IP Library Granted Patent US 9,571,516
Granted Patent B1
US 9,571,516 · App. 14/536,455 · Granted Feb 14, 2017

Cloud service usage monitoring system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,571,516
App. No.
14/536,455
Granted
Feb 14, 2017
Kind
B1
Abstract

A cloud service usage assessment system analyzes network traffic from an enterprise data network and generates cloud service usage analytics for the enterprise. In some embodiments, the cloud service usage analytics may include cloud service usage risk assessment. The cloud service usage assessment system is advantageous applied to assess network security in view of an enterprise's adoption of multiple cloud based services.

Claims (53)

1. A method of assessing a cloud service usage level of an enterprise operating an enterprise data network, the method comprising:

receiving, at an on-premises processor configured within the enterprise data network, network event logs associated with network traffic traveling to and from the enterprise data network, the network event logs comprising network event data describing network events traveling to and from the enterprise data network, the network event data comprising a source indicator, a destination indicator, a time of the network event, and a request parameter;

processing, at the on-premises processor, the network event logs to generate processed network event data containing network event data related to cloud service usage;

transmitting the processed network event data to an off-premises usage analysis system configured outside of the enterprise data network;

assessing, using the off-premises usage analysis system, cloud service usage behavior and pattern of the enterprise based on the processed network event data; and

generating, using the off-premises usage analysis system, a cloud service usage analytic based on the cloud service usage behavior and pattern of the enterprise, the cloud service usage analytic describing the use of cloud-based services from one or more cloud service providers by the enterprise,

wherein processing, at the on-premises processor, the network event logs to generate processed network event data containing network event data related to cloud service usage comprises:

analyzing the network event logs to identify network events related to the use of cloud-based services;

filtering the network event logs to include only network event data relating to the use of cloud-based services;

tokenizing the filtered network event data to remove identifying information relating to the enterprise or to users of the enterprise and to replace the identifying information with random identifiers;

applying a compression algorithm to the tokenized and filtered network event data; and

providing the compressed, tokenized and filtered network event data as the processed network even data.

2. The method of claim 1 , wherein tokenizing the filtered network event data to remove identifying information relating to the enterprise or to users of the enterprise further comprises:

generating an anonymity file comprising a mapping of each identifying information and corresponding random identifier.

3. The method of claim 2 , further comprising:

displaying the cloud service usage analytic on a web browser, the cloud service usage analytic including tokenized data;

receiving the anonymity file and storing the anonymity file in a web storage of the web browser; and

displaying the identifying information in place of the corresponding random identifier using the mapping in the anonymity file.

4. The method of claim 1 , wherein generating, using the off-premises usage analysis system, a cloud service usage analytic comprises:

generating one or more cloud service usage analytics including identification of cloud service providers being used, identities of users using each of the identified cloud service providers, times of usage, the volume of transactions, and the service category of the cloud service providers.

5. The method of claim 1 , wherein generating, using the off-premises usage analysis system, a cloud service usage analytic comprises:

generating one or more cloud service usage analytics including a detected number of cloud service providers being used, a detected number of high risk service providers being used, a detected number of users or unique IP addresses using each cloud service, and a detected volume of high risk activities that users of the enterprise engaged in.

6. The method of claim 1 , wherein assessing cloud service usage behavior and pattern of the enterprise based on the processed network event data and generating the cloud service usage analytic based on the cloud service usage behavior and pattern of the enterprise comprises:

correlating the processed network event data to unique users as identified by the random identifiers;

correlating, using data from a cloud service registry, the processed network event data to one or more cloud service providers;

analyzing the processed network event data to detect anomaly in the network event data; and

generating one or more cloud service usage analytic based the correlated user data and detected anomaly.

7. The method of claim 6 , wherein analyzing the processed network event data to detect anomaly in the network event data comprises:

analyzing the processed network event data to detect for unusual activities of a user, or a certain usage pattern, or a large amount of data download by a user of the enterprise.

8. A system for assessing a cloud service usage level of an enterprise operating an enterprise data network, the system comprising:

a log processor deployed within the enterprise data network to receive network event logs associated with network traffic traveling to and from the enterprise data network and to process the network event logs to generate processed network event data containing network event data related to cloud service usage, the network event logs comprising network event data describing network events traveling to and from the enterprise data network, the network event data comprising a source indicator, a destination indicator, a time of the network event, and a request parameter; and

a usage analysis system deployed outside of the enterprise data network to receive the processed network event data from the log processor, the usage analysis system being configured to assess cloud service usage behavior and pattern of the enterprise based on the processed network event data and to generate a cloud service usage analytic based on the cloud service usage behavior and pattern of the enterprise, the cloud service usage analytic describing the use of cloud-based services from one or more cloud service providers by the enterprise;

wherein the log processor is configured to analyze the network event logs to identify network events related to the use of cloud-based services, to filter the network event logs to include only network event data relating to the use of cloud-based services, to tokenize the filtered network event data to remove identifying information relating to the enterprise or to users of the enterprise and to replace the identifying information with random identifiers, to apply a compression algorithm to the tokenized and filtered network event data, and to provide the compressed, tokenized and filtered network event data as the processed network even data.

