IP Library Granted Patent US 8,590,014
Granted Patent B1
US 8,590,014 · App. 12/880,723 · Granted Nov 19, 2013

Network application security utilizing network-provided identities

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,590,014
App. No.
12/880,723
Granted
Nov 19, 2013
Kind
B1
Abstract

A network security system that correlates security-related events to individual users, as identified by a user identifier and an identity provider. The user identifier may be associated in one or more implicit or explicit social networks.

Claims (36)

1. An apparatus, comprising:

a network interface;

a memory;

one or more processors; and

computer program code for execution by the one or more processors and stored in a non-transitory, computer-readable medium, the computer program code comprising:

a network application module comprising instructions operative, when executed, to cause the one or more processors to deliver network application services to one or more users, the one or more users each identified by a user identifier corresponding to a social network;

a user authentication module comprising instructions operative, when executed, to cause the one or more processors to authenticate users of the social network; and

a security layer module operative to monitor messages transmitted between remote hosts associated with the one or more users and the network application module and transmit security-related event data to a host executing a security application, wherein the security layer comprises a memory-I/O handler operative to intercept input and output of the network application module.

2. The apparatus of claim 1 wherein the security layer comprises a plug-in manager operative to copy and poll traffic of the network application module using one or more security plug-in modules.

3. The apparatus of claim 2 wherein the plug-in manager is further operative to allow: real time modification of memory input or output data of the network application module through the memory-I/O handler.

4. The apparatus of claim 2 wherein the security layer comprises a backend reporting module operative to transmit security-related event data created by the one or more security plug-in modules to a host executing a security application.

5. The apparatus of claim 4 wherein the backend reporting module is operative to encode and digitally sign the security-related event data.

6. The apparatus of claim 4 wherein the backend reporting module is operative to encrypt the security-related event data.

7. The apparatus of claim 1 wherein the security layer comprises a backend observation module operative to synchronize security configuration data for one or more of a user and an IP address with a security database.

8. The apparatus of claim 1 wherein the user authentication module is operative to authenticate a user by interacting with an identity provider system using an open authentication protocol.

9. An apparatus, comprising:

a network interface;

a memory;

one or more processors; and

computer program code for execution by the one or more processors and stored in a non-transitory, computer-readable medium, the computer program code comprising:

a network application module comprising instructions operative, when executed, to cause the one or more processors to deliver network application services to one or more users, the one or more users each identified by a user identifier corresponding to a social network;

a user authentication module comprising instructions operative, when executed, to cause the one or more processors to authenticate users of the social network;

a security layer module operative to monitor messages transmitted between remote hosts associated with the one or more users and the network application module and transmit security-related event data to a host executing a security application, and

a security application operative to correlate security related event data of a first user with security related event data of a second user based on connections between the first user and the second user in a social graph.

10. A method comprising:

delivering network application services to one or more users, the one or more users each identified by a user identifier corresponding to a social network;

authenticating users of the social network;

monitoring messages transmitted between remote hosts associated with the one or more users and the network application module; and

transmitting security-related event data to a host executing a security application, further comprising intercepting, at a memory-I/O handler, input and output of the network application module.

11. The method of claim 10 further comprising copying and polling, using a plug-in manager, traffic of the network application module in connection with one or more security plug-in modules.

12. The method of claim 11 wherein the plug-in manager is further operative to allow real time modification of memory input or output data of the network application module through the memory-I/O handler.

13. The method of claim 11 further comprising transmitting, using a backend reporting module, security-related event data created by the one or more security plug-in modules to a host executing a security application.

14. The method of claim 13 wherein the backend reporting module is operative to encode and digitally sign the security-related event data.

15. The method of claim 13 wherein the backend reporting module is operative to encrypt the security-related event data.

16. The method of claim 10 further comprising synchronizing, using a backend observation module, security configuration data for one or more of a user and an IP address with a security database.

17. The method of claim 10 wherein the user authentication module is operative to authenticate a user by interacting with an identity provider system using an open authentication protocol.

Assignments (4)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded May 23, 2022
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: ZYNGA INC.
Reel/Frame 060163/0437 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Dec 14, 2020
From: ZYNGA INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 054719/0490 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 11, 2020
From: BANK OF AMERICA, N.A., AS LENDER
To: ZYNGA INC.
Reel/Frame 054701/0393 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Dec 21, 2018
From: ZYNGA INC.
To: BANK OF AMERICA, N.A., AS LENDER
Reel/Frame 049147/0546 →