Unified Auditing System for Distributed Resource Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Distributed computer systems face vulnerabilities due to lack of integration among servers and applications, making it difficult to detect and prevent unauthorized access to resources, which is inefficient and often ineffective in real-time due to the difficulty in correlating events across independent systems.
Innovation Solution
A system and method for auditing access to resources in a distributed system, where a sign-on identifier is assigned to a user, and user and session identifiers are provided to applications managing resources, with records of access logged, allowing for determination of prohibited activities and corrective actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If individual servers and applications maintain independent logs without integration, then each system can manage its own access control and resources independently, but the system cannot correlate user activities across multiple systems to detect unauthorized access in real-time
Solution Approach 1:
The patent merges independent logging systems into a unified logging system that collects logs from multiple servers and applications through a common interface. The unified log repository consolidates logs from diverse sources, enabling centralized analysis and correlation of user activities across the distributed system while maintaining the independence of individual logging components.
Solution Approach 2:
The patent introduces an intermediary logging interface that mediates between independent logging systems and the unified log repository. This interface standardizes log formats and provides a common protocol for log collection, allowing heterogeneous systems to contribute logs without direct integration while enabling real-time correlation capabilities.
2Productivity
If logs are collected and analyzed manually from individual systems, then system independence is maintained, but the process becomes labor-intensive and inefficient
Solution Approach 1:
The patent implements self-service logging where the unified logging system automatically collects, standardizes, and analyzes logs from multiple sources without manual intervention. The system autonomously correlates events across different logs, identifies security incidents, and generates reports, eliminating the need for manual log collection and analysis while maintaining system independence.
Solution Approach 2:
The patent establishes feedback mechanisms where the unified logging system continuously monitors log data, analyzes security events in real-time, and provides immediate feedback about unauthorized access attempts. This automated feedback loop enables rapid detection and response to security incidents without manual analysis delays.
3Measurement precision
If clocks of individual systems are not synchronized, then system independence is preserved, but event correlation between systems becomes inaccurate and ineffective
Solution Approach 1:
The patent introduces a timestamp normalization intermediary that mediates between unsynchronized system clocks and the unified logging system. This component standardizes timestamps from different sources to a common reference time, enabling accurate event correlation without requiring actual clock synchronization across the distributed system infrastructure.
Solution Approach 2:
The patent transforms timestamp parameters from local system time references to a standardized universal time reference. By changing the time parameter representation and normalization method, the system enables accurate event correlation across unsynchronized clocks without modifying the underlying clock synchronization infrastructure.
4Reliability
If applications are loosely integrated in a distributed system, then system flexibility and independence are maintained, but the system becomes vulnerable to distributed attacks that exploit lack of awareness between applications
Solution Approach 1:
The patent segments the logging and security monitoring functions from the application logic, creating an independent unified logging system that observes all applications without requiring tight integration. This segmentation maintains application independence and flexibility while providing centralized security monitoring that detects distributed attacks by correlating events across all segmented systems.
Data Source
AI summary
Systems, methods, and machine-readable media are disclosed to provide for auditing of events or access of resources in a distributed system. In one embodiment, auditing access of resources can comprise receiving from a client a request to access one or more of the resources. A sign-on identifier can be assigned to a user of the client requesting to access the resources. The user identifier and sign-on identifier can be provided to one or more applications managing the one or more resources requested by the client. The resources requested by the client can be accessed based on the request. A record of the access of the resources requested by the client can be logged in a repository. Based on these records and information relating to prohibited activity, a determination can be made as to whether a prohibited activity is being performed by one or more users.


