US 7,552,472 B2
Developing and assuring policy documents through a process of refinement and classification
Paul T. Baffes, Austin, Tex. (US); John Michael Garrison, Austin, Tex. (US); Michael Gilfix, Austin, Tex. (US); Allan Hsu, Centerville, Ohio (US); and Tyron Jerrod Stading, Austin, Tex. (US)
Assigned to International Business Machines Corporation, Armonk, N.Y. (US)
Filed on Dec. 19, 2002, as Appl. No. 10/324,502.
Prior Publication US 2004/0123145 A1, Jun. 24, 2004
Int. Cl. G06F 15/177 (2006.01)
U.S. Cl. 726—22  [726/1; 709/223; 709/224; 709/225] 28 Claims
OG exemplary drawing
 
1. A computer implemented method of providing enhanced monitoring and enforcement of usage policy and security for a data processing system network, said method comprising:
monitoring events occurring on said network;
storing data identifying said events as system event data;
analyzing said system event data with a set of initial policy constraints, wherein said analyzing step includes the steps of:
retrieving said system event data from a network session;
storing said system event data within a database, wherein said database is a text file of events of interest within the system;
extracting system event data from said database by parsing each line of said database for identifying information of events that are known and labeled within the initial policy constraints; and
labeling at least some system event data with a label that indicates when said at least some system event data complies or does not comply with said initial policy constraints; and
enabling a system administrator to override at least some of the labeling to produce a set of re-labeled events;
generating refined policy constraints by applying a theory refinement algorithm to the set of re-labeled events, the theory refinement algorithm configured to automatically modify the initial policy constraints to generate refined policy constraints that are consistent with the re-labeled events; and
continuing monitoring and enforcement of said usage policy and security of said network via said refined policy constraints.