IP Library Granted Patent US 11,063,951
Granted Patent B1
US 11,063,951 · App. 15/787,246 · Granted Jul 13, 2021

Systems and methods for correcting file system permissions

Inventors: Sean Bergman (Jersey City, NJ); Kyle Michael Enman (Hoboken, NJ); Jeffrey Adam Warren (Ridgewood, NJ)
Assignee: Stealthbits Technologies LLC
H04L63/101G06F16/122G06F16/182
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,063,951
App. No.
15/787,246
Granted
Jul 13, 2021
Kind
B1
Abstract

A method is described. The method includes generating an access model that simulates a transformation of existing new technology file system (NTFS) permissions for a plurality of shared folders. The method also includes creating permission groups for the plurality of shared folders based on the access model. The method further includes updating the NTFS permissions of the shared folders based on the access model and permission groups.

Claims (54)

1. A method, comprising:

determining existing Server Message Block (SMB) permissions and existing new technology file system (NTFS) permissions for a plurality of shared folders;

expanding domain permission groups and local permission groups for the plurality of shared folders to determine existing users associated with the plurality of shared folders;

determining access of the existing users to the plurality of shared folders based on the existing SMB permissions and the existing NTFS permissions;

generating an access model that simulates a transformation of the existing NTFS permissions for the plurality of shared folders, the access model comprising proposed changes to the existing NTFS permissions, wherein the access model maps existing users with read access to read permission groups, the access model maps existing users with write access to read/write permission groups, and the access model downgrades existing users with full control access to the read/write permission groups;

displaying the access model to present the proposed changes to the existing NTFS permissions;

creating permission groups for the plurality of shared folders based on the access model in response to a user accepting the proposed changes; and

updating the NTFS permissions of the shared folders based on the access model and permission groups, wherein the updated NTFS permissions break permission inheritance of the existing NTFS permissions for the plurality of shared folders.

2. The method of claim 1 , wherein generating the access model comprises comparing access control lists of the plurality of shared folders to simulate changes to the existing NTFS permissions.

3. The method of claim 1 , further comprising applying a traverse group to ensure access of shared folders to a root share after updating the NTFS permissions.

4. The method of claim 1 , further comprising determining a scope of shared folders that are included in the access model.

5. The method of claim 1 , further comprising assessing existing access of shared folders that are included in the access model.

6. The method of claim 1 , wherein generating the access model comprises removing inactive users from one or more shared folders.

7. The method of claim 1 , wherein generating the access model comprises mapping users to a least-privileged permission group based on user activity.

8. The method of claim 1 , wherein generating the access model comprises removing high risk trustees from the NTFS permissions.

9. The method of claim 1 , further comprising identifying the plurality of shared folders as files that are a certain number of levels deep from a specified top level share.

10. The method of claim 1 , wherein the access model adds a full control permission group for a user designated to have full control access to manage the plurality of shared folders.

11. The method of claim 1 , further comprising setting a flag indicating that the plurality of shared folders do not inherit the existing NTFS permissions.

12. The method of claim 1 , wherein updating the NTFS permissions of the shared folders comprises:

removing inherited permissions for the plurality of shared folders; and

applying the updated NTFS permissions for the created permission groups based on the access model.

13. A computing device, comprising:

a processor;

a memory in electronic communication with the processor; and

instructions stored in the memory, the instructions being executable to:

determine existing Server Message Block (SMB) permissions and existing new technology file system (NTFS) permissions for a plurality of shared folders;

expand domain permission groups and local permission groups for the plurality of shared folders to determine existing users associated with the plurality of shared folders;

determine access of the existing users to the plurality of shared folders based on the existing SMB permissions and the existing NTFS permissions;

generate an access model that simulates a transformation of the existing NTFS permissions for the plurality of shared folders, the access model comprising proposed changes to the existing NTFS permissions, wherein the access model maps existing users with read access to read permission groups, the access model maps existing users with write access to read/write permission groups, and the access model downgrades existing users with full control access to the read/write permission groups;

display the access model to present the proposed changes to the existing NTFS permissions;

create permission groups for the plurality of shared folders based on the access model in response to a user accepting the proposed changes; and

update the NTFS permissions of the shared folders based on the access model and permission groups, wherein the updated NTFS permissions break permission inheritance of the existing NTFS permissions for the plurality of shared folders.

