IP Library Granted Patent US 9,251,196
Granted Patent B2
US 9,251,196 · App. 13/022,699 · Granted Feb 2, 2016

Monitoring and auditing system

Inventor: Robert Karch (Greenwich, CT)
Assignee: Teleran Technologies Inc.
G06F17/30368
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,251,196
App. No.
13/022,699
Granted
Feb 2, 2016
Kind
B2
Abstract

An improved method and apparatus for auditing database queries, wherein comments are added by a server prior to the server forwarding the queries to the database system. The comments are then used to derive audit information, which is correlated with other audit information in a different server, to produce a more complete audit record.

Claims (40)

1. A method of logging audit information related to database access, said method comprising:

utilizing a first server to accept database queries transmitted from plural users to said first server, and logging first audit information in a first server log, the first audit information including first sets of parameters for respective reports logged in said first server log;

transmitting said queries from said first server to a database system after logging said first audit information;

monitoring a communications channel between said first server and said database system;

when said query is detected on the communications channel during the monitoring step, capturing second audit information into a second server log from the communications channel, wherein said second audit information includes second sets of parameters for respective reports stored in said second server log;

correlating the first audit information with the second audit information using a parameter in common among the first and second sets of parameters, wherein said correlating step includes matching a time of transaction recorded in said first server log with a time of transaction recorded in said second server log;

identifying a particular one of the reports having said parameter in common among the first and second sets of parameters; and

combining data from said first audit information and said second audit information obtained for said identified particular report to generate a full audit record for said particular report.

2. The method of claim 1 wherein said second audit information includes at least some information that is added to said queries after said queries are transmitted from said plural users to said first server but prior to transmitting said queries from said first server to said database system.

3. The method of claim 2 wherein said first audit information includes at least one of report name, universe/catalog name, and user id of a user initiating at least one of said queries through said first server.

4. The method of claim 3 wherein the user initiating said at least one of said queries does so through a thin client in communication with said first server.

5. The method of claim 2 wherein said audit information is added as a comment.

6. A system for logging information related to database queries, said system comprising:

a first server that accepts database queries from plural users,

a second server that monitors communications between said first server and a database system, said second server recording a first log from information embedded as comments by said first server in messages transmitted from said first server to the database system, and

a third server that combines information in said first log with information placed in a second log by said first server, in order to construct a third log of desired information relevant to said queries, wherein said third log updates rules governing acceptable queries for querying said database.

7. The system of claim 6 wherein said information placed in the second log by said first server includes a user ID to identify a user that initiated a database transaction.

8. A method of implementing database access comprising:

consolidating, at a first server, queries from plural users to be sent to a database,

extracting, at the first server, information from said plural queries and logging first audit information in a first log,

adding, at the first server, comments to said queries and sending said queries to the database,

compiling, at a second server, second audit information into a second log by monitoring communications to said database and reading said comments,

correlating the first audit information with the second audit information using a parameter in common, wherein said correlating step includes matching a time of transaction recorded in the first log with a time of transaction recorded in the second log, and

combining said extracted information with said compiled information to form a third log, said step of combining utilizing identifiers added to said extracted information and said compiled information.

9. The method of claim 8 wherein said database is accessed via a Software Query Language (SQL) query.

10. A method comprising:

receiving, at a first server, queries transmitted from plural users,

logging, at the first server, first audit information into a first server log, wherein the first audit information comprises first sets of parameters for respective reports logged in the first server log,

transmitting, by the first server, the queries from the first server to a database system after logging the first audit information,

capturing, at a second server, second audit information into a second server log obtained from a communications channel between the first server and the database system, wherein the second audit information comprises second sets of parameters for respective reports stored in the second server log,

correlating the first audit information with the second audit information using a parameter in common among the first and second sets of parameters, wherein said correlating step includes matching a time of transaction recorded in said first server log with a time of transaction recorded in said second server log,

identifying a particular one of the reports having the parameter in common among the first and second sets of parameters, and

combining data from the first audit information and the second audit information obtained for the identified particular report to generate a full audit record for the particular report.

11. The method of claim 10 wherein said first audit information is user identities.

12. A system comprising:

a first server for receiving queries from plural users, wherein the first server logs first audit information in a first log, and wherein the first audit information comprises a first set of parameters for respective reports logged in the first log,

a database system for storing a database, and

a monitoring system for auditing the queries transmitted between said first server and the database system, wherein the monitoring system is arranged to capture second audit information into a second log obtained from a communications channel between the first server and the database system, and wherein the second audit information comprises a second set of parameters for respective reports stored in the second log,

the first server being configured to correlate the first audit information with the second audit information using a parameter in common among the first and second sets of parameters in order to ascertain a particular one of the reports having the parameter in common among the first and second sets of parameters, wherein said correlating step includes matching a time of transaction recorded in said first log with a time of transaction recorded in said second log.

13. The system of claim 12 wherein said queries are SQL queries.

Assignments (3)
SECURITY INTEREST Recorded Mar 12, 2014
From: TELERAN TECHNOLOGIES, INC.
To: TRAVNET, LLC, AS REPRESENTATIVE FOR ITSELF AND THE HOLDERS OF CERTAIN PROMISSORY NOTES
Reel/Frame 032416/0589 →
CORRECTIVE ASSIGNMENT TO CORRECT THE INCORRECT SERIAL NUMBER 12/022,699, PREVIOUSLY RECORDED ON REEL 026095 FRAME 0411. ASSIGNOR(S) HERBY CONFIRMS THE ASSIGNMENT. Recorded Dec 14, 2011
From: KARCH, ROBERT
To: TELERAN TECHNOLOGIES, INC.
Reel/Frame 027504/0848 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 8, 2011
From: KARCH, ROBERT
To: TELERAN TECHNOLOGIES, INC.
Reel/Frame 026095/0411 →
Continuity (2)
Continuation 10919643 · Aug 17, 2004
Related Publication 20110276587A1 · Nov 10, 2011