Web Traffic Log Analysis for Network Security Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network security personnel face challenges in monitoring network security weaknesses, policy violations, and intrusions due to limited control over machines, absence of security agents on all systems, and lack of administrative rights, making it difficult to assess risks and detect unauthorized software or malware.
Innovation Solution
Analyzing web traffic logs for HTTP traffic, which contain error reports from various security controls, to identify reportable errors such as outdated patches, unauthorized applications, malware, intrusion attempts, and unknown vulnerabilities, and generating alerts for network security personnel.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security agents are deployed on all systems to monitor security weaknesses and intrusions, then security monitoring capability is improved, but cost and device complexity increase prohibitively
Solution Approach 1:
The patent uses web traffic logs as an intermediary medium to capture security information. Instead of deploying agents on every system, the solution places logging mechanisms at web traffic intermediaries (proxies, firewalls) that naturally handle web communications. These intermediaries capture error reports and crash data from multiple systems centrally, eliminating the need for complex distributed agent deployment while maintaining comprehensive security monitoring capability.
Solution Approach 2:
The patent enables systems to self-report security events through automated error reporting mechanisms. Applications and operating systems automatically generate and transmit crash reports and error data to centralized log collection points. This self-service approach eliminates manual security monitoring and reduces the need for active security agents, as systems autonomously provide security-relevant information through their existing error reporting infrastructure.
2Measurement precision
If administrative rights are obtained on all systems for full inspection, then security assessment accuracy is improved, but ease of operation and user control are worsened
Solution Approach 1:
The patent extracts only the necessary security-relevant information from systems without requiring full administrative access. By focusing specifically on error reports, crash data, and web traffic logs, the solution obtains sufficient security assessment information while leaving systems operationally autonomous. This selective extraction approach maintains security monitoring accuracy without imposing administrative control overhead on user systems.
Solution Approach 2:
Instead of systems providing full access to security personnel, the patent inverts the approach by having security information actively reported to centralized log collection points. Error reports and crash data are automatically generated and transmitted by systems themselves, reversing the traditional model where security personnel would need to actively query or inspect systems. This inversion maintains assessment accuracy while preserving system operational independence.
3Reliability
If comprehensive security monitoring is implemented across the network, then security detection capability is improved, but loss of information and data processing overhead increase
Solution Approach 1:
The patent extracts and analyzes only security-relevant portions of web traffic logs, specifically focusing on error reports, crash data, and exception information. Rather than processing entire log files or all network traffic, the solution selectively identifies and examines specific data elements that indicate security issues. This targeted extraction reduces data processing overhead while maintaining comprehensive security detection capability by focusing computational resources on high-value security indicators.
Data Source
AI summary
Most machines in an organization's computer network connect to the Internet and create web traffic logs which allow analysis of HTTP traffic in a simple, centralized way. The web traffic logs may contain error reports and error reports contain significant information that can be used to detect network security. By reviewing the error reports, significant information about a network and its security can be found as common sources of network security weakness may be watched for in the error reports.


