IP Library Granted Patent US 7,636,736
Granted Patent B1
US 7,636,736 · App. 11/232,253 · Granted Dec 22, 2009

Method and apparatus for creating and using a policy-based access/change log

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,636,736
App. No.
11/232,253
Granted
Dec 22, 2009
Kind
B1
Abstract

A method and apparatus for creating and using a policy-based file access/change log. Using the policy-based techniques, specific objects within the file system are selected for logging within an access/change log. These selected objects are then processed to identify attributes of the selected objects that are to be logged such that a policy is created regarding the objects to be logged and the attributes of those objects. Lastly, the policy is applied to the object either by having a separate object (file) created that is related to the object to be logged that identifies the policy for logging, or by attaching certain attributes directly to the object such that access to the object identifies the logging policy for that object. When an object that uses policy-based logging is changed, the object access/change log policy is utilized to log only the information that is identified in the policy. In this manner, the amount of information that is logged is controlled by the logging policy, limiting the size of the access/change log.

Claims (37)

1. A method for creating a logging policy for an access/change log, comprising:

selecting at least one object of a file system executing on a computer system to be logged;

identifying at least one attribute of the selected at least one object to be logged; and

generating a logging policy based upon the selected at least one object and the at least one attribute wherein the at least one attribute comprises at least one of user name/identifier, group name/identifier, application name/identifier, computer identity information, file access time, file modification time, file creation time, file allocation/reallocation/reservation policies, file name/path/inode number, size of the file, number of links to a file, offset/length of access/modification, access control lists, filed named data streams.

2. The method of claim 1 further comprising:

associating the logging policy with the at least one object.

3. The method of claim 2 further comprising storing the logging policy in a file.

4. The method of claim 2 further comprising storing the logging policy in metadata related to the at least one object.

5. The method of claim 1 further comprising:

detecting at least one of a change or access associated with the at least one object;

accessing the logging policy; and

updating a access/change log in accordance with the logging policy.

6. The method of claim 1 wherein the selected at least one object forms a subset of less than all objects that are available for logging.

7. A method of using a policy-based access/change log comprising;

detecting at least one of a change or access associated with at least one object of a file system executing on a computer system;

accessing a logging policy associated with the at least one object; and

updating a access/change log in accordance with the logging policy, wherein the logging policy was generated based upon at least one attribute of the at least one object wherein the at least one attribute comprises at least one of user name/identifier, group name/identifier, application name/identifier, computer identity information, file access time, file modification time, file creation time, file allocation/reallocation/reservation policies, file name/path/inode number, size of the file, number of links to a file, offset/length of access/modification, access control lists, filed named data streams.

8. The method of claim 7 wherein the updating step further comprises:

logging at least one attribute of the at least one object in accordance with the logging policy.

9. A computer readable medium comprising software that, when executed by a processor within a computer system, causes the computer system to perform a method for creating a logging policy for an access/change log, comprising:

selecting at least one object of a file system executing on a computer system to be logged;

identifying at least one attribute of the selected at least one object to be logged; and

generating a logging policy based upon the selected at least one object and the at least one attribute wherein the at least one attribute comprises at least one of user name/identifier, group name/identifier, application name/identifier, computer identity information, file access time, file modification time, file creation time, file allocation/reallocation/reservation policies, file name/path/inode number, size of the file, number of links to a file, offset/length of access/modification, access control lists, filed named data streams.

10. The method of claim 9 further comprising:

associating the logging policy with the at least one object.

11. The method of claim 10 further comprising storing the logging policy in a file.

12. The method of claim 10 further comprising storing the logging policy in metadata related to the at least one object.

13. The method of claim 9 further comprising:

detecting at least one of a change or access associated with the at least one object;

accessing the logging policy; and

updating a access/change log in accordance with the logging policy.

14. A computer readable medium comprising software that, when executed by a processor within a computer system, causes the computer system to perform a method of using a policy-based access/change log comprising;

detecting at least one of a change or access associated with at least one object of a file system executing on a computer system;

accessing a logging policy associated with the at least one object; and

updating a access/change log in accordance with the logging policy, wherein the logging policy was generated based upon at least one attribute of the at least one object wherein the at least one attribute comprises at least one of user name/identifier, group name/identifier, application name/identifier, computer identity information, file access time, file modification time, file creation time, file allocation/reallocation/reservation policies, file name/path/inode number, size of the file, number of links to a file, offset/length of access/modification, access control lists, filed named data streams.

15. The method of claim 14 wherein the updating step further comprises:

logging at least one attribute of the at least one object in accordance with the logging policy.

Assignments (11)
RELEASE OF SECURITY INTEREST Recorded Dec 16, 2024
From: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC (F/K/A VERITAS US IP HOLDINGS LLC)
Reel/Frame 069712/0090 →
RELEASE OF SECURITY INTEREST Recorded Dec 13, 2024
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069634/0584 →
ASSIGNMENT OF SECURITY INTEREST IN PATENT COLLATERAL Recorded Nov 25, 2024
From: BANK OF AMERICA, N.A., AS ASSIGNOR
To: ACQUIOM AGENCY SERVICES LLC, AS ASSIGNEE
Reel/Frame 069440/0084 →
TERMINATION AND RELEASE OF SECURITY IN PATENTS AT R/F 037891/0726 Recorded Nov 30, 2020
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: VERITAS US IP HOLDINGS, LLC
Reel/Frame 054535/0814 →
SECURITY INTEREST Recorded Aug 20, 2020
From: VERITAS TECHNOLOGIES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 054370/0134 →
MERGER AND CHANGE OF NAME Recorded Apr 18, 2016
From: VERITAS US IP HOLDINGS LLC; VERITAS TECHNOLOGIES LLC
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 038455/0752 →
SECURITY INTEREST Recorded Feb 23, 2016
From: VERITAS US IP HOLDINGS LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037891/0001 →
SECURITY INTEREST Recorded Feb 23, 2016
From: VERITAS US IP HOLDINGS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 037891/0726 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2016
From: SYMANTEC CORPORATION
To: VERITAS US IP HOLDINGS LLC
Reel/Frame 037697/0412 →
CHANGE OF NAME Recorded Sep 21, 2007
From: VERITAS OPERATING CORPORATION
To: SYMANTEC OPERATING CORPORATION
Reel/Frame 019866/0480 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2005
From: KUMAR, NOOKALA SUNDER PHANI; BORATE, MILIND; NAGARAJ, MURALI; NAGARALU, SREE HARI
To: VERITAS OPERATING CORPORATION
Reel/Frame 017023/0084 →