IP Library Granted Patent US 7,032,026
Granted Patent B1
US 7,032,026 · App. 10/043,800 · Granted Apr 18, 2006

Method and apparatus to facilitate individual and global lockouts to network applications

Assignee: Oracle International Corp.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,032,026
App. No.
10/043,800
Granted
Apr 18, 2006
Kind
B1
Abstract

One embodiment of the present invention provides a system that facilitates locking an adversary out of a network application. The system operates by receiving a request at a server, which includes an authentication credential, to access the network application. This authentication credential includes a user identifier associated with a user and an address of a user device. The system examines an audit log to determine if the user identifier has been locked out from the address of the user device. If so, the system denies access to the network application. Otherwise, the system checks the authentication credential for validity. If the authentication credential is valid, the system allows access to the network application. Otherwise, the system logs a failed attempt in the audit log and denies access to the network application. After a threshold number of failed attempts, the user identifier is locked out from the network address.

Claims (42)

1. A method to facilitate locking an adversary out of a network application, comprising:

receiving at a server a request, including an authentication credential, to access the network application, wherein the authentication credential includes a user identifier and a specific network address of a user device;

if the user identifier has been locked out from the specific network address,

denying access to the network application; and

if the authentication credential is valid, allowing access to the network application, otherwise,

logging a failed attempt in the audit log,

imposing a lockout for the user identifier from only the specific network address after a threshold number of failed attempts from the specific network address,

if a threshold number of specific network addresses are locked out for the user identifier, imposing a global lockout for the user identifier, and

denying access to the network application.

2. The method of claim 1 , further comprising: removing a lockout after a predetermined period of time.

3. The method of claim 1 , further comprising: manually removing a lockout by an administrator of the server.

4. The method of claim 1 , wherein the authentication credential includes a user name and a password.

5. The method of claim 4 , wherein checking the authentication credential for validity involves:

verifying that an administrator has authorized access to the network application for a combination of the user name and the password; and

determining if the request violates an access rule in a rule table.

6. The method of claim 5 , wherein the access rule can specify:

an allowed time-of-day;

an allowed number of access attempts;

an allowed network address; and

an allowed network domain.

7. The method of claim 1 , wherein the network address includes an Internet Protocol address.

8. A computer-readable storage medium storing instructions that when executed by a computer cause the computer to perform a method to facilitate locking an adversary out of a network application, the method comprising:

receiving at a server a request, including an authentication credential, to access the network application, wherein the authentication credential includes a user identifier and a specific network address of a user device;

if the user identifier has been locked out from the specific network address,

denying access to the network application; and

if the authentication credential is valid, allowing access to the network application, otherwise,

logging a failed attempt in the audit log,

imposing a lockout for the user identifier from only the specific network address after a threshold number of failed attempts from the specific network address,

if a threshold number of network addresses are locked out for the user identifier, imposing a global lockout for the user identifier, and

denying access to the network application.

9. The computer-readable storage medium of claim 8 , the method further comprising: removing a lockout after a predetermined period of time.

10. The computer-readable storage medium of claim 8 , the method further comprising: manually removing a lockout by an administrator of the server.

11. The computer-readable storage medium of claim 8 , wherein the authentication credential includes a user name and a password.

12. The computer-readable storage medium of claim 11 , wherein checking the authentication credential for validity involves:

verifying that an administrator has authorized access to the network application for a combination of the user name and the password; and

determining if the request violates an access rule in a rule table.

13. The computer-readable storage medium of claim 12 , wherein the access rule can specify:

an allowed time-of-day;

an allowed number of access attempts;

an allowed network address; and

an allowed network domain.

14. The computer-readable storage medium of claim 8 , wherein the network address includes an Internet Protocol address.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2003
From: ORACLE CORPORATION
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 013737/0276 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2002
From: BISWAS, KAMALENDU; SWAMINATHAN, ARUN; BHATIA, GAURAV
To: ORACLE CORPORATION
Reel/Frame 012490/0393 →
Continuity (1)
Provisional Application 6031680800 · Aug 31, 2001