IP Library Granted Patent US 9,596,249
Granted Patent B2
US 9,596,249 · App. 14/694,647 · Granted Mar 14, 2017

Detecting shared or compromised credentials through analysis of simultaneous actions

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,596,249
App. No.
14/694,647
Granted
Mar 14, 2017
Kind
B2
Abstract

A privileged account management system can detect when credentials used to access one or more servers have been shared or otherwise compromised. This detection can occur through analysis of simultaneous actions that are performed via multiple sessions associated with the same administrator. When two or more sessions associated with the same administrator are opened, the interactions performed over each of the sessions can be monitored to identify whether such interactions could be performed by a single administrator. If it is determined that the interactions over the multiple sessions could not reasonably be performed by a single administrator, various actions can be taken to address the possible breach to the security of the one or more servers.

Claims (52)

1. A method, implemented by a privileged account management system, for detecting when multiple individuals are likely interacting with multiple privileged sessions that are associated with a single administrator, the method comprising:

monitoring multiple privileged sessions that are each associated with a single administrator, each of the multiple privileged sessions being concurrently established using the same admin credentials, the multiple privileged sessions including a first privileged session that is established with a first client device and a second privileged session that is established with a second client device;

while monitoring the multiple privileged sessions, detecting that first data is transmitted over the first privileged session at a first time and that second data is transmitted over the second privileged session at a second time;

comparing the first time to the second time to determine that the second time is within a threshold of the first time;

analyzing the first data and the second data to determine that the first data represents first user input to the first client device and that the second data represents second user input to the second client device;

based on the comparison and the analysis, determining that it is unlikely that the single administrator provided the first user input and the second user input; and

in response to determining that it is unlikely that the single administrator provided the first user input and the second user input, causing an action to be performed to mitigate risk to one or more servers accessible via one or both of the first and second privileged sessions.

2. The method of claim 1 , wherein one or both of the first and second privileged sessions comprises a remote session between the client device and a component of the privileged account management system and a remote session between the component and one of the one or more servers.

3. The method of claim 2 , wherein the component is a proxy.

4. The method of claim 2 , wherein the component is a hosted session component.

5. The method of claim 1 , wherein one or both of the first and second privileged sessions comprises a remote session between the client device and an agent component of the privileged account management system that resides on one of the one or more servers.

6. The method of claim 1 , wherein detecting that first data is transmitted over the first privileged session at a first time and that second data is transmitted over the second privileged session at a second time comprises:

identifying that the first data is received by the privileged account management system at the first time and that the second data is received by the privileged account managements system at the second time.

7. The method of claim 1 , wherein the threshold is based on a latency of the privileged sessions.

8. The method of claim 1 , wherein the first data and the second data each represent human interaction with a human input device.

9. The method of claim 8 , wherein determining that it is unlikely that the single administrator provided the first user input and the second user input comprises:

determining that the first data and the second data both represent one of keyboard input or mouse input.

10. The method of claim 8 , wherein determining that it is unlikely that the single administrator provided the first user input and the second user input comprises:

determining that the first data represents keyboard input and the second data represents mouse input.

11. The method of claim 1 , wherein analyzing the first data and the second data to determine that the first data represents first user input to the first client device and that the second data represents second user input to the second client device further comprises:

comparing the second data to the first data to determine whether both the first data and the second data represent a same sequence of commands that are likely generated using automation technology.

12. The method of claim 1 , wherein determining that it is unlikely that the single administrator provided the first user input and the second user input comprises:

determining that a single individual is not capable of providing the first user input and the second user input simultaneously.

13. The method of claim 1 , wherein the action comprises one or more of:

closing one or both of the first and second privileged sessions;

recording one or both of the first and second privileged sessions;

alerting a security officer; or

flagging data associated with one or both of the first and second privileged sessions.

14. The method of claim 1 , wherein the first and second privileged sessions each comprise one of an SSH session or an RDP session.

