Log Event Correlation for Granular User Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enforcing granular policies in enterprise networks is challenging due to the increasing number and variety of devices, as existing technologies struggle to accurately identify users and enforce policies across diverse devices and communication protocols.
Innovation Solution
A data appliance system that determines user identities based on events from various sources, such as Microsoft Exchange, instant messaging, and collaborative editing, and enforces policies by correlating log data with directory service provider information, using a process that involves agent applications and syslog protocols to manage user access across multiple devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional firewall devices are used to enforce access policies, then basic access control can be implemented, but granular policy enforcement becomes difficult as device variety increases
Solution Approach 1:
The patent introduces an intermediary component that collects log events from multiple diverse devices and correlates them with directory service provider information. This intermediary layer translates various device log formats into a unified user identification system, enabling granular policy enforcement without requiring direct integration with each device type. The intermediary acts as a mediator between heterogeneous devices and the policy enforcement mechanism.
Solution Approach 2:
The system segments the user identification process into separate functional components: log collection from devices, log parsing and event extraction, correlation with directory service information, and policy enforcement. This segmentation allows each component to specialize in specific tasks, improving overall system efficiency and making it easier to handle diverse device types without increasing overall complexity.
2Reliability
If granular policies are enforced across diverse devices, then secure access control is improved, but the difficulty of implementation increases
Solution Approach 1:
The patent creates a universal log event processing framework that can handle multiple device types and communication protocols through a single unified interface. The system uses standardized log formats and universal correlation methods that work across firewalls, proxies, authentication servers, and other network devices. This universality enables granular policy enforcement without requiring device-specific implementation complexity.
Solution Approach 2:
The system automatically collects log events from devices, parses them using configured templates, correlates user information with directory services, and enforces policies without manual intervention. The self-service automation reduces implementation difficulty by eliminating the need for manual configuration of each device and policy rule, while maintaining high reliability through consistent automated enforcement.
3Measurement precision
If user identification is based on directory service provider communication, then accurate user identification is achieved, but devices that do not communicate with the directory service provider cannot be monitored
Solution Approach 1:
The patent introduces log event collection as an intermediary mechanism that captures user activity information from any device that generates logs, regardless of whether the device communicates with the directory service provider. The intermediary collects device logs, extracts user identification information from log events, and correlates it with directory service provider data when available. This approach extends adaptability to diverse devices while maintaining identification accuracy through correlation.
Solution Approach 2:
The system adds another dimension to user identification by using log event data as an additional source of user information alongside directory service provider communication. Instead of relying solely on direct directory service communication, the system correlates log events (first dimension) with directory service data (second dimension), enabling identification of users from devices that do not directly communicate with the directory service provider.
Data Source
AI summary
Enforcing a policy is described. System log messages are received, via an interface, from a network device. At least a portion of the received system log messages are parsed to obtain an IP address and to obtain a user identifier. A policy to apply to a session associated with the IP address is determined, based at least in part on the user identifier. The policy is applied to the session.


