). In one embodiment, an event processing rule for the user's user account can be created, and an access control request blocking the user login corresponding to the detected access can be transmitted to the application server based on the event processing rule.
[0756] In one embodiment, a correlation analysis rule for user behavior can be generated based on at least one event for the user, and an access control request for blocking the detected access can be sent to the application server based on the correlation analysis rule.
[0757] In one embodiment, access address information for a user may be obtained, and an access control request blocking the user's detected access based on the access address information may be transmitted to the application server. For details, refer to the details described above in FIGS. 62 to 66.
[0758]
[0759] Figure 68 is a drawing illustrating an embodiment in which a data management device according to an embodiment reproduces a screen.
[0760] According to the above-described embodiment, the present invention can collect packets using a network device.
[0761] More specifically, the data management device of the present invention can collect communication data between an SAP system and a user in packet form via a network device. To this end, the data management device can utilize the aforementioned collection module (not shown). Here, SAP may include SAP GUI (SAP GUI client), SAP AP (application server, application server), and a database, and the internal communication protocol between SAP GUI and SAP AP may be referred to as the SAP DIAG (dialog) protocol. Hereinafter, the SAP protocol may include the SAP DIAG protocol.
[0762] Additionally, the data management device can analyze the protocol of collected packets based on TCP session information. To this end, the data management device can utilize the analysis module (not shown) described above.
[0763] In one embodiment, if the packet protocol is SAP-based, the data management device may process and analyze the SAP protocol and store it in an audit log. For details, refer to the above-described embodiment.
[0764] In one embodiment, a data management device may receive a request from a user (e.g., a security officer) to query SAP user activity records. Specifically, the user may log into the administrator console of a data management platform (not shown) and request a query for SAP user activity records. The user may then request a query for SAP user activity records using various conditions.
[0765] In one embodiment, if the audit log requested for query is based on the HTTP protocol, the data management device can reproduce the user screen using an HTTP emulator. In another embodiment, if the audit log requested for query is based on the SAP GUI protocol, the data management device can reproduce the user screen using an SAP GUI emulator.
[0766] In one embodiment, the data management device may output a reproduced user screen to the administrator console using the audit log for which a query has been requested. At this time, the screen reproduction may be displayed by distinguishing between the request screen and the response screen. In addition, if personal information is included in the audit log, the personal information items may be output by distinguishing between "Personal Information Type", "Count", and "Personal Information". In addition, if the audit log includes a response message, the response message may be included in the message item and output. This will be described in detail with examples below.
[0767] Accordingly, the present invention can collect packets containing communication data between a SAP system and a first user, store an audit log, and provide the communication data in the form of a graphical user interface (GUI) that reproduces a screen recording the user's actions upon a request for an audit log inquiry from a second user (the aforementioned security officer). In particular, the present invention can provide the second user with a reproduction of the SAP GUI application screen used by the first user and a provision of a web application screen.
[0768] Accordingly, user behavior can be graphically represented to enhance the readability and comprehensibility of log data. This allows security personnel to monitor and analyze user behavior more efficiently.
[0769] Below, when collecting packets based on the SAP GUI protocol, we will analyze the audit log, which is XML data, to explain the flow of screen reproduction and the screen reproduced for each control displayed on the SAP GUI screen.
[0770]
[0771] Figure 69 is a drawing illustrating an example of reproducing a screen from data according to an embodiment.
[0772] According to the above-described embodiment, the data management device can analyze SAP protocol packets to generate XML data (1065) for request and response screens and store them in an audit log. The data management device of the present invention can analyze XML data (1065) as shown in this drawing and provide it to a security officer in a form similar to a user screen (1066).
[0773] More specifically, the data management device can analyze XML data (1065) and output a response screen in the form of a user screen (1066). That is, the response screen (1066) on the right side of this drawing corresponds to a page that a security officer can directly check through a display.
[0774] For example, XML data (1065) parsed from a SAP protocol may include a tab for a response screen (1066).
[0775] In one embodiment, the data management device may output “@B4 / QEdited view@ Basic data 1”, “Purchasing”, “Purchase order text”, etc. as a tab (1067) for the response screen (1066) according to the code included in the XML data (1065).
