Security Logger Segmentation for Real-Time Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional logging systems in application servers are inadequate for efficiently and effectively observing and logging vast numbers of requests and events, leading to delayed identification of security breaches and increased risk due to the large amount of data that needs to be analyzed.
Innovation Solution
A security platform that enables detailed, customized logging of specific events based on hardware and application-specific contextual information, allowing for real-time identification of security threats and breaches through custom queries and machine learning techniques, thereby reducing the amount of data analyzed and enhancing query speed and accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional logging systems log all requests and events, then complete security monitoring is achieved, but data analysis time and processing complexity increase significantly
Solution Approach 1:
The patent segments logging into multiple specialized loggers (security logger, access logger, error logger, performance logger) that each capture specific types of events. This segmentation allows the system to monitor comprehensive security aspects while reducing the processing burden on any single logging component, thereby maintaining complete security monitoring without excessive analysis time.
Solution Approach 2:
The patent extracts and separates security-critical logging functions from general application logging. The security logger specifically extracts security-relevant events (authentication, authorization, security exceptions) into dedicated log files, allowing security analysis to focus only on extracted security data rather than analyzing all application logs, thus reducing overall data analysis time.
2Measurement precision
If detailed logging of all events is implemented, then security breach detection capability is improved, but the volume of data to be analyzed increases
Solution Approach 1:
The patent applies local quality by making different loggers capture different levels of detail appropriate to their specific function. The security logger captures detailed security events with full context, while other loggers capture only essential information for their domains. This ensures high detection accuracy for security events without uniformly increasing data volume across all logging systems.
Solution Approach 2:
The patent implements partial logging by having the security logger capture only the specific security-relevant portions of events rather than complete event details. This partial action approach maintains sufficient detection accuracy for security purposes while avoiding the excessive data volume that would result from logging all event details comprehensively.
3Reliability
If comprehensive security logging is implemented across all application servers, then security coverage is improved, but system complexity and resource consumption increase
Solution Approach 1:
The patent implements a universal logging framework where a base logger provides common functionality (log file management, formatting, filtering) that is inherited and extended by specialized loggers. This multi-functionality approach allows comprehensive security coverage across all application servers while reducing complexity by sharing common logging infrastructure rather than implementing separate logging systems for each security concern.
Solution Approach 2:
The patent merges multiple logging concerns into a unified logging system where security logging, access logging, error logging, and performance logging are coordinated through a common framework. This combining approach achieves comprehensive security coverage while managing system complexity through centralized log management and coordinated operation of multiple loggers.
Data Source
AI summary
Systems, methods, and devices log activity associated with security platforms implemented across web servers and application server. Systems include a first server including one or more processors configured to generate a plurality of log files based on requests received from a client device, where each log file is generated based, at least in part, on event information associated with a request and at least one of a plurality of custom parameters. Systems further include a second server comprising one or more processors configured to host an application accessed by the client device, where the first server is coupled between the client device and the second server and is configured to handle requests between the client device and the second server. Systems also include a database system configured to store application data associated with the application and the client device.


