Method and apparatus for tracing data in audit trail, and computer product
    1.
    发明申请
    Method and apparatus for tracing data in audit trail, and computer product 有权
    跟踪审计跟踪数据的方法和装置,以及计算机产品

    公开(公告)号:US20070011303A1

    公开(公告)日:2007-01-11

    申请号:US11360395

    申请日:2006-02-24

    IPC分类号: G06F15/173

    CPC分类号: H04L63/08 H04L63/20

    摘要: In an information system, a web server records web access logs of a client outside of a LAN. A mail server records transmission/reception logs of e-mails. A DB server records access right operation logs. A task application server records DB access log. An administrative server collects logs recorded in the web server, the mail server, the DB server, and the task application server, and operation logs of the client terminals to trace a person and an operation related to information leakage using the collected logs.

    摘要翻译: 在信息系统中,Web服务器记录LAN外部的客户端的Web访问日志。 邮件服务器记录电子邮件的发送/接收日志。 DB服务器记录访问权限操作日志。 任务应用程序服务器记录数据库访问日志。 管理服务器收集记录在Web服务器,邮件服务器,DB服务器和任务应用服务器中的日志,以及客户终端的操作日志,以使用收集的日志跟踪人员和与信息泄漏相关的操作。

    Method and apparatus for tracing data in audit trail, and computer product
    2.
    发明授权
    Method and apparatus for tracing data in audit trail, and computer product 有权
    跟踪审计跟踪数据的方法和装置,以及计算机产品

    公开(公告)号:US08266117B2

    公开(公告)日:2012-09-11

    申请号:US11360395

    申请日:2006-02-24

    IPC分类号: G06F17/30

    CPC分类号: H04L63/08 H04L63/20

    摘要: In an information system, a web server records web access logs of a client outside of a LAN. A mail server records transmission/reception logs of e-mails. A DB server records access right operation logs. A task application server records DB access log. An administrative server collects logs recorded in the web server, the mail server, the DB server, and the task application server, and operation logs of the client terminals to trace a person and an operation related to information leakage using the collected logs.

    摘要翻译: 在信息系统中,Web服务器记录LAN外部的客户端的Web访问日志。 邮件服务器记录电子邮件的发送/接收日志。 DB服务器记录访问权限操作日志。 任务应用程序服务器记录数据库访问日志。 管理服务器收集记录在Web服务器,邮件服务器,DB服务器和任务应用服务器中的日志,以及客户终端的操作日志,以使用收集的日志跟踪人员和与信息泄漏相关的操作。

    Computer program, method, and system for access control
    4.
    发明授权
    Computer program, method, and system for access control 有权
    用于访问控制的计算机程序,方法和系统

    公开(公告)号:US08448217B2

    公开(公告)日:2013-05-21

    申请号:US11897187

    申请日:2007-08-29

    CPC分类号: G06F21/6218 G06F2221/2141

    摘要: A computer program, method, and system for access control, which are capable of keeping and guaranteeing consistency of access control settings. A collector collects access control information and resource information which are set for each unit of processing such as an application and a file system and are transmitted from a transmitter, and stores them in an access control information memory. A combiner combines the collected access control information to create and store combined access control information in a combined access control information memory. A consistency adjuster analyzes the policies defined in the combined access control information stored in the combined access control information memory to detect inconsistency, and if inconsistency is detected, resolves the inconsistency according to an inconsistency measure policy. Thus, consistent filtering master information for the entire system is created and stored in a filtering master information memory.

    摘要翻译: 一种用于访问控制的计算机程序,方法和系统,其能够保持和保证访问控制设置的一致性。 收集器收集对于诸如应用和文件系统的每个处理单元设置的访问控制信息和资源信息,并且从发送器发送,并将它们存储在访问控制信息存储器中。 组合器组合收集的访问控制信息以在组合的访问控制信息存储器中创建和存储组合的访问控制信息。 一致性调整器分析存储在组合访问控制信息存储器中的组合访问控制信息中定义的策略以检测不一致性,并且如果检测到不一致,则根据不一致度量策略来解决不一致。 因此,整个系统的一致的过滤主信息被创建并存储在过滤主信息存储器中。

    ACCESS CONTROL POLICY COMPLIANCE CHECK PROCESS
    6.
    发明申请
    ACCESS CONTROL POLICY COMPLIANCE CHECK PROCESS 有权
    访问控制政策合规检查流程

    公开(公告)号:US20090300711A1

    公开(公告)日:2009-12-03

    申请号:US12361269

    申请日:2009-01-28

    IPC分类号: G06F21/00

    摘要: A storage medium on which is recorded a program for causing an information processing device. The program executes, an access right management information obtainment process for obtaining access right management information, a violation detection process for obtaining a policy from a policy storing unit for storing the policy set for the resource or the access to the resource, for checking whether or not the access right management information complies with the policy, and for detecting access right management information, a policy compliance level calculation process for calculating a risk score in accordance with a degree of risk of the violation, and for calculating a level of compliance with the policy.

    摘要翻译: 其上记录有用于引起信息处理装置的程序的存储介质。 该程序执行用于获取访问权限管理信息的访问权限管理信息获取处理,用于从用于存储资源的策略集或资源访问的策略存储单元获取策略的违规检测处理,以检查是否或 访问权限管理信息不符合该策略,并且用于检测访问权限管理信息,根据违规风险程度计算风险分数的策略合规级别计算过程,以及用于计算与 政策。

    Access control policy compliance check process
    9.
    发明授权
    Access control policy compliance check process 有权
    访问控制策略合规性检查流程

    公开(公告)号:US08413211B2

    公开(公告)日:2013-04-02

    申请号:US12361269

    申请日:2009-01-28

    IPC分类号: G06F17/30

    摘要: A storage medium on which is recorded a program for causing an information processing device. The program executes, an access right management information obtainment process for obtaining access right management information, a violation detection process for obtaining a policy from a policy storing unit for storing the policy set for the resource or the access to the resource, for checking whether or not the access right management information complies with the policy, and for detecting access right management information, a policy compliance level calculation process for calculating a risk score in accordance with a degree of risk of the violation, and for calculating a level of compliance with the policy.

    摘要翻译: 其上记录有用于引起信息处理装置的程序的存储介质。 该程序执行用于获取访问权限管理信息的访问权限管理信息获取处理,用于从用于存储资源的策略集或资源访问的策略存储单元获取策略的违规检测处理,以检查是否或 访问权限管理信息不符合该策略,并且用于检测访问权限管理信息,根据违规风险程度计算风险分数的策略合规级别计算过程,以及用于计算与 政策。