15. One or more computer storage media storing computer executable instructions which when executed by one or more processors of a privileged account management system implement a method for detecting when multiple individuals are likely interacting with multiple privileged sessions that are associated with a single administrator, the method comprising:

monitoring multiple privileged sessions that are each associated with a single administrator, each of the multiple privileged sessions being concurrently established using the same admin credentials, the multiple privileged sessions including a first privileged session that is established with a first client device and a second privileged session that is established with a second client device;

while monitoring the multiple privileged sessions, detecting that first data is transmitted over the first privileged session at a first time and that second data is transmitted over the second privileged session at a second time;

comparing the first time to the second time to determine that the second time is within a threshold of the first time;

analyzing the first data and the second data to determine that the first data represents first user input to the first client device and that the second data represents second user input to the second client device;

based on the comparison and the analysis, determining that it is unlikely that the single administrator provided the first user input and the second user input; and

in response to determining that it is unlikely that the single administrator provided the first user input and the second user input, causing an action to be performed to mitigate risk to one or more servers accessible via one or both of the first and second privileged sessions.

16. A privileged account management system comprising:

one or more processors; and

one or more computer storage media storing computer executable instructions which when executed by the one or more processors implement a method for detecting when multiple individuals are likely interacting with multiple privileged sessions that are associated with a single administrator, the method comprising:

establishing a first privileged session between a first client device and a first server, the first privileged session being established using admin credentials that are checked out to an administrator;

while the first privileged session is established, establishing a second privileged session between a second client device and the first server or a second server, the second privileged session also being established using the admin credentials that are checked out to the administrator;

monitoring data transmitted over the first and second privileged sessions; receiving first data that is transmitted over the first privileged session and second data that is transmitted over the second privileged session;

analyzing the first data and the second data to determine that the first data represents first user input to the first client device and the second data represents second user input to the second client device;

determining that the first user input and the second user input occurred simultaneously thereby indicating that the administrator likely did not provide both the first user input and the second user input; and

causing an action to be performed to mitigate risk to the first or second servers.

17. The privileged account management system of claim 16 , wherein determining that the first user input and the second user input occurred simultaneously comprises determining that a first time when the first data is received is within a threshold of a second time when the second data is received.

18. The privileged account management system of claim 16 , wherein the method further comprises:

receiving third data that is transmitted over the first privileged session and fourth data that is transmitted over the second privileged session;

analyzing the third data and the fourth data to determine that the third data represents third user input to the first client device and the fourth data represents fourth user input to the second client device;

determining that the third user input and the fourth user input occurred simultaneously thereby indicating that the administrator likely did not provide both the third user input and the fourth user input; and

causing a further action to be performed to mitigate risk to the first or second servers.

19. The privileged account management system of claim 16 , wherein the further action comprises closing one or both of the first and second privileged sessions.

Assignments (29)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA PREVIOUSLY RECORDED ON REEL 70194 FRAME 942. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 27, 2025
From: QUEST SOFTWARE INC.
To: ONE IDENTITY LLC
Reel/Frame 070678/0366 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2025
From: QUEST SOFTWARE INC.
To: ONE IDENTIFY LLC
Reel/Frame 070194/0942 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CHANGE OF NAME Recorded Sep 13, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 043834/0852 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
RELEASE OF REEL 035860 FRAME 0878 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
Reel/Frame 040027/0158 →
RELEASE OF REEL 035860 FRAME 0797 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
Reel/Frame 040028/0551 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 035858 FRAME 0612 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
Reel/Frame 040017/0067 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 14, 2016
From: DELL PRODUCTS L.P.
To: DELL SOFTWARE, INC.
Reel/Frame 037491/0068 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Jun 9, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC; SECUREWORKS, INC.; STATSOFT, INC.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 035860/0878 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jun 9, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 035860/0797 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Jun 9, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 035858/0612 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 23, 2015
From: PETERSON, MATTHEW T.; PETERSON, DANIEL F.; JONES, JORDAN S.
To: DELL PRODUCTS L.P.
Reel/Frame 035484/0403 →