IP Library Granted Patent US 9,225,723
Granted Patent B2
US 9,225,723 · App. 14/327,087 · Granted Dec 29, 2015

Systems and methods for automatic discovery of systems and accounts

Inventors: Gyle Iverson (Woodland Hills, CA); Jeffery Nielsen (Simi Valley, CA); Julie Lustig-Rusch (West Hills, CA); James Mitchell (Moorpark, CA)
Assignee: BeyondTrust Software, Inc.
H04L63/10H04L63/083H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,225,723
App. No.
14/327,087
Granted
Dec 29, 2015
Kind
B2
Abstract

In various embodiments, a method comprises scanning a directory structure to generate a scan result comprising a plurality of discovered systems, identifying one or more accounts associated with at least one of the plurality of discovered systems, configuring a security appliance to change one or more old passwords to one or more new passwords for the one or more accounts, and changing, with the configured security appliance, the one or more old passwords to the one or more new passwords.

Claims (45)

1. A method, comprising:

receiving during a registration process a registration request at a security appliance separate from a client device, the registration request being for a seeking application at the client device to access a secured application or secured database separate from the security appliance;

receiving, by the security appliance, a first program factor associated with the seeking application as part of the registration request;

confirming, by the security appliance, the first program factor to assist in confirming authorization of the seeking application to access the secured application or secured database;

receiving, by the security appliance, an access request after the registration process from the seeking application;

obtaining, by the security appliance, a program factor instance for the seeking application;

evaluating, by the security appliance, the program factor instance relative to the first program factor to assist in confirming authorization of the seeking application to access the secured application or secured database; and

altering a user right associated with a user account having access to the secured application or secured database when the authorization of the seeking application to access the secured application or secured database is confirmed, the access by the user account being based at least in part on the user right, and the altering being based at least in part on the registration request.

2. The method of claim 1 , wherein the first program factor is selected from a group consisting of a program name, a program version, a program executable hash, a dependent DLL name, shared library names, a dependent DLL version, shared library versions, environmental factors, and debugging identification.

3. The method of claim 1 , wherein the first program factor is selected from a group consisting of a system name, a fully qualified domain name (FQDN), a domain name, an IP address, a MAC address, a user name, a user ID, a CPU ID, a CPU serial number, a root disk volume ID, an OS version, and an OS type.

4. The method of claim 1 , further comprising confirming a second program factor associated with the seeking application.

5. The method of claim 4 , wherein the altering the user right is based, at least, on the confirmation of the first program factor and the confirmation of the second program factor.

6. The method of claim 1 , wherein the user right is further associated with a file, volume, or device.

7. The method of claim 1 , wherein the user right determines whether a user can view, access, make a change to, or share the secured application or secured database.

8. A system, comprising:

memory;

a hardware processor; and

a security registration module configured by the hardware processor to:

receive during a registration process a registration request at a security appliance separate from a client device, the registration request being for a seeking application at the client device to access a secured application or secured database separate from the security appliance;

receive a first program factor associated with the seeking application as part of the registration request;

confirm the first program factor to assist in confirming authorization of the seeking application to access the secured application or secured database;

receive an access request after the registration process from the seeking application;

obtain a program factor instance for the seeking application;

evaluate the program factor instance relative to the first program factor to assist in confirming authorization of the seeking application to access the secured application or secured database; and

alter a user right associated with a user account having access to the secured application or secured database when the authorization of the seeking application to access the secured application or secured database is confirmed, the access by the user account being based at least in part on the user right, and the altering being based at least in part on the registration request.

9. The system of claim 8 , wherein the first program factor is selected from a group consisting of a program name, a program version, a program executable hash, a dependent DLL name, shared library names, a dependent DLL version, shared library versions, environmental factors, and debugging identification.

10. The system of claim 8 , wherein the first program factor is selected from a group consisting of a system name, a fully qualified domain name (FQDN), a domain name, an IP address, a MAC address, a user name, a user ID, a CPU ID, a CPU serial number, a root disk volume ID, an OS version, and an OS type.

11. The system of claim 8 , wherein the security registration module is further configured by the processor to confirm a second program factor associated with the seeking application.

12. The system of claim 11 , wherein the altering the user right is based, at least, on the confirmation of the first program factor and the confirmation of the second program factor.

13. The system of claim 8 , wherein the user right is further associated with a file, volume, or device.

14. The system of claim 8 , wherein the user right determines whether a user can view, access, make a change to, or share the secured application or secured database.

