IP Library Granted Patent US 11,057,436
Granted Patent B1
US 11,057,436 · App. 16/571,857 · Granted Jul 6, 2021

System and method for monitoring computing servers for possible unauthorized access

Inventors: Bryan Martin (San Jose, CA); Zhishen Liu (San Jose, CA); Qing Zhao (San Jose, CA)
Assignee: 8x8, Inc.
H04L63/20H04L63/102H04L63/1408H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,057,436
App. No.
16/571,857
Granted
Jul 6, 2021
Kind
B1
Abstract

A system is provided that includes one or more computing servers and a processing circuit for analyzing data transactions of the computing servers. Each of the computing servers is configured to provide respective services to remote users. The processing circuit is configured to analyze data transactions of at least one of the computing servers, which is associated with a user account. A security policy of the user account includes conditions that are indicative of unauthorized access when the conditions are satisfied by various characteristics of the analyzed data transactions. The processing circuit is configured to determine a threat level as function of the characteristics of the data transactions and the conditions of the security policy. In response to the threat level exceeding a first threshold level indicated in the security policy of the user account, the processing circuit performs an action for the user account that is associated with the first threshold level.

Claims (33)

1. A system, comprising:

one or more Voice-over-Internet Protocol (VoIP) servers, each configured to provide respective VoIP and data communications services to remote users; and

a processing circuit communicatively-coupled to the one or more VoIP servers and to: monitor data transactions involving at least one of the VoIP servers of the processing circuit to determine whether VoIP call characteristics of a VoIP call indicate that the VoIP call is in a possible call loop;

determine, in response to the VoIP call characteristics indicating that the VoIP call is in a possible call loop and the monitored data transactions, a threat level as an indication that the possible call loop corresponds to an actual call loop; and

in response to the indication exceeding an adaptive threshold level indicated in a security policy of a user account corresponding to the VoIP call, send a notification to an authorized user of the user account, wherein the threshold level is a function of a characteristic of the data transactions associated with the possible call loop, wherein the notification indicates that the possible call loop corresponds to an actual call loop.

2. The system of claim 1 , wherein the processing circuit is further configured to:

in response to the monitored data transactions exhibiting characteristics indicative of a system problem, send a notification to the authorized user of the user account.

3. The system of claim 2 , wherein the processing circuit is further configured to in further response to the monitored data transactions exhibiting characteristics indicative of a system problem:

determine if the system problem is a server-side problem or a user-side problem;

in response to determining that the system problem is a server-side problem, send a notification to the authorized user of the user account; and

in response to determining that the system problem is a user-side problem, of one of the remote users corresponding to one of the monitored data transactions, send a notification to the remote user.

4. The system of claim 2 , wherein the characteristics indicative of a system problem include call jitter, dropped data packets, and network connectivity.

5. The system of claim 1 , wherein the processing circuit is configured to determine a threat level based on a number of conditions of the security policy that are satisfied by the one or more characteristics of the data transactions.

6. The system of claim 1 , wherein one or more conditions of the security policy indicative of unauthorized access includes a condition that is satisfied by a frequency of data transactions exceeding a threshold indicated in the security policy.

7. The system of claim 1 , wherein one or more conditions of the security policy indicative of unauthorized access includes a condition that is satisfied by a size of a data transaction exceeding a threshold transaction size in the security policy.

8. The system of claim 1 , wherein one or more conditions of a security policy indicative of unauthorized access includes a condition that is satisfied by exceeding a daily data transfer limit indicated in the security policy.

9. The system of claim 1 , wherein one or more conditions of a security policy indicative of unauthorized access includes a condition that is satisfied by a frequency of data transactions surpassing a stored average for the user account by a threshold indicated in the security policy.

10. The system of claim 1 , wherein one or more conditions of a security policy indicative of unauthorized access includes a condition that is satisfied by detecting a user logged in to the at least one server from an IP address outside of an IP address range specified by the security policy.

11. The system of claim 1 , wherein one or more conditions of a security policy indicative of unauthorized access includes a condition that is satisfied by a number of failed login attempts exceeding a limit indicated in the security policy.

12. The system of claim 1 , wherein the processing circuit is configured to determine a threat level as a function of sensitivity level of files/folders that are accessed.

13. The system of claim 1 , wherein the processing circuit is configured to determine a threat level as a function of a direction of the data transactions.

14. The system of claim 1 , wherein the processing circuit is configured to determine a threat level as a function of IP location of a user initiating the data transactions.

15. The system of claim 1 , wherein the processing circuit is further configured to, responsive to a threat level exceeding a second threshold level indicated in the security policy, perform one or more automated tasks to prevent further unauthorized access to the at least one server.

16. The system of claim 1 , wherein the processing circuit is configured to send the notification by sending one or more types of messages including: an SMS text message to a number listed in the security policy, an automated voice call to a number listed in the security policy, an email to an email address listed in the security policy, and a social network message.

17. The system of claim 1 , wherein the notification provides a mechanism to allow the authorized user to select from one or more possible actions.

18. The system of claim 1 , wherein the processing circuit is further configured to:

provide an internet based graphical user interface (GUI); and

modify the security policy in response to user input via the GUI.

19. A method, comprising:

monitoring data transactions that involve a Voice-over-Internet Protocol (VoIP) server and that correspond to a user account having a security policy;

determining a potential problem as a possible call loop associated with the monitored data transactions as a function of the security policy, and determining a threat level as an indication that the possible call loop corresponds to an actual call loop; and

in response to an assessment of potential problem relative to the security policy associated with the user account and in response to the threat level exceeding an adaptive threshold level indicated in a security policy of the user account, sending a notification to an authorized user of the user account, wherein the notification indicates that the possible call loop corresponds to an actual call loop.

20. The method of claim 19 , further including sending the notification via an internet based graphical user interface (GUI).

Assignments (5)
SECURITY INTEREST Recorded Aug 5, 2024
From: 8X8, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 068327/0819 →
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2024
From: WILMINGTON SAVINGS FUND SOCIETY, FSB
To: 8X8, INC.; FUZE, INC.
Reel/Frame 068328/0569 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS SECTION TO REMOVE APPLICATION NUMBERS 11265423, 11252205, 11240370, 11252276, AND 11297182 PREVIOUSLY RECORDED ON REEL 061085 FRAME 0861. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY SECURITY AGREEMENT. Recorded Jan 26, 2024
From: 8X8, INC.; FUZE, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066383/0936 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: 8X8, INC.; FUZE, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 061085/0861 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2019
From: MARTIN, BRYAN; LIU, ZHISHEN; ZHAO, QING
To: 8X8, INC.
Reel/Frame 050390/0009 →
Continuity (3)
Continuation 15785697 · Oct 17, 2017
Continuation 15074147 · Mar 18, 2016
Continuation 14107656 · Dec 16, 2013