Log Event Correlation for Granular User Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enforcing granular policies in enterprise networks is challenging due to the increasing number and variety of devices, as existing technologies struggle to accurately identify users and enforce policies across diverse devices and communication protocols.

Innovation Solution

A data appliance system that determines user identities based on events from various sources, such as Microsoft Exchange, instant messaging, and collaborative editing, and enforces policies by correlating log data with directory service provider information, using a process that involves agent applications and syslog protocols to manage user access across multiple devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional firewall devices are used to enforce access policies, then basic access control can be implemented, but granular policy enforcement becomes difficult as device variety increases

Engineering Contradiction:
Improveuser identification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component that collects log events from multiple diverse devices and correlates them with directory service provider information. This intermediary layer translates various device log formats into a unified user identification system, enabling granular policy enforcement without requiring direct integration with each device type. The intermediary acts as a mediator between heterogeneous devices and the policy enforcement mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the user identification process into separate functional components: log collection from devices, log parsing and event extraction, correlation with directory service information, and policy enforcement. This segmentation allows each component to specialize in specific tasks, improving overall system efficiency and making it easier to handle diverse device types without increasing overall complexity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If granular policies are enforced across diverse devices, then secure access control is improved, but the difficulty of implementation increases

Engineering Contradiction:
Improvepolicy enforcement reliabilityVSAvoidimplementation ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a universal log event processing framework that can handle multiple device types and communication protocols through a single unified interface. The system uses standardized log formats and universal correlation methods that work across firewalls, proxies, authentication servers, and other network devices. This universality enables granular policy enforcement without requiring device-specific implementation complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system automatically collects log events from devices, parses them using configured templates, correlates user information with directory services, and enforces policies without manual intervention. The self-service automation reduces implementation difficulty by eliminating the need for manual configuration of each device and policy rule, while maintaining high reliability through consistent automated enforcement.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If user identification is based on directory service provider communication, then accurate user identification is achieved, but devices that do not communicate with the directory service provider cannot be monitored

Engineering Contradiction:
Improveuser identification accuracyVSAvoiddevice compatibility
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent introduces log event collection as an intermediary mechanism that captures user activity information from any device that generates logs, regardless of whether the device communicates with the directory service provider. The intermediary collects device logs, extracts user identification information from log events, and correlates it with directory service provider data when available. This approach extends adaptability to diverse devices while maintaining identification accuracy through correlation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system adds another dimension to user identification by using log event data as an additional source of user information alongside directory service provider communication. Instead of relying solely on direct directory service communication, the system correlates log events (first dimension) with directory service data (second dimension), enabling identification of users from devices that do not directly communicate with the directory service provider.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10560478B1Using log event messages to identify a user and enforce policies
Publication Date: 2020.02.11 PALO ALTO NETWORKS INC
  • US10560478B1 patent drawing
  • US10560478B1 patent drawing
  • US10560478B1 patent drawing

AI summary

Enforcing a policy is described. System log messages are received, via an interface, from a network device. At least a portion of the received system log messages are parsed to obtain an IP address and to obtain a user identifier. A policy to apply to a session associated with the IP address is determined, based at least in part on the user identifier. The policy is applied to the session.