9. The system of claim 8 , wherein the log processor is configured to generate an anonymity file comprising a mapping of each identifying information and corresponding random identifier.

10. The system of claim 8 , wherein the usage analysis system is configured to generate one or more cloud service usage analytics including identification of cloud service providers being used, identities of users using each of the identified cloud service providers, times of usage, the volume of transactions, and the service category of the cloud service providers.

11. The system of claim 8 , wherein the usage analysis system is configured to generate one or more cloud service usage analytics including a detected number of cloud service providers being used, a detected number of high risk service providers being used, a detected number of users or unique IP addresses using each cloud service, and a detected volume of high risk activities that users of the enterprise engaged in.

12. The system of claim 8 , wherein the usage analysis system is configured to correlate the processed network event data to unique users as identified by the random identifiers, to correlating, using data from a cloud service registry, the processed network event data to one or more cloud service providers, to analyze the processed network event data to detect anomaly in the network event data, and to generate one or more cloud service usage analytic based the correlated user data and detected anomaly.

13. The system of claim 12 , wherein the usage analysis system is further configured to analyze the processed network event data to detect for unusual activities of a user, or a certain usage pattern, or a large amount of data download by a user of the enterprise.

14. A method of identifying cloud service providers from the network traffic of an enterprise operating an enterprise data network, the method comprising:

receiving, at an on-premises processor configured within the enterprise data network, network event logs associated with network traffic traveling to and from the enterprise data network;

processing, at the on-premises processor and using data from a cloud service registry, the network event logs to generate processed network event data containing network event data related to cloud service usage;

obtaining, using the on-premises processor and from the network event logs, destination IP addresses of network events destined to one or more known cloud service providers;

determining, using the on-premises processor, whether a network event uses a secure socket layer protocol;

in response to a network event using a secure socket layer protocol, collecting, using the on-premises processor, the destination IP addresses into a queue;

scanning, using the on-premises processor, the destination IP addresses in the queue to identify the cloud service provider to which the destination IP address is destined;

classifying, using the on-premises processor, each destination IP address in the queue as a public website, an existing cloud service provider, a tenant specific cloud service, an unknown website and an unable to connect;

in response to a destination IP address in the queue being classified as a public website, storing, using the on-premises processor, the destination IP address in an exclude list in the cloud service registry, the network event associated with the destination IP address being excluded from the processed network event data;

in response to a destination IP address in the queue being classified as an existing cloud service provider, storing, using the on-premises processor, the destination IP address in the cloud service registry associated with the existing cloud service provider; and

in response to a destination IP address in the queue being classified as a tenant specific cloud service, storing, using the on-premises processor, the destination IP address in the cloud service registry associated with the tenant cloud service provider.

15. The method of claim 14 , wherein scanning, using the on-premises processor, the destination IP addresses in the queue to identify the cloud service provider to which the destination IP address is destined comprises:

scanning, using the on-premises processor, a certificate associated with each of the destination IP addresses to identify the cloud service provider from a common name field in the certificate.

16. The method of claim 14 , wherein scanning, using the on-premises processor, the destination IP addresses in the queue to identify the cloud service provider to which the destination IP address is destined comprises:

for each destination IP address, discovering, using a secure socket layer protocol handshake, a common name and domain of the cloud service provider associated with the destination IP address.

Assignments (16)
ASSIGNMENT OF INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 14, 2025
From: UBS AG, STAMFORD BRANCH
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 070840/0598 →
INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 24, 2025
From: SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 070618/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SKYHIGH SECURITY LLC
Reel/Frame 069272/0570 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CHANGE OF NAME Recorded May 9, 2022
From: SKYHIGH NETWORKS, LLC
To: SKYHIGH SECURITY LLC
Reel/Frame 059912/0601 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 046416/0286 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: SKYHIGH NETWORKS, LLC
Reel/Frame 054211/0739 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA PREVIOUSLY RECORDED AT REEL: 046416 FRAME: 0286. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 19, 2020
From: SKYHIGH NETWORKS, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 054560/0325 →
CHANGE OF NAME Recorded Dec 27, 2018
From: SKYHIGH NETWORKS, INC.
To: SKYHIGH NETWORKS, LLC
Reel/Frame 047985/0861 →
SECURITY INTEREST Recorded Jul 20, 2018
From: SKYHIGH NETWORKS, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 046416/0225 →
SECURITY INTEREST Recorded Jul 20, 2018
From: SKYHIGH NETWORKS, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 046416/0286 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2015
From: CURCIC, DEJAN; SARUKKAI, SEKHAR; NARAYAN, KAUSHIK; GUPTA, RAJIV; TARANIGANTY, RAMA; MULVANEY, GLENN
To: SKYHIGH NETWORKS, INC.
Reel/Frame 034685/0456 →