Trust Relationship Discovery via Log Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for discovering and managing trust relationships in computer networks are inefficient, requiring universal access, are prone to security risks, and fail to detect dynamically changing access patterns, especially when keys are stored in non-standard locations or encrypted.

Innovation Solution

A method that processes log information to detect security protocol-related events, generates trust relationship records, and updates databases to track key usage outside managed environments, using log data from various sources and scanning file systems for cryptographic keys to create both dynamic and static trust records.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If scanning-based methods are used to discover trust relationships by accessing all hosts, then trust relationship discovery capability is improved, but security risk increases and network/CPU load increases

Engineering Contradiction:
Improvetrust relationship discovery capabilityVSAvoidsecurity risk
Core Design Contradiction:
Difficulty of detecting and measuringVSObject-affected harmful factors

Solution Approach 1:

The patent introduces log files as an intermediary medium to discover trust relationships. Instead of directly scanning hosts and accessing sensitive cryptographic materials, the system analyzes log files that already contain authentication event information. This intermediary approach enables trust relationship discovery while avoiding direct security risks associated with host scanning and key exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If scanning-based methods are used to discover trust relationships, then trust relationship discovery capability is improved, but network and CPU load increase

Engineering Contradiction:
Improvetrust relationship discovery capabilityVSAvoidnetwork and CPU load
Core Design Contradiction:
Difficulty of detecting and measuringVSUse of energy by moving object

Solution Approach 1:

The patent extracts trust relationship information from log files rather than performing comprehensive host scanning. By taking out only the necessary authentication event data from logs, the system avoids the heavy network and CPU load associated with scanning all hosts and their file systems, while still achieving effective trust relationship discovery.

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If comprehensive host scanning is performed to discover trust relationships, then discovery completeness is improved, but processing time increases

Engineering Contradiction:
Improvediscovery completenessVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent leverages log files that have already been generated and populated with authentication event information before the discovery process begins. This preliminary action of logging authentication events enables the system to achieve comprehensive trust relationship discovery without the time-consuming process of scanning all hosts and file systems during the discovery operation.

Inventive Principle:
Principle #10Preliminary action

4Use of energy by moving object

If log-based analysis is used to detect security protocol events, then network and CPU load are reduced, but ability to detect keys in non-standard locations decreases

Engineering Contradiction:
Improvenetwork and CPU loadVSAvoidkey detection capability
Core Design Contradiction:
Use of energy by moving objectVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the trust relationship discovery process into two complementary approaches: log-based analysis for efficient overall discovery and targeted file system scanning for comprehensive key detection. The log-based analysis handles the majority of discovery needs with low resource consumption, while selective scanning addresses the limitation of detecting keys in non-standard locations, combining the advantages of both methods.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11277414B2Trust relationships in a computerized system
Publication Date: 2022.03.15 SSH COMMUNICATIONS SECURITY
  • US11277414B2 patent drawing
  • US11277414B2 patent drawing
  • US11277414B2 patent drawing

AI summary

Methods and apparatuses for a computerized system are disclosed. A data processing device receives information from at least one source of log information in the computerized system and detects, based at least in part on said received log information, at least one security protocol related event at a first host device, the at least one security protocol related event being initiated by a second host device. Information is then stored for determination of a trust relationship record based on the detected at least one security protocol related event and information of the second host device.