Enterprise Cyber Reports via IP Access Control and Error Handler Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cyber monitoring tools lack the ability to understand business logic, leading to false alerts and inefficient detection of abnormal events in enterprise web applications, especially when new users or developers are added.
Innovation Solution
A rules-based model that links IP access control logic with error handlers and audit logs, compartmentalized by web application for different user groups, to generate enterprise cyber reports using multiple monitoring tools data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If cyber monitoring tools use standard port references to detect abnormal events, then network security monitoring is simplified, but false alerts increase when new users or developers are added
Solution Approach 1:
The patent segments the monitoring system by creating separate error and audit tables compartmentalized by web application and user group. This allows different segments (user groups, applications) to have customized monitoring rules, preventing false alerts when new developers are added while maintaining simple overall system architecture.
Solution Approach 2:
The patent applies local quality by allowing custom port references and access control rules to be defined specifically for each user group and web application. Instead of using uniform monitoring rules across the entire enterprise, each local segment (user group/application) can have tailored rules that match their specific business logic and access patterns.
2Quantity of substance
If cyber teams monitor the entire enterprise network view, then comprehensive security coverage is achieved, but insight into web application business logic is lost
Solution Approach 1:
The patent merges network-level monitoring data with application-level business logic by linking error and audit tables to web applications. This integration allows cyber teams to maintain comprehensive network coverage while simultaneously gaining insight into application-specific business logic through unified reports that combine both perspectives.
Solution Approach 2:
The patent introduces web application error handlers and audit logs as intermediaries between the cyber monitoring system and the web applications. These intermediaries capture business logic information that would otherwise be invisible to network monitoring tools, translating application-level events into a format that cyber teams can analyze while maintaining comprehensive network coverage.
3Adaptability or versatility
If development teams manage access controls separately from cyber teams, then application development flexibility is maintained, but security consistency across the enterprise deteriorates
Solution Approach 1:
The patent creates universal access control tables that serve multiple functions: they support application-specific development needs while simultaneously enforcing enterprise-wide security policies. The same infrastructure is used by both development teams for application functionality and cyber teams for security monitoring, ensuring consistency across the enterprise while maintaining flexibility.
Solution Approach 2:
The patent implements feedback mechanisms where access control decisions and security events are logged and reported back to both development and cyber teams. This feedback loop ensures that application-specific access controls remain consistent with enterprise security policies, allowing development flexibility while maintaining security stability through continuous monitoring and reporting.
Data Source
AI summary
A method for generating enterprise cyber reports through linking IP access control logic with error handler and audits compartmentalized by web application for different user groups with multiple monitoring tools data. Business logic may be defined in access control tables for multiple user groups sharing multiple different application data and programmable access control logic applied to subfolders within the website subfolders based on functional user group role permissions. A common network event field name may be used to map multiple different monitoring tools data into common field alias. The field alias mapping allows multiple networking capture tools to be included within the same cyber report. Joining multiple network events field alias with an IP location allows for groups of different IP zone reports to be created within the enterprise being monitored by different monitoring tools.


