Audit Log Visualization via Network Graphs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current audit log querying tools are inefficient and non-intuitive, primarily using batch-oriented relational queries that present data in two-dimensional tables, making it difficult for users to explore time-ordered audit events related to specific users or entities.
Innovation Solution
A graphical user interface (GUI) utilizing timelines to represent time-ordered audit events, with central and peripheral nodes indicating access frequencies, allowing users to select time frames and interact with icons representing different audit events for detailed information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If batch-oriented relational queries are used to generate audit log reports, then information security compliance requirements are met, but the reports are not intuitive and efficient for end users and do not facilitate exploration of audit events
Solution Approach 1:
The patent transforms the traditional two-dimensional tabular representation of audit logs into a multi-dimensional network graph visualization. This dimensional change allows users to explore audit events from multiple perspectives simultaneously - temporal sequences, entity relationships, access patterns - making the system both more intuitive and efficient for security compliance analysis.
Solution Approach 2:
The network graph visualization serves multiple functions simultaneously: it displays temporal sequences of audit events, reveals relationships between entities (users, systems, resources), identifies access patterns and anomalies, and enables drill-down exploration. This multi-functionality resolves the contradiction by providing both intuitive visualization and efficient analysis capabilities in a single interface.
2Productivity
If two-dimensional tables are used to present audit log reports, then computational and input/output demands are reduced, but the reports fail to facilitate exploration of audit events related to particular users
Solution Approach 1:
The patent segments the audit log data into distinct entities (users, systems, resources, events) and represents them as separate nodes in the network graph. This segmentation allows users to focus exploration on specific entities of interest while the underlying computational structure efficiently processes the complete dataset, resolving the contradiction between computational efficiency and exploration versatility.
Solution Approach 2:
The network graph acts as an intermediary representation layer between the raw audit log data and the user interface. It transforms computationally intensive relational queries into efficient graph-based operations while providing versatile exploration capabilities through interactive visualization, thus maintaining computational efficiency while enhancing adaptability.
3Reliability
If traditional report generation tools are used, then information security compliance is achieved, but user experience and ease of gathering access information is poor
Solution Approach 1:
The patent replaces the mechanical interaction model of traditional report generation (form filling, query construction, batch processing) with an intuitive graphical interaction model. Users can visually explore audit events through network graph manipulation, dragging, filtering, and drilling down, which maintains compliance reliability while dramatically improving ease of operation and user experience.
Data Source
AI summary
Methods, systems, and computer-storage media are provided for generating graphical representations of audit events. A party-of-interest is represented by a central node, and one or more peripheral nodes surrounding the central node represent parties having electronic records accessed by the party-of-interest during a selected time frame. The size of the peripheral nodes represents a frequency of access of the node's respective electronic record. Each of the peripheral nodes is actionable enabling a user to view information related to the audit event.


