File system monitoring and auditing via monitor system having user-configured policies

    公开(公告)号:US11184399B2

    公开(公告)日:2021-11-23

    申请号:US16665463

    申请日:2019-10-28

    摘要: Centralized monitoring of plural file systems that operate within or in association with an enterprise computing environment is provided. Each of the plural file systems are provided with a security policy, wherein the security policy defines one or more file system access activities to be monitored at the file system. Each file system is instrumented with a software agent that intercepts the relevant file system access activity. A centralized collector component is operative to receive from each of the plural file systems audit trail data, wherein the audit trail data is data that has been generated locally as file system access activity is intercepted at the file system by the local software agent in accordance with the applicable security policy. The collector applies the security policy against the audit trail data received from at least one of the plural file systems and, in response thereto, takes a given action.

    File system monitoring and auditing via monitor system having user-configured policies

    公开(公告)号:US10462183B2

    公开(公告)日:2019-10-29

    申请号:US14804532

    申请日:2015-07-21

    摘要: Centralized monitoring of plural file systems that operate within or in association with an enterprise computing environment is provided. Each of the plural file systems are provided with a security policy, wherein the security policy defines one or more file system access activities to be monitored at the file system. Each file system is instrumented with a software agent that intercepts the relevant file system access activity. A centralized collector component is operative to receive from each of the plural file systems audit trail data, wherein the audit trail data is data that has been generated locally as file system access activity is intercepted at the file system by the local software agent in accordance with the applicable security policy. The collector applies the security policy against the audit trail data received from at least one of the plural file systems and, in response thereto, takes a given action.

    File system monitoring and auditing via monitor system having user-configured policies
    3.
    发明申请
    File system monitoring and auditing via monitor system having user-configured policies 审中-公开
    通过具有用户配置策略的监控系统进行文件系统监控和审核

    公开(公告)号:US20170024408A1

    公开(公告)日:2017-01-26

    申请号:US14804532

    申请日:2015-07-21

    IPC分类号: G06F17/30 H04L29/06

    摘要: Centralized monitoring of plural file systems that operate within or in association with an enterprise computing environment is provided. Each of the plural file systems are provided with a security policy, wherein the security policy defines one or more file system access activities to be monitored at the file system. Each file system is instrumented with a software agent that intercepts the relevant file system access activity. A centralized collector component is operative to receive from each of the plural file systems audit trail data, wherein the audit trail data is data that has been generated locally as file system access activity is intercepted at the file system by the local software agent in accordance with the applicable security policy. The collector applies the security policy against the audit trail data received from at least one of the plural file systems and, in response thereto, takes a given action.

    摘要翻译: 提供了在企业计算环境中或与企业计算环境相关联的多个文件系统的集中监控。 多个文件系统中的每一个被提供有安全策略,其中安全策略定义要在文件系统处监视的一个或多个文件系统访问活动。 每个文件系统都装有一个拦截相关文件系统访问活动的软件代理。 集中收集器组件可操作以从多个文件系统中的每一个接收审核跟踪数据,其中审计跟踪数据是当本地软件代理程序根据文件系统访问活动在文件系统被截取时本地生成的数据, 适用的安全策略。 收集器对从多个文件系统中的至少一个接收的审计跟踪数据应用安全策略,并且作为响应,采取给定的动作。

    File system monitoring and auditing via monitor system having user-configured policies

    公开(公告)号:US20200067988A1

    公开(公告)日:2020-02-27

    申请号:US16665463

    申请日:2019-10-28

    摘要: Centralized monitoring of plural file systems that operate within or in association with an enterprise computing environment is provided. Each of the plural file systems are provided with a security policy, wherein the security policy defines one or more file system access activities to be monitored at the file system. Each file system is instrumented with a software agent that intercepts the relevant file system access activity. A centralized collector component is operative to receive from each of the plural file systems audit trail data, wherein the audit trail data is data that has been generated locally as file system access activity is intercepted at the file system by the local software agent in accordance with the applicable security policy. The collector applies the security policy against the audit trail data received from at least one of the plural file systems and, in response thereto, takes a given action.