SAP Traffic Analysis Apparatus for Session Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current personal information protection measures for SAP systems, which do not use commercial database systems, are inadequate, as they lack effective monitoring and security protocols for analyzing and managing SAP application traffic, leading to potential data leaks and misuse.
Innovation Solution
A traffic analysis apparatus and method that analyzes and monitors SAP application packets between clients and servers by identifying pre-registered and new SAP sessions, checking for predetermined monitoring information, and performing response actions based on a security policy to prevent data leaks and unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If commercial database system protection measures are used, then database security is improved, but SAP application traffic monitoring capability deteriorates
Solution Approach 1:
The patent segments the protection approach by separating database-level security measures from application-level traffic monitoring. It introduces a dedicated traffic analysis apparatus that operates independently at the SAP application layer, analyzing packets between clients and servers without interfering with database system security mechanisms. This allows both database security and SAP traffic monitoring to function simultaneously without conflict.
Solution Approach 2:
The patent introduces a traffic analysis apparatus as an intermediary component between SAP clients and servers. This intermediary monitors and analyzes SAP application traffic independently, checking packets for monitoring information and enforcing security policies without disrupting the underlying database system operations. The intermediary approach enables versatile SAP traffic monitoring while preserving database security measures.
2Reliability
If personal information protection measures are implemented, then information security is improved, but SAP protocol monitoring effectiveness deteriorates
Solution Approach 1:
The patent implements preliminary action by pre-registering SAP session information and establishing monitoring rules before actual SAP traffic analysis begins. The traffic analysis apparatus pre-configures security policies and monitoring criteria, enabling effective detection of SAP protocol violations without compromising information security. This preliminary preparation ensures that monitoring can proceed effectively while maintaining security standards.
Solution Approach 2:
The patent incorporates feedback mechanisms where the traffic analysis apparatus continuously monitors SAP traffic, compares actual packets against pre-registered session information and security policies, and enforces corrective actions when violations are detected. This closed-loop feedback system maintains information security while improving SAP protocol monitoring effectiveness through real-time detection and response.
Data Source
AI summary
Provided are a traffic analysis apparatus and method. The traffic analysis apparatus includes an analysis unit and a policy application unit. The analysis unit determines whether a network packet between at least one client and a server is a packet of a pre-registered SAP session, and, when the network packet is not the packet of the pre-registered SAP session, the analysis unit determines whether the network packet is a packet of a new SAP session. The policy application unit determines whether the network packet includes predetermined monitoring information when the network packet is the packet of the pre-registered SAP session or new SAP session and, when the network packet includes the monitoring information, the policy application unit performs a response action conforming to a predetermined security policy.


