IP Library Patent Application 15850524
Patent Application
App. No. 15/850,524

Shadow IT Discovery Using Traffic Signatures

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/850,524
Abstract

A method, system and computer-usable medium for performing a shadow information technology discover operation, comprising: monitoring interactions initiated via an endpoint device; determining when the interactions comprise a cloud services request, the cloud services request comprising a request by a user to access a cloud service; monitoring interactions between the user and the cloud service when a request to access the cloud service is detected; determining whether the interactions between the user and the cloud service represent a non-authorized use of the cloud service; and, managing risk associated with non-authorized use of the cloud service.

Claims (58)

1 . A computer-implementable od for performing a shadow information technology discover operation, comprising:

monitoring interactions initiated via an endpoint device;

determining when the interactions comprise a cloud services request, the cloud services request comprising a request by a user to access a cloud service;

monitoring interactions between the user and the cloud service when a request to access the cloud service is detected;

determining whether the interactions between the user and the cloud service represent a non-authorized use of the cloud service;

managing risk associated with non-authorized use of the cloud service.

2 . The method of claim 1 , wherein:

the managing risk comprises elevating a risk level associated with the user when the interactions represent the non-authorized use of the cloud service.

3 . The method of claim 1 , wherein:

the interactions between the user and the cloud service are monitored via a shadow information technology discovery system.

4 . The method of claim 1 , wherein:

the monitoring includes review of web proxy traffic logs.

5 . The method of claim further comprising:

determining whether the cloud service corresponds to a restricted cloud service; and,

when the cloud service corresponds to the restricted cloud service then a security policy corresponding to the restricted cloud service is enforced.

6 . The method of claim 1 , wherein:

managing risk associated with the non-authorized use of the cloud service includes restricting use of the cloud service.

7 . A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

monitoring interactions initiated via an endpoint device;

determining when the interactions comprise a cloud services request, the cloud services request comprising a request by a user to access a cloud service;

monitoring interactions between the user and the cloud service when a request to access the cloud service is detected;

determining whether the interactions between the user and the cloud service represent a non-authorized use of the cloud service;

managing risk associated with non-authorized use of the cloud service.

8 . The system of claim 7 , wherein:

the managing risk comprises elevating a risk level associated with the user when the interactions represent the non-authorized use of the cloud service.

9 . The system of claim 7 , wherein:

the interactions between the user and the cloud service are monitored via a shadow information technology discovery system.

10 . The system of claim 7 , wherein:

the monitoring includes review of web proxy traffic logs.

11 . The system of claim 7 , wherein the instructions executable by the processor are further configured for:

determining whether the cloud service corresponds to a restricted cloud service; and,

when the cloud service corresponds to the restricted cloud service then a security policy corresponding to the restricted cloud service is enforced.

12 . The system of claim 7 , wherein:

managing risk associated with the non-authorized use of the cloud service includes restricting use of the cloud service.

3 . A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

monitoring interactions initiated via an endpoint device;

determining when the interactions comprise a cloud services request, the cloud services request comprising a request by a user to access a cloud service;

monitoring interactions between the user and the cloud service when a request to access the cloud service is detected;

determining whether the interactions between the user and the cloud service represent a non-authorized use of the cloud service;

managing risk associated with non-authorized use of the cloud service.

14 . The non-transitory, computer-readable storage medium of claim 13 , wherein:

the managing risk comprises elevating a risk level associated with the user when the interactions represent the non-authorized use of the cloud service.

15 . The non-transitory, computer-readable storage medium of claim 13 , wherein:

the interactions between the user and the cloud service are monitored via a shadow information technology discovery system.

16 . The non-transitory, computer-readable storage medium of claim 13 , wherein:

the monitoring includes review of web proxy traffic logs.

17 . The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are further configured for:

determining whether the cloud service corresponds to a restricted cloud service; and,

when the cloud service corresponds to the restricted cloud service then a security policy corresponding to the restricted cloud service is enforced.

18 . The non-transitory, computer-readable storage medium of claim 13 , wherein:

managing risk associated with the non-authorized use of the cloud service includes restricting use of the cloud service.

19 . The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

20 . The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055479/0676 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 15, 2019
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 048613/0636 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2017
From: LIPMAN, ALEX; YAROM, OFER
To: FORCEPOINT, LLC
Reel/Frame 044463/0080 →