发明授权
- 专利标题: File system monitoring and auditing via monitor system having user-configured policies
-
申请号: US14804532申请日: 2015-07-21
-
公开(公告)号: US10462183B2公开(公告)日: 2019-10-29
- 发明人: Sean Christopher Foley , Christopher J. Berube , Sagi Shechter
- 申请人: International Business Machines Corporation
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 代理商 Jeffrey S. LaBaw; David H. Judson
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; G06F21/62 ; G06F21/55 ; G06F21/60
摘要:
Centralized monitoring of plural file systems that operate within or in association with an enterprise computing environment is provided. Each of the plural file systems are provided with a security policy, wherein the security policy defines one or more file system access activities to be monitored at the file system. Each file system is instrumented with a software agent that intercepts the relevant file system access activity. A centralized collector component is operative to receive from each of the plural file systems audit trail data, wherein the audit trail data is data that has been generated locally as file system access activity is intercepted at the file system by the local software agent in accordance with the applicable security policy. The collector applies the security policy against the audit trail data received from at least one of the plural file systems and, in response thereto, takes a given action.
公开/授权文献
信息查询