Systems and methods to protect shared privileged remote access (PRA) sessions based on user risk
Systems and methods to protect shared Privileged Remote Access (PRA) sessions based on user risk include receiving, at a Privileged Remote Access (PRA) system, one or more invitations from a host, the one or more invitations being for one or more users to join a PRA session; responsive to receiving the one or more invitations, determining a risk score of each of the one or more users associated with the one or more invitations; and rejecting or allowing each of the one or more invitations based on the risk score of each of the one or more users.
1 . A method comprising steps of:
receiving, at a Privileged Remote Access (PRA) system, one or more invitations from a host, the one or more invitations being for one or more users to join a PRA session;
responsive to receiving the one or more invitations, determining a risk score of each of the one or more users associated with the one or more invitations; and
rejecting or allowing each of the one or more invitations based on the risk score of each of the one or more users,
wherein, responsive to allowing an invitation of the one or more invitations, the PRA system creates the PRA session and brokers, via a service edge acting as a broker, a connection between a user device of the allowed user and an application through a lightweight connector that establishes an inside-out outbound connection to the service edge without accepting inbound connections,
wherein the PRA system enforces, for the PRA session, a security and access policy that includes selectively blocking commands from the user device from reaching the application to provide read-only access based on the risk score;
responsive to allowing one or more invitations, creating a PRA session, and brokering a connection between one or more users associated with the one or more allowed invitations and an application through a lightweight connector, and enabling the one or more users to send commands to the application;
continuously monitoring risk scores of the one or more users during the PRA session, including receiving, at an exporter associated with the PRA system, an asynchronous notification responsive to an updated risk score stored in a user risk database, and automatically updating a security and access policy applied to the PRA session based on the updated risk score; and
responsive to detecting an updated risk score for a user of the one or more users, enforcing read-only policy on the user during the PRA session,
wherein enforcing the read-only policy comprises, at an exporter handling the PRA session, blocking relaying of session instructions from the user device to a protocol daemon associated with the lightweight connector such that the protocol daemon does not receive the user's commands, while continuing to transmit pixels associated with the PRA session to the user device.
2 . The method of claim 1 , wherein the determining includes referencing the user risk database for determining a risk score of each of the one or more users associated with the one or more invitations.
3 . The method of claim 1 , wherein the rejecting or allowing is based on the risk score of each of the one or more users being below or above a threshold.
4 . The method of claim 1 , wherein the steps comprise:
(i) rejecting an invitation of the one or more invitations based on a user associated with the invitation being in a high-risk category based on their risk score, (ii) allowing an invitation of the one or more invitations based on a user associated with the invitation being in a low-risk category based on their risk score, and (iii) allowing an invitation of the one or more invitations with read-only access based on a user associated with the invitation being in a medium-risk category based on their risk score.
5 . The method of claim 1 , wherein the steps further comprise:
enforcing read-only policy on any of the one or more users during the PRA session based on the risk score of each of the one or more users.
6 . The method of claim 1 , wherein the steps further comprise:
responsive to detecting an updated risk score for a user of the one or more users, kicking the user from the PRA session.
7 . The method of claim 1 , wherein the steps further comprise:
responsive to detecting an updated risk score for a user of the one or more users, notifying the host of the updated risk score.
8 . A non-transitory computer-readable medium comprising instructions, wherein the instructions are executable by a cloud-based system to perform steps of:
receiving, at a Privileged Remote Access (PRA) system, one or more invitations from a host, the one or more invitations being for one or more users to join a PRA session;
responsive to receiving the one or more invitations, determining a risk score of each of the one or more users associated with the one or more invitations; and
rejecting or allowing each of the one or more invitations based on the risk score of each of the one or more users,
wherein, responsive to allowing an invitation of the one or more invitations, the PRA system creates the PRA session and brokers, via a service edge acting as a broker, a connection between a user device of the allowed user and an application through a lightweight connector that establishes an inside-out outbound connection to the service edge without accepting inbound connections,
wherein the PRA system enforces, for the PRA session, a security and access policy that includes selectively blocking commands from the user device from reaching the application to provide read-only access based on the risk score;
responsive to allowing one or more invitations, creating a PRA session, and brokering a connection between one or more users associated with the one or more allowed invitations and an application through a lightweight connector, and enabling the one or more users to send commands to the application;
continuously monitoring risk scores of the one or more users during the PRA session, including receiving, at an exporter associated with the PRA system, an asynchronous notification responsive to an updated risk score stored in a user risk database, and automatically updating a security and access policy applied to the PRA session based on the updated risk score; and
responsive to detecting an updated risk score for a user of the one or more users, enforcing read-only policy on the user during the PRA session,
wherein enforcing the read-only policy comprises, at an exporter handling the PRA session, blocking relaying of session instructions from the user device to a protocol daemon associated with the lightweight connector such that the protocol daemon does not receive the user's commands, while continuing to transmit pixels associated with the PRA session to the user device.
9 . The non-transitory computer-readable medium of claim 8 , wherein the determining includes referencing the user risk database for determining a risk score of each of the one or more users associated with the one or more invitations.
10 . The non-transitory computer-readable medium of claim 8 , wherein the rejecting or allowing is based on the risk score of each of the one or more users being below or above a threshold.
11 . The non-transitory computer-readable medium of claim 8 , wherein the steps comprise:
(i) rejecting an invitation of the one or more invitations based on a user associated with the invitation being in a high-risk category based on their risk score, (ii) allowing an invitation of the one or more invitations based on a user associated with the invitation being in a low-risk category based on their risk score, and (iii) allowing an invitation of the one or more invitations with read-only access based on a user associated with the invitation being in a medium-risk category based on their risk score.
12 . The non-transitory computer-readable medium of claim 8 , wherein the steps further comprise:
enforcing read-only policy on any of the one or more users during the PRA session based on the risk score of each of the one or more users.
13 . The non-transitory computer-readable medium of claim 8 , wherein the steps further comprise:
responsive to detecting an updated risk score for a user of the one or more users, kicking the user from the PRA session.
14 . The non-transitory computer-readable medium of claim 8 , wherein the steps further comprise:
responsive to detecting an updated risk score for a user of the one or more users, notifying the host of the updated risk score.