14. The computing device of claim 13 , wherein the instructions executable to generate the access model comprise instructions executable to compare access control lists of the plurality of shared folders to simulate changes to the existing NTFS permissions.

15. The computing device of claim 13 , further comprising instructions executable to apply a traverse group to ensure access of shared folders to a root share after updating the NTFS permissions.

16. The computing device of claim 13 , further comprising instructions executable to determine a scope of shared folders that are included in the access model.

17. The computing device of claim 13 , further comprising instructions executable to assess existing access of shared folders that are included in the access model.

18. The computing device of claim 13 , wherein the instructions executable to generate the access model comprise instructions executable to remove inactive users from one or more shared folders.

19. The computing device of claim 13 , wherein the instructions executable to generate the access model comprise instructions executable to map users to a least-privileged permission group based on user activity.

20. The computing device of claim 13 , wherein the instructions executable to generate the access model comprise instructions executable to remove high risk trustees from the NTFS permissions.

21. A non-transitory, tangible computer-readable medium, comprising executable instructions for:

determining existing Server Message Block (SMB) permissions and existing new technology file system (NTFS) permissions for a plurality of shared folders;

expanding domain permission groups and local permission groups for the plurality of shared folders to determine existing users associated with the plurality of shared folders;

determining access of the existing users to the plurality of shared folders based on the existing SMB permissions and the existing NTFS permissions;

generating an access model that simulates a transformation of the existing NTFS permissions for the plurality of shared folders, the access model comprising proposed changes to the existing NTFS permissions, wherein the access model maps existing users with read access to read permission groups, the access model maps existing users with write access to read/write permission groups, and the access model downgrades existing users with full control access to the read/write permission groups;

displaying the access model to present the proposed changes to the existing NTFS permissions;

creating permission groups for the plurality of shared folders based on the access model in response to a user accepting the proposed changes; and

updating the NTFS permissions of the shared folders based on the access model and permission groups, wherein the updated NTFS permissions break permission inheritance of the existing NTFS permissions for the plurality of shared folders.

22. The computer-readable medium of claim 21 , wherein the instructions executable for generating the access model comprise instructions executable for comparing access control lists of the plurality of shared folders to simulate changes to the existing NTFS permissions.

23. The computer-readable medium of claim 21 , further comprising instructions executable for applying a traverse group to ensure access of shared folders to a root share after updating the NTFS permissions.

24. The computer-readable medium of claim 21 , further comprising instructions executable for determining a scope of shared folders that are included in the access model.

25. The computer-readable medium of claim 21 , further comprising instructions executable for assessing existing access of shared folders that are included in the access model.

26. The computer-readable medium of claim 21 , wherein the instructions executable for generating the access model comprise instructions executable for removing inactive users from one or more shared folders.

27. The computer-readable medium of claim 21 , wherein the instructions executable for generating the access model comprise instructions executable for mapping users to a least-privileged permission group based on user activity.

28. The computer-readable medium of claim 21 , wherein the instructions executable for generating the access model comprise instructions executable for removing high risk trustees from the NTFS permissions.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Jul 7, 2022
From: TC LENDING, LLC, AS COLLATERAL AGENT
To: STEALTHBITS TECHNOLOGIES LLC (F/K/A STEALTHBITS TECHNOLOGIES II LLC)
Reel/Frame 060430/0798 →
SECURITY INTEREST Recorded Jun 9, 2022
From: NETWRIX CORPORATION; POLICYPAK SOFTWARE, LLC; STEALTHBITS TECHNOLOGIES LLC
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060152/0855 →
MERGER AND CHANGE OF NAME Recorded Feb 25, 2021
From: STEALTHBITS TECHNOLOGIES, INC.; STEALTHBITS TECHNOLOGIES II LLC; STEALTHBITS TECHNOLOGIES II LLC
To: STEALTHBITS TECHNOLOGIES LLC
Reel/Frame 055416/0485 →
PATENT SECURITY AGREEMENT Recorded Dec 31, 2020
From: STEALTHBITS TECHNOLOGIES II LLC
To: TC LENDING, LLC, AS COLLATERAL AGENT
Reel/Frame 054884/0804 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2017
From: BERGMAN, SEAN; ENMAN, KYLE MICHAEL; WARREN, JEFFREY ADAM
To: STEALTHBITS TECHNOLOGIES, INC.
Reel/Frame 044019/0397 →