Claims
- 1. A method for logging access system events, comprising the steps of:
detecting an access system event; creating a log entry for said access system event; and storing information from an identity profile in said log entry, said identity profile pertains to a first user, said access system event involves said first user.
- 2. A method according to claim 1, wherein:
said access system event is an authorization success event.
- 3. A method according to claim 1, wherein:
said access system event is an authorization failure event.
- 4. A method according to claim 1, wherein:
said access system event is an authentication success event.
- 5. A method according to claim 1, wherein:
said access system event is an authentication failure event.
- 6. A method according to claim 1, further comprising the step of:
storing an identification of a resource in said log entry, said access system event pertains to said resource.
- 7. A method according to claim 1, further comprising the step of:
storing an identification of an access rule in said log entry, said access rule is used during said access system event.
- 8. A method according to claim 1, further comprising the step of:
storing an identification of said access system event in said log entry.
- 9. A method according to claim 1, further comprising the step of:
storing an identification of a time of said access system event in said log entry.
- 10. A method according to claim 1, wherein:
said step of detecting an access event consists of denying authorization for said first user to access a resource.
- 11. A method according to claim 1, further comprising the step of:
accessing said identity profile in an LDAP directory.
- 12. A method according to claim 1, further comprising the step of:
receiving configuration information for said log entry, said configuration information includes an identification of a type of access system event to log.
- 13. A method according to claim 1, further comprising the step of:
receiving configuration information for said log entry, said configuration information includes an identification of one or more identity profile attributes to store in said log entry.
- 14. A method according to claim 1, further comprising the steps of:
receiving a request to access a resource from said first user, said access system event pertains to said resource; attempting to authorize said first user to access said resource; and denying authorization for said first user to access said resource.
- 15. A method according to claim 1, further comprising the steps of:
receiving a request to access a resource from said first user, said access system event pertains to said resource; attempting to authorize said first user to access said resource; and allowing said first user to access said resource.
- 16. A method according to claim 1, further comprising the steps of:
receiving a default audit rule for a set of resources; receiving a specific audit rule for a subset of said set of resources; receiving a request to access a first resource from said first user; and determining that said first resource is not in said subset of said set of resources, said step of creating a log entry is performed according to said default audit rule.
- 17. A method according to claim 1, further comprising the steps of:
receiving a default audit rule for a set of resources; receiving a specific audit rule for a subset of said set of resources; receiving a request to access a first resource from said first user; and determining that said first resource is in said subset of said set of resources, said step of creating a log entry is performed according to said specific audit rule.
- 18. One or more processor readable storage devices having processor readable code embodied on said processor readable storage devices, said processor readable code for programming one or more processors to perform a method comprising the steps of:
detecting an access system event; creating a log entry for said access system event; and storing information from an identity profile in said log entry, said identity profile pertains to a first user, said access system event involves said first user.
- 19. One or more processor readable storage devices according to claim 18, wherein said method further comprises the step of:
accessing said identity profile in an LDAP directory.
- 20. One or more processor readable storage devices according to claim 18, wherein said method further comprises the step of:
receiving configuration information for said log entry, said configuration information includes an identification of a type of access system event to log.
- 21. One or more processor readable storage devices according to claim 18, wherein said method further comprises the step of:
receiving configuration information for said log entry, said configuration information includes an identification of one or more identity profile attributes to store in said log entry.
- 22. One or more processor readable storage devices according to claim 18, wherein said method further comprises the steps of:
receiving a request to access a resource from said first user, said access system event pertains to said resource; attempting to authorize said first user to access said resource; and denying authorization for said first user to access said resource.
- 23. One or more processor readable storage devices according to claim 18, wherein said method further comprises the steps of:
receiving a request to access a resource from said first user, said access system event pertains to said resource; attempting to authorize said first user to access said resource; and allowing said first user to access said resource.
- 24. One or more processor readable storage devices according to claim 18, wherein said method further comprises the steps of:
receiving a default audit rule for a set of resources; receiving a specific audit rule for a subset of said set of resources; receiving a request to access a first resource from said first user; and determining that said first resource is not in said subset of said set of resources, said step of creating a log entry is performed according to said default audit rule.
- 25. One or more processor readable storage devices according to claim 18, wherein said method further comprises the steps of: receiving a default audit rule for a set of resources;
receiving a specific audit rule for a subset of said set of resources; receiving a request to access a first resource from said first user; and determining that said first resource is in said subset of said set of resources, said step of creating a log entry is performed according to said specific audit rule.
- 26. An access system, comprising:
a communication interface; one or more storage devices; and one or more processors in communication with said one or more storage devices and said communication interface, said one or more processors programmed to preform a method comprising the steps of:
detecting an access system event, creating a log entry for said access system event, and storing information from an identity profile in said log entry, said identity profile pertains to a first user, said access system event involves said first user.
- 27. An access system according to claim 26, wherein said method further comprises the step of:
accessing said identity profile in an LDAP directory.
- 28. An access system according to claim 26, wherein said method further comprises the step of:
receiving configuration information for said log entry, said configuration information includes an identification of a type of access system event to log.
- 29. An access system according to claim 26, wherein said method further comprises the step of:
receiving configuration information for said log entry, said configuration information includes an identification of one or more identity profile attributes to store in said log entry.
- 30. An access system according to claim 26, wherein said method further comprises the steps of:
receiving a request to access a resource from said first user, said access system event pertains to said resource; attempting to authorize said first user to access said resource; and denying authorization for said first user to access said resource.
- 31. An access system according to claim 26, wherein said method further comprises the steps of:
receiving a request to access a resource from said first user, said access system event pertains to said resource; attempting to authorize said first user to access said resource; and allowing said first user to access said resource.
- 32. An access system according to claim 26, wherein said method further comprises the steps of:
receiving a default audit rule for a set of resources; receiving a specific audit rule for a subset of said set of resources; receiving a request to access a first resource from said first user; and determining that said first resource is not in said subset of said set of resources, said step of creating a log entry is performed according to said default audit rule.
- 33. An access system according to claim 26, wherein said method further comprises the steps of:
receiving a default audit rule for a set of resources; receiving a specific audit rule for a subset of said set of resources; receiving a request to access a first resource from said first user; and determining that said first resource is in said subset of said set of resources, said step of creating a log entry is performed according to said specific audit rule.
- 34. An access system according to claim 26, wherein:
said access system includes an identity management system and an access management system.
Parent Case Info
[0001] This application claims the benefit of U.S. Provisional Application No. 60/216,955, Web Access Management, filed Jul. 10, 2000, incorporated herein by reference.
Provisional Applications (1)
|
Number |
Date |
Country |
|
60216955 |
Jul 2000 |
US |