IP Library Granted Patent US 9,591,016
Granted Patent B1
US 9,591,016 · App. 14/946,921 · Granted Mar 7, 2017

Assessing security risks associated with connected application clients

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,591,016
App. No.
14/946,921
Granted
Mar 7, 2017
Kind
B1
Abstract

A method for assessing security risks associated with a cloud application to which one or more connected applications are coupled begins by configuring a security risk assessment application to function as a connected application. The security risk assessment application collects “first” data associated with one or more accounts, and “second” data associated with the one or more connected applications coupled to the cloud application. After receiving the first and second data, the security risk assessment application instantiates that data into a generic “data object” that the system uses to represent each account and each of the connected applications. Each such data object thus is populated either with the first data or the second data, depending on whether the data object represents an account or a connected application. A risk assessment is then applied to the generic data object to assess a security risk associated with the cloud application.

Claims (34)

1. A method for assessing security risks associated with a cloud application to which one or more connected applications are coupled, comprising:

configuring a security risk assessment application to function as a connected application to the cloud application, wherein a connected application is an application that has been granted access to the cloud application with one or more privileges or permissions to collect data and manage the cloud application;

collecting, by the security risk assessment application, first data associated with one or more accounts, and second data associated with the one or more connected applications coupled to the cloud application, wherein at least one account is an identity and access management (IAM) account that is an entity that includes a set of parameters defining application-specific attributes of a principal;

generating, by the security risk assessment application, multiple data objects of a same type, wherein each account is represented by one of the multiple data objects, and wherein each connected application is represented by one of the multiple data objects, wherein a data object that represents an account is populated with the first data, wherein a data object that represents a connected application is populated with the second data; and

applying a risk assessment to a particular data object to assess a security risk associated with the cloud application.

2. The method as described in claim 1 wherein the first data includes a list of accounts and additional data associated with at least one account.

3. The method as described in claim 1 wherein the second data includes a list of the one or more connected applications coupled to the cloud application and additional data associated with at least one of the connected applications.

4. The method as described in claim 1 wherein applying the risk assessment to the data object applies a same risk assessment operation to both the first data and the second data.

5. The method as described in claim 1 wherein applying the risk assessment to the data object applies a different risk assessment operation to each of the first data and the second data.

6. The method as described in claim 1 wherein applying the risk assessment to the data object applies a same risk assessment operation to both the first data and the second data but with distinct evaluation criteria.

7. The method as described in claim 1 wherein at least one connected application coupled to the cloud application is an Internet-of-Things (IoT) client.

8. An apparatus, comprising:

a processor;

computer memory holding computer program instructions executed by the processor to assess security risks associated with a cloud application to which one or more connected applications are coupled, the computer program instructions comprising a security risk assessment application operative to:

configure the security risk assessment application to function as a connected application to the cloud application, wherein a connected application is an application that has been granted access to the cloud application with one or more privileges or permissions to collect data and manage the cloud application;

collect first data associated with one or more accounts, and second data associated with the one or more connected applications coupled to the cloud application, wherein at least one account is an identity and access management (IAM) account that is an entity that includes a set of parameters defining application-specific attributes of a principal;

generate multiple data objects of a same type, wherein each account is represented by one of the multiple data objects, and wherein each connected application is represented by one of the multiple data objects, wherein a data object that represents an account is populated with the first data, wherein a data object that represents a connected application is populated with the second data; and

apply a risk assessment to a particular data object to assess a security risk associated with the cloud application.

9. The apparatus as described in claim 8 wherein the first data includes a list of accounts and additional data associated with at least one account.

10. The apparatus as described in claim 8 wherein the second data includes a list of the one or more connected applications coupled to the cloud application and additional data associated with at least one of the connected applications.

11. The apparatus as described in claim 8 wherein the risk assessment applies a same risk assessment operation to both the first data and the second data.

12. The apparatus as described in claim 8 wherein the risk assessment applies a different risk assessment operation to each of the first data and the second data.

13. The apparatus as described in claim 8 wherein the risk assessment applies a same risk assessment operation to both the first data and the second data but with distinct evaluation criteria.

14. The apparatus as described in claim 8 wherein at least one connected application coupled to the cloud application is an Internet-of-Things (IoT) client.

15. A computer program product in a non-transitory computer readable medium for use in a data processing system, the computer program product holding computer program instructions which, when executed by the data processing system, assess security risks associated with a cloud application to which one or more connected applications are coupled, the computer program instructions comprising a security risk assessment application operative to:

configure the security risk assessment application to function as a connected application to the cloud application, wherein a connected application is an application that has been granted access to the cloud application with one or more privileges or permissions to collect data and manage the cloud application;

collect first data associated with one or more accounts, and second data associated with the one or more connected applications coupled to the cloud application, wherein at least one account is an identity and access management (IAM) account that is an entity that includes a set of parameters defining application-specific attributes of a principal;

generate multiple data objects of a same type, wherein each account is represented by one of the multiple data objects, and wherein each connected application is represented by one of the multiple data objects, wherein a data object that represents an account is populated with the first data, wherein a data object that represents a connected application is populated with the second data; and

apply a risk assessment to a particular data object to assess a security risk associated with the cloud application.

16. The computer program product as described in claim 15 wherein the first data includes a list of accounts and additional data associated with at least one account.

17. The computer program product as described in claim 15 wherein the second data includes a list of the one or more connected applications coupled to the cloud application and additional data associated with at least one of the connected applications.

18. The computer program product as described in claim 15 wherein the risk assessment applies a same risk assessment operation to both the first data and the second data.

19. The computer program product as described in claim 15 wherein the risk assessment applies a different risk assessment operation to each of the first data and the second data.

20. The computer program product as described in claim 15 wherein the risk assessment applies a same risk assessment operation to both the first data and the second data but with distinct evaluation criteria.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: AIRBNB, INC.
Reel/Frame 056427/0193 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2015
From: PALMIERI, DAVID WALSH; CHIA, GEE NGOO; ROBKE, JEFFREY TOBIAS
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 037096/0929 →