[0776] Likewise, XML data (1065) generated by analyzing the SAP protocol may include a code for an object included in a tab (1067) for a response screen (1066). At this time, the data management device may analyze the code for the object and output it to the response screen (1066). For example, the XML data (1065) may include location coordinates and width values for where the button of the object is located. Accordingly, the data management device may output at least one object in the first tab (1067) of the response screen (1066) based on the code included in the XML data (1065).
[0777]
[0778] Figure 70 is a drawing illustrating an example of reproducing a screen from data according to an embodiment.
[0779] By using XML data generated by analyzing SAP protocol packets according to the above-described embodiment, the data management device of the present invention can analyze XML data on the left side as shown in this drawing and provide a screen like the one on the right side to the user.
[0780] At this time, if there is a table Control within the screen where the first user views the SAP system, a code (1068) corresponding to the table is generated within the XML data generated by the collected packets, and the data management device can analyze the code (1068) and output a table (1069) as shown in the drawing on the right to provide it to the user. For this, refer to the above-described content.
[0781]
[0782] Figure 71 is a drawing illustrating an example of reproducing a screen from data according to an embodiment.
[0783] By using XML data generated by analyzing SAP protocol packets according to the above-described embodiment, the data management device of the present invention can analyze XML data on the left side as shown in this drawing and provide a screen like the one on the right side to the user.
[0784] At this time, if a code (1070) corresponding to a grid exists in the XML data, the data management device can analyze the code (1070) and output a grid (1071) as shown in the drawing on the right to provide it to the user. For this, refer to the above-described content.
[0785]
[0786] Figure 72 is a drawing illustrating an example of reproducing a screen from data according to an embodiment.
[0787] By using XML data generated by analyzing SAP protocol packets according to the above-described embodiment, the data management device of the present invention can analyze XML data on the left side as shown in this drawing and provide a screen like the one on the right side to the user.
[0788] At this time, if there is a code (1072) corresponding to a pop-up screen in the XML data, the data management device can analyze the code (1072) and output a pop-up (1073) as shown in the drawing on the right to provide it to the user. For this, refer to the above-described content.
[0789]
[0790] Figure 73 is a drawing illustrating a user screen reproduced by a data management device according to an embodiment.
[0791] According to the above-described embodiment, the data management device of the present invention can analyze data contained in a packet and output a user screen. The user can log into the software of the data management device to view the audit log and be provided with a user screen.
[0792] At this time, the displayed user screen may include SAP application logs, application audit logs, statistical reports, monitoring reports, and system configuration screens. Specifically, the SAP application log screen may include real-time application logs and real-time session logs. The application audit log screen may include application logs, search by event type, search by alert type, and personal information processing audit logs. The statistical report screen may include system usage statistics, system status statistics by user, application risk factors, and weekly and monthly statistical reports. The monitoring report screen may include process monitoring reports, database usage monitoring reports, error log monitoring reports, and real-time support monitoring reports. The system configuration screen may include user / authorization management, monitoring target management, rule editor, control rule management, event and notification management, and archive data management.
[0793] In one embodiment, the data management device may output at least one of the following information on a dashboard of a user screen: alert occurrence status by SID, message (audit) occurrence status by SID, alert occurrence status by instance, message (audit) occurrence status by instance, recent message occurrence status, application (Tcode) execution ranking, message (Audit) status by organization, and engine status. In this case, the data management device may determine the content to be output on the dashboard based on the user's selection.
[0794]
[0795] Figure 74 is a drawing illustrating a user screen reproduced by a data management device according to an embodiment.
[0796] According to the above-described embodiment, the data management device can analyze data included in a packet and provide it to a user.
[0797] To this end, the data management device can search real-time session and application logs using the real-time session log tab. In one embodiment, when a user requests detailed information about a first session (1074), the data management device can reproduce the detailed information about the first session (1074) and the corresponding user screen.
