| US 7,543,333 B2 | ||
| Enhanced computer intrusion detection methods and systems | ||
| Bhalchandra S. Pandit, Redmond, Wash. (US); Praerit Garg, Kirkland, Wash. (US); Richard B. Ward, Redmond, Wash. (US); Paul J. Leach, Seattle, Wash. (US); Scott A. Field, Redmond, Wash. (US); Robert P. Reichel, Redmond, Wash. (US); and John E. Brezak, Woodinville, Wash. (US) | ||
| Assigned to Microsoft Corporation, Redmond, Wash. (US) | ||
| Filed on Apr. 08, 2002, as Appl. No. 10/118,808. | ||
| Prior Publication US 2003/0191953 A1, Oct. 09, 2003 | ||
| Int. Cl. G06F 21/06 (2006.01); G06F 21/20 (2006.01); G06F 21/22 (2006.01); G06F 21/24 (2006.01); G08B 23/00 (2006.01); G06F 15/173 (2006.01); H04K 1/00 (2006.01) | ||
| U.S. Cl. 726—23 [709/224; 709/225; 713/182] | 39 Claims |

| 1. A method to enable detection of unauthorized access to a platform, the method comprising:
providing at least one parameter that is associated with an authentication process;
encrypting said at least one parameter to form at least one audit identifier;
combining a plurality of parameters associated with said authentication process to form said at least one parameter;
recording an audit entry in an audit log, the audit entry comprising the at least one audit identifier, an associated audit
event and an associated unique device identifier, wherein the audit entry is associated with a principal seeking authentication,
wherein the associated unique device identifier includes a device network address associated with the principal seeking authentication;
and
sending the audit entry to an auditing service over a network, said auditing service being configured to gather and analyze
a plurality of audit entries from a plurality of platforms;
wherein said sending enables said auditing service to analyze the recorded audit entry,
wherein the plurality of parameters associated with said authentication process comprise:
(i) user identifying information;
(ii) realm identifying information; and
(iii) a timestamp; and
wherein the auditing service tracks principal movement and login ID used at each platform of a plurality of platforms by analyzing
audit entries associated with said at least one audit identifier and with the principal seeking authentication, the analyzing
the associated audit entries comprising:
identifying within the associated audit entries, at least one audit entry that contains an audit event that is a switch event,
the switch event indicating that the principle seeking authentication has switched from a first login ID to a second login
ID; and
deducing that the principle is masquerading as a user associated with the second login ID based on correlation of the switch
event with audit identifiers, audit events and unique device identifiers contained in the associated audit entries.
|