发明授权
US06574627B1 Method and apparatus for the verification of server access logs and statistics
失效
用于验证服务器访问日志和统计信息的方法和装置
- 专利标题: Method and apparatus for the verification of server access logs and statistics
- 专利标题(中): 用于验证服务器访问日志和统计信息的方法和装置
-
申请号: US09256417申请日: 1999-02-24
-
公开(公告)号: US06574627B1公开(公告)日: 2003-06-03
- 发明人: Francesco Bergadano , Pancrazio De Mauro
- 申请人: Francesco Bergadano , Pancrazio De Mauro
- 主分类号: G06F15163
- IPC分类号: G06F15163
摘要:
A method and apparatus for verifying the correctness of server access logs. The server is required to transfer the relevant log information for each client request to, an authentication device. In a preferred embodiment, the device has to be tamper-evident and responds with a Message Authentication Code (MAC) and a binary digit B. The MAC is stored on an accessible medium by the server. If B=0, the request is processed normally. If B=1 (this happens with a small probability), the server is required to issue a “redirect” response to the client, instructing it to connect to a different server, controlled by a certification agency. The agency's server logs this request and redirects it back to the original server, where it is eventually serviced. The certification agency periodically verifies each MAC and checks whether requests where B=1 correspond to an associated client log entry on its server. If this does not happen in a high number of cases, certification of the log file could be denied, based on the agency's policy. A preferred embodiment of this invention is with the HTTP protocol, for the auditing of Web site popularity.
信息查询