[0798] At this time, the details (1075) for the first session (1074) may include session information, connection information, and SAP information, and the user screen (1076) for the first session (1074) may include a request screen, request data, a response screen, response data, and a message. At this time, the request screen and the response screen may include tabs, tables, grids, and pop-ups, etc., which are reproduced by analyzing the code included in the data corresponding to the session according to the above-described embodiment.
[0799]
[0800] Figure 75 is a drawing illustrating a user screen reproduced by a data management device according to an embodiment.
[0801] In one embodiment, the data management device can search logs based on connection information (server IP, server port, client IP, client port, client name), program information (Tcode, Dynpro name) and user information.
[0802] In one embodiment, the data management device may output detailed information and a user screen for search results, similar to the aforementioned embodiment. At this time, the data management device may receive a request (1077) from the user to play back the screen for the first log. For example, the user may request playback of the screen for the first log by selecting a play back button (not shown) for the first log. This will be described later.
[0803]
[0804] FIG. 76 is a drawing illustrating an embodiment in which a data management device according to an embodiment reproduces a user screen.
[0805] When a data management device is requested to reproduce a screen for the first log, the data management device can reproduce the user actions corresponding to the request time on the screen.
[0806] More specifically, the data management device can reproduce user actions from the first time to the nth time (1078) of the first log on the screen. To this end, the data management device analyzes data from the first time to the nth time (1078) of the first log, reproduces it as a request screen (1079) and a response screen (1080), and sequentially outputs the request screen (1079) and the response screen (1080) as a video over time.
[0807] In addition, the data management device can output a request screen (1079) and a response screen (1080) according to the time flow from the 1st time to the nth time (1078), and simultaneously output information such as the request time, Tcode, Dynpro name, and title main. At this time, if the log corresponding to the screen being played includes event information, the data management device can highlight and display it according to the event information level.
[0808] This has the advantage that security officers can check user actions recorded in the audit log over time.
[0809]
[0810] Figure 77 is a drawing illustrating an embodiment in which a data management device according to an embodiment manages events and alarms.
[0811] In one embodiment, the data management device can manage events and alarms for audit logs.
[0812] More specifically, the data management device can filter stored audit logs based on at least one event or alarm. To this end, the data management device can manage event codes, event code names, event types (types), event category names, alarm level names, alarm suppression times, and the like. At this time, event and alarm information can be input by the user.
[0813] In one embodiment, the user can confirm an alarm that the first event (1081) corresponds to a fatal error through software provided by the data management device.
[0814] Accordingly, let's look at how a user can check the screen of the audit log corresponding to a fatal error.
[0815]
[0816] FIG. 78 is a drawing illustrating an embodiment in which a data management device according to an embodiment searches for logs by event type or warning type and reproduces a user screen.
[0817] According to the above-described embodiment, a user can confirm an alarm indicating that the first event corresponds to a fatal error and retrieve an audit log corresponding to the event through a data management device.
[0818] At this time, the data management device can search for an audit log corresponding to the alarm based on at least one of the event type (1082) or the alert type (1083).
[0819] When a data management device receives a request for audit log search (inquiry) from a user, the data management device can search for an alert log (1084) and, when an event is selected, provide an application log (1085) in which an event occurred. Here, the alert log (1084) can include an alert level ID, an alert level name, an event code, an event name, an SID, a protocol, a server IP, a client IP, and a Count (wherein, the count represents the number of times the corresponding event occurred during the search period). In addition, the application log (1085) can include a request time, a user ID, a user name, an OK code, a Tcode, a title main, a Dynpro name, and a Dynpro number.
[0820] Thereafter, the data management device can provide details (1086) and a user screen (1087) corresponding to the log selected by the user. For this, refer to the above-described content.
[0821]
[0822] Figure 79 is a flowchart illustrating a data management method according to an embodiment.
[0823] In one embodiment, a data management method may receive data (S60010). If the data protocol is HTTPS, the data management method may configure a proxy server and set up SSL. Furthermore, the data management method may process request and response data corresponding to HTTPS-based packets through the proxy server, and may generate message data by combining HTTP request and response data. Furthermore, the data management method may load the generated message data into a queue using multi-threading. For further details, please refer to the details described above in FIGS. 8 to 11.
