发明名称 Service compliance enforcement using user activity monitoring and work request verification
摘要 Auditing system logs of a remote client device is provided. Login session information entered at a workstation device accessing the remote client device to perform an activity associated with a work request is received. An access token is generated based on the login session information and information associated with the work request on the remote client device. The access token is compared with an audit log report of the remote client device that includes the activity associated with the work request performed by the workstation device on the remote client device. It is determined whether information in the access token matches information in the audit log report of the remote client device. In response to determining that the information in the access token does not match the information in the audit log report of the remote client device, an action alert is sent.
申请公布号 US8826403(B2) 申请公布日期 2014.09.02
申请号 US201213364157 申请日期 2012.02.01
申请人 International Business Machines Corporation 发明人 Bhaskaran Kumar;Driscoll Paul;Hernandez Milton H.;Ruan Yaoping
分类号 G06F17/30 主分类号 G06F17/30
代理机构 Yee & Associates, P.C. 代理人 Yee & Associates, P.C. ;Percello Lou
主权项 1. A computer implemented method for auditing system logs of a remote client device, the computer implemented method comprising: receiving, by a data processing device, login session information that includes an internet protocol address of a workstation device where a user logged in, a name of the user, a timestamp of the workstation device when the login session information was generated, a first timestamp of the remote client device when the user logged in to the remote client device to perform an activity associated with a work request, a second timestamp of the remote client device when the user logged out of the remote client device, a reason to access the remote client device, and an internet protocol address of the remote client device entered at the workstation device accessing the remote client device via a network to perform the activity to correct a problem on the remote client device associated with the work request, wherein the remote client device is a remote server device that performs an information technology service for customers, and wherein the information technology service is regulated by federal regulations; retrieving, by the data processing device, information associated with the work request to correct the problem on the remote client device that includes a problem ticket identification, a problem ticket status, the name of the user assigned to the problem ticket identification, a description of the problem ticket, and a customer identification associated with the remote client device; generating, by the data processing device, an access token based on the login session information that includes the internet protocol address of the workstation device where the user logged in, the name of the user, the timestamp of the workstation device when the login session information was generated, the first timestamp of the remote client device when the user logged in to the remote client device to perform the activity associated with the work request, the second timestamp of the remote client device when the user logged out of the remote client device, the reason to access the remote client device, and the internet protocol address of the remote client device entered at the workstation device accessing the remote client device to perform the activity to correct the problem on the remote client device associated with the work request and the information associated with the work request to correct the problem on the remote client device that includes the problem ticket identification, the problem ticket status, the name of the user assigned to the problem ticket identification, the description of the problem ticket, and the customer identification associated with the remote client device; comparing, by the data processing device, the access token based on the login session information and the information associated with the work request to correct the problem on the remote client device with an audit log report of the remote client device that includes the activity to correct the problem on the remote client device associated with the work request performed by the workstation device on the remote client device; determining, by the data processing device, whether information in the access token matches information in the audit log report of the remote client device; responsive to determining that the information in the access token matches the information in the audit log report of the remote client device, storing, by the data processing device, an association between the access token and the audit log report of the remote client device demonstrating compliance with the federal regulations; and responsive to determining that the information in the access token does not match the information in the audit log report of the remote client device, sending, by the data processing device, an action alert via a voicemail messaging system to compliance monitoring personnel.
地址 Armonk NY US