IP Library Granted Patent US 10,158,675
Granted Patent B2
US 10,158,675 · App. 15/706,475 · Granted Dec 18, 2018

Identity security and containment based on detected threat events

Inventors: Keith Martin Graham (Ashburn, VA); Stephen Garnett Cox (Leesburg, VA)
Assignee: SecureAuth Corporation
H04L63/20H04L63/08H04L63/10H04L63/102H04L63/1416H04L63/1433H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,158,675
App. No.
15/706,475
Granted
Dec 18, 2018
Kind
B2
Abstract

An alert source issues security alerts to an identity provider, which acts as a gatekeeper to a secure resource. Each security alert is associated with an alert user identity and a security threat. When a user identity requests access to the secure resource, the identity provider may look up security alerts associated with the user identity, such as by matching up the user identity with the alert user identity associated with each alert. Based on any discovered security alerts that correspond to the user identity and a pre-defined security policy, the identity provider may perform various security actions on the user identity. The identity provider may provide access to the secure resource without containing the user identity if there are no discovered security alerts associated with the user identity, or if the discovered security alerts pose a minor threat.

Claims (22)

1. A system for controlling access to a secure network resource, comprising:

an identity provider system that implements an authentication process to control network-based accesses to the secure network resource based on user identities, the identity provider system comprising a hardware processor; and

a security threat detection system configured to detect security threats associated with user identities, including threats in which an endpoint device becomes infected with malware, and to issue security alert messages based on the detected security threats, the security threat detection system comprising a processor;

wherein the security threat detection system is responsive to detecting a security threat involving a compromised endpoint device by generating, and sending on a network, a security alert message specifying at least a type of the detected security threat and a user identity associated with the compromised endpoint device, the user identity being distinct from a device identifier of the compromised endpoint device;

wherein the identity provider system maintains a record of the security alerts messages received from the security threat detection system, and is configured to respond to an attempt, by a first endpoint device, to use a first user identity to access the secure network resource, by at least:

determining, from the record of security alert messages, using a fuzzy matching process, whether any security alert messages have been received that correspond to the first user identity, the fuzzy matching process accounting for differences in user identifier formats between the first user identity and the security alert messages; and

when one or more security alert messages have been received that correspond to the first user identity, using a security protocol to select one of a plurality of defined security actions to perform to control access by the first endpoint device to the secure network resource, wherein the security protocol uses the security threat types specified in the security alert messages to select between the plurality of defined security actions.

2. The system of claim 1 , wherein the plurality of defined security actions include a security action in which the identity provider system requires the first endpoint device to provide an additional authentication factor that is not ordinarily required for authentication of the first user identity.

3. The system of claim 1 , wherein the plurality of defined security actions include a security action in which the identity provider system disables a user account associated with the first user identity.

4. The system of claim 1 , wherein security threat detection system comprises (1) a first computing device that detects endpoint security threats associated with user identities, and (2) a second computing device that detects network security threats associated with user identities.

5. A process of controlling access to a secure network resource, the process comprising:

receiving, from a security threat detection system, a security alert message specifying a type of a detected security threat and a user identity associated with the security threat;

storing a representation of the security alert message in computer storage;

subsequently, receiving an authentication request from an endpoint device, the authentication request including a user identifier;

determining, using a fuzzy matching process that accounts for a format difference between the user identifier and the security alert message, that the user identifier corresponds to the user identity included in the security alert message; and

in response to determining that the user identifier corresponds to the user identity, selecting, based on a security protocol, a security action to perform to restrict access by the endpoint device to the secure resource, wherein the security protocol maps different security threat types to different security actions;

said process performed by execution of program code by a computing system that provides authentication-based access to the secure network resource.

6. The process of claim 5 , wherein the security alert message specifies that an endpoint device associated with the user identity is infected with malware.

7. The process of claim 5 , wherein the user identity is not unique to a particular endpoint device.

8. The process of claim 5 , wherein the user identity is capable of being used to obtain access to the secure network resource from any of a plurality of endpoint devices.

9. The process of claim 5 , wherein the selected security action comprises disabling a user account associated with the user identity.

10. The process of claim 5 , wherein the selected security action comprises requiring entry of an additional authentication factor not ordinarily required for authentication of the user identity.

Assignments (1)
SECURITY INTEREST Recorded Aug 12, 2024
From: CLOUDENTITY, INC.; SECUREAUTH CORPORATION
To: WESTERN ALLIANCE BANK
Reel/Frame 068563/0176 →
Continuity (2)
Continuation 15061846 · Mar 4, 2016
Related Publication 20180103065A1 · Apr 12, 2018
Cited By (1)
US 12,335,280