[0824] Additionally, in another embodiment, the data management method may transmit and receive client requests by processing the NI (Network Interface) protocol via a proxy server when the data is received via the SAP GUI protocol and RFC protocol. For details, refer to the contents described above in FIGS. 44 to 52.
[0825] In one embodiment, the data management method can analyze TCP packets of received data (S60020). For details, refer to the contents described above in FIGS. 9, 41, 44, and 52.
[0826] In one embodiment, the data management method may analyze data based on a data protocol, generate XML data for at least one of a request screen and a response screen, and store the XML data in an audit log (S60030). For details, refer to the details described above in FIG. 68.
[0827] In one embodiment, when there is a request to view a stored audit log, the data management method may analyze the code contained in XML data and output it to a user screen (S60040). At this time, in order to output it to the user screen, the data management method may analyze the code contained in the XML data and output at least one of the request screen and response screen from the first time to the nth time corresponding to the first log as a video according to the passage of time. For this, please refer to the contents described above in FIGS. 69 to 78.< / replacegroupname>
Claims
1. Step of collecting packets; A step of analyzing the collected packets; and A step of monitoring the above analyzed packets; Including, The above analysis steps are: Step of receiving data; A step of analyzing a TCP packet of the received data; A step of analyzing the data based on the protocol of the data to generate XML data for at least one of the request screen and the response screen and storing the XML data in an audit log; and Including a step of analyzing the code included in the XML data and outputting it to the user screen when there is a request to view the stored audit log; How to manage data.
2. In paragraph 1, The above analysis steps are: A step of receiving first data from a proxy server that processes data transmitted and received from one of the HTTP protocol, the SAP GUI protocol, and the RFC protocol; A step of analyzing the protocol of the first data received above; and A step of generating a log from the first data analyzed above; The above proxy server processes the NI (Network Interface) protocol to send and receive client requests when data is received through the SAP GUI protocol and the RFC protocol. How to manage data.
3. In paragraph 1, The above analysis steps are: A step of decompressing packets collected from at least one agent installed on a cloud server; and A step of analyzing the decompressed packet based on the protocol of the packet; Packets collected from at least one agent are loaded into a netfilter queue and then distributed to a transmission queue, and the packets distributed to the transmission queue are merged into a first unit and compressed. How to manage data.
4. In paragraph 1, The above analysis steps are: Step of receiving first data; A step of analyzing the protocol of the first data received above; If the protocol of the first data is the HTTP protocol, a step of filtering the first data using an HTTP processing script; and A step of generating fourth data by deleting third data included in second data corresponding to WEBGUI among unfiltered HTTP data using the HTTP processing script in the first data; The above third data is a value that can be extracted according to preset conditions. How to manage data.
5. In paragraph 1, The above analysis steps are: In a data management platform controlling at least one engine or module included in a data management software package, a step of detecting access to a user's computing system; and A step of transmitting an access control request to block access of the user to an application server for the computing system based on pre-stored access control information; including, How to manage data.
6. A database that stores data; and Including a processor for processing the above data, The above processor, Receive data, Analyze the TCP packet of the above received data, Based on the protocol of the above data, the data is analyzed to generate XML data for at least one of the request screen and the response screen and stored in the audit log, When there is a request to view the above-mentioned stored audit log, the code included in the above-mentioned XML data is analyzed and output to the user screen. Data management device.
7. Step of collecting packets; A step of analyzing the collected packets; and Performing a step of monitoring the above analyzed packet; The above analysis steps are: Step of receiving data; A step of analyzing a TCP packet of the received data; A step of analyzing the data based on the protocol of the data to generate XML data for at least one of the request screen and the response screen and storing the XML data in an audit log; and A computer-readable recording medium storing a computer program for executing a data management method on a computer, the method including the step of analyzing the code included in the XML data and outputting it to a user screen when there is a request to view the stored audit log.
Citation Information
Patent Citations
Web traffic logging system and method for detecting web hacking in real time
KR101909957B1
Method for reassigning work having history of return of crowdsourcing based project for artificial intelligence training data generation
KR102195955B1
System, method and computer program product for auditing XML messages in a network-based message stream
US20020174340A1