IP Library Granted Patent US 9,813,422
Granted Patent B2
US 9,813,422 · App. 14/700,502 · Granted Nov 7, 2017

Detecting unauthorized risky or inefficient usage of privileged credentials through analysis of task completion timing

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,813,422
App. No.
14/700,502
Granted
Nov 7, 2017
Kind
B2
Abstract

A privileged account management system can maintain a database that defines a normal amount of time that it takes to perform a task associated with a reason code. When an administrator requests admin credentials for accessing a server, the administrator can provide a reason code which defines a task that the administrator intends to accomplish. A PAM system can maintain a database that defines, for each reason code, a normal amount of time that is required to accomplish the task associated with the reason code. The PAM system can then monitor an elapsed time over which the admin credentials are checked out to an administrator to determine whether the elapsed time exceeds the corresponding normal amount of time. If the elapsed time exceeds the normal amount, the PAM system can take appropriate action to mitigate any potential harm to the server.

Claims (47)

1. A method, implemented by a privileged account management system that comprises at least one processor and memory, for detecting unauthorized, risky, or inefficient usage of admin credentials, the method comprising:

maintaining, by the privileged account management system, a database that defines, for each of a plurality of reason codes, a normal amount of time for performing a task associated with the reason code;

receiving, from a first administrator using a client device, a request for admin credentials to be used to access a first server, the request including a first reason code that identifies a first task that the first administrator intends to perform on the first server;

in response to the request, checking out the admin credentials to the first administrator to enable the first administrator to access the first server;

accessing the database to identify a first normal amount of time that is defined for the first reason code;

tracking an elapsed time over which the admin credentials are checked out to the first administrator;

comparing the elapsed time to the first normal amount of time; and

when the elapsed time exceeds the first normal amount of time by a defined threshold, taking an action to mitigate harm to the server.

2. The method of claim 1 , wherein the database stores a plurality of normal amounts of time for the first reason code, and wherein the first normal amount of time defines an amount of time that the first administrator normally takes to perform the first task.

3. The method of claim 1 , wherein the database stores a plurality of normal amounts of time for the first reason code, and wherein the first normal amount of time defines an amount of time that is normally required to perform the first task on the first server.

4. The method of claim 1 , wherein the database stores a plurality of normal amounts of time for the first reason code, and wherein the first normal amount of time defines an amount of time that the first administrator normally takes to perform the first task on the first server.

5. The method of claim 4 , wherein the plurality of normal amounts of time for the first reason code includes a second normal amount of time that defines an amount of time that the first administrator normally takes to perform the first task on a second server.

6. The method of claim 4 , wherein the plurality of normal amounts of time for the first reason code includes a second normal amount of time that defines an amount of time that a second administrator normally takes to perform the first task on the first server.

7. The method of claim 1 , wherein the action comprises notifying a security officer that the elapsed time has exceeded the first normal amount of time.

8. The method of claim 1 , wherein the action comprises flagging, monitoring, recording, or killing a remote session between the client device and the first server.

9. The method of claim 1 , wherein the action comprises storing a notice in association with the request, the notice identifying that the elapsed time exceeded the first normal amount of time.

10. The method of claim 1 , wherein the first normal amount is generated based on a plurality of previously monitored elapsed times that were associated with the first reason code.

11. The method of claim 1 , wherein checking out the admin credentials comprises one of:

sending the admin credentials to the client device; or

creating a remote session with the client device to allow the client device to access the first server.

12. The method of claim 1 , wherein the action is taken while the admin credentials remain checked out to the first administrator.

13. A method, implemented by a privileged account management system that comprises at least one processor and memory, for creating a database that defines, for each of a plurality of reason codes, a normal amount of time for performing a task associated with a reason code, the method comprising:

for each of the plurality of reason codes:

receiving, at the privileged account management system, a plurality of requests, from one or more administrators using one or more client devices, for admin credentials that specify the reason code;

for each of the plurality of requests, identifying an elapsed time over which the admin credentials were checked out while a task associated with the reason code was performed; and

generating a normal amount for the reason code based on the plurality of identified elapsed times such that the normal amount defines an amount of time that is normally required to perform the task associated with the reason code.

