发明名称 A distributed auditing subsystem for an operating system.
摘要 <p>The distributed auditing subsystem invention runs in a UNIX-like operating system environment with a hierarchical file system. The invention provides an audit trail of accesses to the objects it protects and maintains and protects that audit trail from modification or unauthorized access or destruction. The audit data generated by the invention is protected so that read access to it is limited to those who are authorized for audit data. The invention enables the recording of events which are relevant to the maintenance of the security of the system, such as the use of identification and authentication mechanisms, the introduction of objects into a user's address space, the deletion of such objects, actions taken by computer operators and system administrators and/or system security officers, and other security relevant events. The invention generates an audit record for each recorded event which includes the date and time of the event, the user, the type of event, and the success or failure of the event. The invention performs an on-line compression of the audit trail log file using a UNIX-type daemon process. The audit daemon process has a restartable feature that enables it to recover after node failures. The invention finds particular application in a distributed processing system in which files may be variously stored at diverse storage locations in the network. In such a distributed system, the audit process of the invention can be carried out on a network-wide, distributed basis so that audit files located at diverse storage locations can be concentrated into a single audit trail log file. In this manner, a secure computer system which conforms to the DoD Standard is achieved, which can generate, manipulate and data compress audit information concerning actions affecting the security of the system.</p>
申请公布号 EP0325777(B1) 申请公布日期 1994.05.04
申请号 EP19880121479 申请日期 1988.12.22
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 HECHT, MATTHEW STERLING;WEI, TSUNG TSAN;JOHRI, ABHAI;STEVENS, DOUGLAS H.
分类号 G06F12/14;G06F1/00;G06F9/46;G06F11/30;G06F11/34;G06F12/00;G06F15/00;G06F15/16;G06F15/177;G06F21/00;G06F21/24;(IPC1-7):G06F11/30 主分类号 G06F12/14
代理机构 代理人
主权项
地址