Agent Process for Legacy Application Compliance Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy data processing applications pose significant challenges for compliance with regulations such as HIPAA due to high costs and risks associated with rewriting existing software, leading to non-compliance by some organizations, especially in healthcare, where stringent security and auditing standards are required.

Innovation Solution

An application logging, recording, and reporting infrastructure that captures low-level user input events through a core agent process, avoiding the need to modify legacy applications, providing centralized monitoring, automated auditing, and compliance with regulatory directives by storing application-level actions in a central server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If legacy applications are rewritten to comply with regulations, then compliance with regulatory directives is improved, but cost and time requirements increase significantly

Engineering Contradiction:
Improvecompliance with regulatory directivesVSAvoidtime and cost for remediation
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces an intermediary component (agent process) that sits between the user and the legacy application. This agent captures low-level input events and translates them into compliance-relevant data without requiring modifications to the legacy application itself, thus resolving the contradiction by enabling compliance through an intermediate layer rather than direct application rewriting

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The compliance solution is segmented into separate components: the legacy application remains unchanged, while a separate agent process handles monitoring and compliance functions. This segmentation allows the legacy system to continue operating as-is while compliance requirements are met through the separate agent component, avoiding the need to rewrite the entire application

Inventive Principle:
Principle #1Segmentation

2Reliability

If legacy applications are rewritten to ensure compliance, then security and auditing standards are improved, but business risks and costs increase

Engineering Contradiction:
Improvesecurity and auditing standardsVSAvoidbusiness risks and costs
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The agent process serves as a mediator that enhances security and auditing capabilities without requiring changes to the legacy application. By intercepting and analyzing low-level input events, the agent provides security monitoring and audit trails while the legacy application continues to operate without modification, thereby reducing business risks associated with rewriting critical systems

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of modifying the original legacy application, the system creates a virtual copy or representation of user interactions through the agent process. The agent captures and records input events, creating a compliant version of the interaction flow that can be monitored and audited without altering the original application's security model or codebase

Inventive Principle:
Principle #26Copying

3Ease of operation

If application code is modified to capture user interactions, then monitoring capability is improved, but application stability and reliability worsen

Engineering Contradiction:
Improvemonitoring capabilityVSAvoidapplication stability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The agent process acts as an intermediary that captures user interactions at the input level, before they reach the application. This approach provides comprehensive monitoring capability while keeping the legacy application completely unchanged, thereby maintaining application stability and reliability without compromising monitoring effectiveness

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of instrumenting the application to capture output, the system inverts the approach by capturing input events at the source (keyboard, mouse) and deriving monitoring information from there. This inversion enables monitoring without application modification, preserving application stability while achieving comprehensive interaction tracking

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS7496575B2Application instrumentation and monitoring
Publication Date: 2009.02.24 DIGITAL GUARDIAN LLC
  • US7496575B2 patent drawing
  • US7496575B2 patent drawing
  • US7496575B2 patent drawing

AI summary

A data processing application logging, recording, and reporting process and infrastructure. Compliance with regulatory directives such as HIPAA, internal organizational and corporate, personal information privacy, and other security policies can thus be enforced without the need to recode legacy application software. In one preferred embodiment, a core agent process provides “listener” functionality that captures user input events, such as keyboard and mouse interactions, between a user and a legacy application of interest. The agent obtains instructions for how to deal with such events, accessing information that describes the application's behavior as already captured by an application profiler tool. Keyboard and mouse data entry sequences, screen controls and fields of interest are tagged during application profiling process. This data is stored in application profile developed for each mode of a legacy application. The technique can be implemented in various Information Technology (IT) environments including mainframe/terminal applications and/or client/server applications. Thus, full coverage of “fat” client, “thin” client, and legacy “mainframe” applications can be provided with a common approach across an enterprise.