15. A non-transitory computer readable medium comprising executable instructions, the instructions being executable by a processor to perform a method, the method comprising:

receiving during a registration process a registration request at a security appliance separate from a client device, the registration request being for a seeking application at the client device to access a secured application or secured database separate from the security appliance;

receiving, by the security appliance, a first program factor associated with the seeking application as part of the registration request;

confirming, by the security appliance, the first program factor to assist in confirming authorization of the seeking application to access the secured application or secured database;

receiving, by the security appliance, an access request after the registration process from the seeking application;

obtaining, by the security appliance, a program factor instance for the seeking application;

evaluating, by the security appliance, the program factor instance relative to the first program factor to assist in confirming authorization of the seeking application to access the secured application or secured database; and

altering a user right associated with a user account having access to the secured application or secured database when the authorization of the seeking application to access the secured application or secured database is confirmed, the access by the user account being based at least in part on the user right, and the altering being based at least in part on the registration request.

16. The non-transitory computer readable medium of claim 15 , wherein the first program factor is selected from a group consisting of a program name, a program version, a program executable hash, a dependent DLL name, shared library names, a dependent DLL version, shared library versions, environmental factors, and debugging identification.

17. The non-transitory computer readable medium of claim 15 , wherein the first program factor is selected from a group consisting of a system name, a fully qualified domain name (FQDN), a domain name, an IP address, a MAC address, a user name, a user ID, a CPU ID, a CPU serial number, a root disk volume ID, an OS version, and an OS type.

18. The non-transitory computer readable medium of claim 15 , the method further comprising confirming a second program factor associated with the seeking application.

19. The non-transitory computer readable medium of claim 18 , wherein the altering the user right is based, at least, on the confirmation of the first program factor and the confirmation of the second program factor.

20. The non-transitory computer readable medium of claim 15 , wherein the user right is further associated with a file, volume, or device.

21. The non-transitory computer readable medium of claim 15 , wherein the user right determines whether a user can view, access, make a change to, or share the secured application or secured database.

Assignments (13)
MERGER Recorded Dec 5, 2023
From: BEYONDTRUST SOFTWARE, INC.
To: BEYONDTRUST CORPORATION
Reel/Frame 065764/0741 →
RELEASE OF SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 28, 2023
From: JEFFERIES FINANCE LLC,
To: BEYONDTRUST SOFTWARE, INC.
Reel/Frame 065697/0345 →
RELEASE OF FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 28, 2023
From: JEFFERIES FINANCE LLC
To: BEYONDTRUST SOFTWARE, INC.
Reel/Frame 065696/0798 →
SECURITY INTEREST Recorded Nov 28, 2023
From: BEYONDTRUST CORPORATION
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 065682/0447 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 4, 2018
From: BEYONDTRUST SOFTWARE, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 047195/0252 →
RELEASE OF SECURITY INTEREST UNDER REEL/FRAME NO. 044496/0009 Recorded Oct 3, 2018
From: ARES CAPITAL CORPORATION
To: BEYONDTRUST SOFTWARE, INC.
Reel/Frame 047189/0516 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 3, 2018
From: BEYONDTRUST SOFTWARE, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 047190/0238 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 033824/0803 Recorded Nov 21, 2017
From: OAKTREE FUND ADMINISTRATION, LLC (AS SUCCESSOR TO FIFTH STREET MANAGEMENT LLC)
To: BEYONDTRUST, INC.
Reel/Frame 044495/0927 →
PATENT SECURITY AGREEMENT Recorded Nov 21, 2017
From: BEYONDTRUST SOFTWARE, INC.
To: ARES CAPITAL CORPORATION
Reel/Frame 044496/0009 →
ASSIGNMENT OF PATENT SECURITY AGREEMENT Recorded Oct 20, 2017
From: FIFTH STREET MANAGEMENT LLC
To: OAKTREE FUND ADMINISTRATION, LLC
Reel/Frame 044242/0538 →
PATENT SECURITY AGREEMENT Recorded Sep 25, 2014
From: BEYONDTRUST, INC.
To: FIFTH STREET MANAGEMENT LLC
Reel/Frame 033824/0803 →
TO CORRECT AN ERROR IN A COVER SHEET PREVIOUSLY RECORDED AT 033548/0760, WHICH SUBMITTED AN ASSIGNMENT, THE ASSIGNEE'S NAME WAS MISSPELLED AS "BEYONTTRUST" AND SHOULD HAVE BEEN "BEYONDTRUST", AS SHOWN IN ASSIGNMENT DOCUMENT. Recorded Aug 19, 2014
From: IVERSON, GYLE; NIELSEN, JEFFERY; LUSTIG-RUSCH, JULIE; MITCHELL, JAMES
To: BEYONDTRUST SOFTWARE, INC.
Reel/Frame 033568/0580 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2014
From: IVERSON, GYLE; NIELSEN, JEFFERY; LUSTIG-RUSCH, JULIE; MITCHELL, JAMES
To: BEYONTTRUST SOFTWARE, INC.
Reel/Frame 033548/0760 →
Continuity (4)
Continuation 12571231 · Sep 30, 2009
Continuation In Part 12497429 · Jul 2, 2009
Provisional Application 61219359 · Jun 22, 2009
Related Publication 20140325611A1 · Oct 30, 2014