| US 7,552,472 B2 | ||
| Developing and assuring policy documents through a process of refinement and classification | ||
| Paul T. Baffes, Austin, Tex. (US); John Michael Garrison, Austin, Tex. (US); Michael Gilfix, Austin, Tex. (US); Allan Hsu, Centerville, Ohio (US); and Tyron Jerrod Stading, Austin, Tex. (US) | ||
| Assigned to International Business Machines Corporation, Armonk, N.Y. (US) | ||
| Filed on Dec. 19, 2002, as Appl. No. 10/324,502. | ||
| Prior Publication US 2004/0123145 A1, Jun. 24, 2004 | ||
| Int. Cl. G06F 15/177 (2006.01) | ||
| U.S. Cl. 726—22 [726/1; 709/223; 709/224; 709/225] | 28 Claims |

| 1. A computer implemented method of providing enhanced monitoring and enforcement of usage policy and security for a data
processing system network, said method comprising:
monitoring events occurring on said network;
storing data identifying said events as system event data;
analyzing said system event data with a set of initial policy constraints, wherein said analyzing step includes the steps
of:
retrieving said system event data from a network session;
storing said system event data within a database, wherein said database is a text file of events of interest within the system;
extracting system event data from said database by parsing each line of said database for identifying information of events
that are known and labeled within the initial policy constraints; and
labeling at least some system event data with a label that indicates when said at least some system event data complies or
does not comply with said initial policy constraints; and
enabling a system administrator to override at least some of the labeling to produce a set of re-labeled events;
generating refined policy constraints by applying a theory refinement algorithm to the set of re-labeled events, the theory
refinement algorithm configured to automatically modify the initial policy constraints to generate refined policy constraints
that are consistent with the re-labeled events; and
continuing monitoring and enforcement of said usage policy and security of said network via said refined policy constraints.
|