Trust Relationship Discovery via Log Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for discovering and managing trust relationships in computer networks are inefficient, requiring universal access, are prone to security risks, and fail to detect dynamically changing access patterns, especially when keys are stored in non-standard locations or encrypted.
Innovation Solution
A method that processes log information to detect security protocol-related events, generates trust relationship records, and updates databases to track key usage outside managed environments, using log data from various sources and scanning file systems for cryptographic keys to create both dynamic and static trust records.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If scanning-based methods are used to discover trust relationships by accessing all hosts, then trust relationship discovery capability is improved, but security risk increases and network/CPU load increases
Solution Approach 1:
The patent introduces log files as an intermediary medium to discover trust relationships. Instead of directly scanning hosts and accessing sensitive cryptographic materials, the system analyzes log files that already contain authentication event information. This intermediary approach enables trust relationship discovery while avoiding direct security risks associated with host scanning and key exposure.
2Difficulty of detecting and measuring
If scanning-based methods are used to discover trust relationships, then trust relationship discovery capability is improved, but network and CPU load increase
Solution Approach 1:
The patent extracts trust relationship information from log files rather than performing comprehensive host scanning. By taking out only the necessary authentication event data from logs, the system avoids the heavy network and CPU load associated with scanning all hosts and their file systems, while still achieving effective trust relationship discovery.
3Measurement precision
If comprehensive host scanning is performed to discover trust relationships, then discovery completeness is improved, but processing time increases
Solution Approach 1:
The patent leverages log files that have already been generated and populated with authentication event information before the discovery process begins. This preliminary action of logging authentication events enables the system to achieve comprehensive trust relationship discovery without the time-consuming process of scanning all hosts and file systems during the discovery operation.
4Use of energy by moving object
If log-based analysis is used to detect security protocol events, then network and CPU load are reduced, but ability to detect keys in non-standard locations decreases
Solution Approach 1:
The patent segments the trust relationship discovery process into two complementary approaches: log-based analysis for efficient overall discovery and targeted file system scanning for comprehensive key detection. The log-based analysis handles the majority of discovery needs with low resource consumption, while selective scanning addresses the limitation of detecting keys in non-standard locations, combining the advantages of both methods.
Data Source
AI summary
Methods and apparatuses for a computerized system are disclosed. A data processing device receives information from at least one source of log information in the computerized system and detects, based at least in part on said received log information, at least one security protocol related event at a first host device, the at least one security protocol related event being initiated by a second host device. Information is then stored for determination of a trust relationship record based on the detected at least one security protocol related event and information of the second host device.