14. The method of claim 13 , further comprising:

for at least one of the plurality of reason codes:

for each of the plurality of requests, identifying criteria of the request, the criteria comprising one or both of an administrator that made the request and a server specified in the request; and

generating a plurality of normal amounts for the reason code, each normal amount being specific to a different combination of the identified criteria.

15. The method of claim 14 , wherein for the at least one of the plurality of reason codes, the plurality of normal amounts comprise a first normal amount that defines an amount of time that a first administrator normally takes to perform the associated task on a first server and a second normal amount that defines an amount of time that that first administrator normally takes to perform the associated task on a second server.

16. The method of claim 14 , wherein for the at least one of the plurality of reason codes, the plurality of normal amounts comprise a first normal amount that defines an amount of time that a first administrator normally takes to perform the associated task on a first server and a second normal amount that defines an amount of time that a second administrator normally takes to perform the associated task on the first server.

17. The method of claim 13 , wherein generating a normal amount comprises updating a previously generated normal amount.

18. A privileged account management system comprising:

one or more processors; and

one or more non-transitory computer storage media storing computer executable instructions which when executed by the one or more processors implement a method for detecting unauthorized, risky, or inefficient usage of admin credentials, the method comprising:

maintaining a database that defines, for each of a plurality of reason codes, a plurality of normal amounts of time for performing a task associated with the reason code, each of the plurality of normal amounts of time being associated with a different combination of criteria, each combination of criteria comprising one or more of an administrator that performs the task and a server on which the task is performed;

receiving, from a first administrator using a client device, a request for admin credentials to be used to access a first server, the request including a first reason code that identifies a first task that the first administrator intends to perform on the first server;

in response to the request, checking out the admin credentials to the first administrator to enable the first administrator to access the first server;

accessing the database to identify a first normal amount of time that is defined for the first reason code, the first normal amount also being associated with a combination of criteria including one or both of the first administrator and the first server;

tracking an elapsed time over which the admin credentials are checked out to the first administrator;

comparing the elapsed time to the first normal amount of time; and

when the elapsed time exceeds the first normal amount of time by a defined threshold, taking an action to mitigate harm to the server.

19. The privileged account management system of claim 18 , wherein the first normal amount is associated with the first administrator and the first server.

20. The privileged account management system of claim 18 , further comprising:

receiving a second request that includes the first reason code; and

accessing the database to identify a second normal amount of time that is defined for the first reason code, the second normal amount being associated with a different combination of criteria than the combination of criteria associated with the first normal amount.

Assignments (29)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA PREVIOUSLY RECORDED ON REEL 70194 FRAME 942. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 27, 2025
From: QUEST SOFTWARE INC.
To: ONE IDENTITY LLC
Reel/Frame 070678/0366 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2025
From: QUEST SOFTWARE INC.
To: ONE IDENTIFY LLC
Reel/Frame 070194/0942 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CHANGE OF NAME Recorded Sep 13, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 043834/0852 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
RELEASE OF REEL 035860 FRAME 0878 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
Reel/Frame 040027/0158 →
RELEASE OF REEL 035860 FRAME 0797 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
Reel/Frame 040028/0551 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 035858 FRAME 0612 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
Reel/Frame 040017/0067 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 14, 2016
From: DELL PRODUCTS L.P.
To: DELL SOFTWARE, INC.
Reel/Frame 037490/0907 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Jun 9, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC; SECUREWORKS, INC.; STATSOFT, INC.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 035860/0878 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jun 9, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 035860/0797 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Jun 9, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 035858/0612 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2015
From: PETERSON, MATTHEW T.; PETERSON, DANIEL F.; JONES, JORDAN S.
To: DELL PRODUCTS L.P.
Reel/Frame 035548/0785 →