IP Library Granted Patent US 12,489,791
Granted Patent B2
US 12,489,791 · App. 17/390,888 · Granted Dec 2, 2025

Privilege assurance of computer network environments

Inventors: Gandhi Balasubramaniam (Shalimar, FL); Randy Clayton (Frederick, MD); Jason Crabtree (Vienna, VA); Richard Kelley (Woodbridge, VA); Artem Panasenkov (Reston, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX LLC
H04L63/20G06F16/2477G06F16/951H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,489,791
App. No.
17/390,888
Granted
Dec 2, 2025
Kind
B2
Abstract

A system and method for privilege assurance protection of computer networks that remedies the deficiencies of the current directory service structure. The system uses a software agent to collect and store snapshots of all network resources on a computer network by identifying network domains, searching the directory service of each domain for network resources, and periodically querying the network resources for changes. The software agent communicates with a backend server which provides searching, querying, storage, administrative and other functionality to the agent via remote procedure calls.

Claims (40)

1 . A system for privilege assurance protection of computer networks operating a directory service, comprising:

a software agent comprising a first plurality of programming instructions stored in a memory of, and operating on a processor of, a first computing device within a computer network operating a directory service, wherein the first plurality of programming instructions, when operating on the processor of the first computing device, causes the first computing device to:

search the directory service to identify a plurality of network resources operating on the computer network;

periodically query the plurality of network resources for network information, the network information comprising device identifiers and configuration parameters;

receive responses to the queries from the plurality of network resources, the responses comprising the network information;

send the responses to a backend server for storage in a database;

for each periodic query, create a current state of the plurality of network resources from the responses, the current state comprising either an initial state of the plurality of network resources or differences from a previous state of the plurality of network resources relative to the current state, wherein the differences from the previous state of the plurality of network resources relative to the current state are determined using a highest committed update sequence number (USN) obtained from the directory service before the periodic query is performed; and

send the current state of the plurality of network resources to the backend server for storage in the database; and

the backend server comprising a second plurality of programming instructions stored in a memory of, and operating on a processor of, a second computing device, wherein the second plurality of programming instructions, when operating on the processor of the second computing device, causes the second computing device to:

receive the responses from each periodic query and store the responses them in the database; and

receive the current stte from each periodic query and store the current state it in the database;

wherein the computer network comprises a plurality of domains in a hierarchy having a master domain and one or more sub-domains,

wherein the software agent is installed and operated on a top-level domain of the hierarchy, and

wherein the software agent monitors the plurality of network resources separately for each domain.

2 . The system of claim 1 , wherein communications between the software agent and the backend server are facilitated by remote procedure calls, wherein the software agent makes the remote procedure calls to the backend server, and the methods associated with the remote procedure calls are stored on, and executed by, the backend server.

3 . The system of claim 2 , wherein each remote procedure call by the software agent includes credentials of the software agent contained in metadata of the remote procedure call.

4 . The system of claim 1 , wherein the initial state, current state, and previous state are created and stored as cookies.

5 . The system of claim 1 , wherein the search of the directory service to identify a plurality of network resources includes searching for deleted network resources.

6 . The system of claim 1 , wherein the computer network comprises a plurality of domains, each comprising a directory service and some of the network resources, and the software agent monitors the network resources separately for each domain.

7 . The system of claim 1 , wherein the computer network comprises a plurality of domains, each comprising a directory service and some of the network resources, and a separate software agent is installed on and monitors the network resources separately for each domain.

8 . A method for privilege assurance protection of computer networks operating a directory service, comprising the steps of:

using a software agent operating on a first computing device within a computer network to:

search the directory service to identify a plurality of network resources operating on the computer network;

periodically query the plurality of network resources for network information, the network information comprising device identifiers and configuration parameters;

receive responses to the queries from the plurality of network resources, the responses comprising the network information;

send the responses to a backend server for storage in a database;

for each periodic query, create a current state of the plurality of network resources from the responses, the current state comprising either an initial state of the plurality of network resources or differences from a previous state of the plurality of network resources relative to the current state, wherein the differences from the previous state of the plurality of network resources relative to the current state are determined using a highest committed update sequence number (USN) obtained from the directory service before the periodic query is performed; and

send the current state of the plurality of network resources to the backend server for storage in the database; and

using the backend server operating on a second computing device to:

receive the responses from each periodic query and store the responses in the database; and

receive the current state from each periodic query and store the current state in the database;

wherein the computer network comprises a plurality of domains in a hierarchy having a master domain and one or more sub-domains,

wherein the software agent is installed and operated on a top-level domain of the hierarchy, and

wherein the software agent monitors the network resources separately for each domain.

9 . The method of claim 8 , wherein communications between the software agent and the backend server are facilitated by remote procedure calls, wherein the software agent makes the remote procedure calls to the backend server, and the methods associated with the remote procedure calls are stored on, and executed by, the backend server.

10 . The method of claim 9 , wherein each remote procedure call by the software agent includes credentials of the software agent contained in the metadata of the remote procedure call.

11 . The method of claim 8 , wherein the initial state, current state, and previous state are created and stored as cookies.

12 . The method of claim 8 , wherein the search of the directory service to identify a plurality of network resources includes searching for deleted network resources.

13 . The method of claim 8 , wherein the computer network comprises a plurality of domains, each comprising a directory service and some of the network resources, and the software agent monitors the network resources separately for each domain.

14 . The method of claim 8 , wherein the computer network comprises a plurality of domains, each comprising a directory service and some of the network resources, and a separate software agent is installed on and monitors the network resources separately for each domain.

Assignments (5)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 17, 2022
From: BALASUBRAMANIAM, GANDHI; CLAYTON, RANDY; CRABTREE, JASON; KELLEY, RICHARD; PANASENKOV, ARTEM; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 059936/0995 →
Continuity (50)
Continuation In Part 17008276 · Aug 31, 2020
Continuation In Part 17000504 · Aug 24, 2020
Continuation In Part 16855724 · Apr 22, 2020
Continuation In Part 16836717 · Mar 31, 2020
Continuation In Part 16777270 · Jan 30, 2020
Continuation In Part 16720383 · Dec 19, 2019
Continuation In Part 16412340 · May 14, 2019
Continuation In Part 16267893 · Feb 5, 2019
Continuation In Part 16248133 · Jan 15, 2019
Continuation In Part 15887496 · Feb 2, 2018
Continuation In Part 15849901 · Dec 21, 2017
Continuation In Part 15835436 · Dec 7, 2017
Continuation In Part 15835312 · Dec 7, 2017
Continuation 15823363 · Nov 27, 2017
Continuation In Part 15823285 · Nov 27, 2017
Continuation In Part 15818733 · Nov 20, 2017
Continuation In Part 15813097 · Nov 14, 2017
Continuation In Part 15806697 · Nov 8, 2017
Continuation In Part 15790457 · Oct 23, 2017
Continuation In Part 15790327 · Oct 23, 2017
Continuation In Part 15788718 · Oct 19, 2017
Continuation In Part 15788002 · Oct 19, 2017
Continuation In Part 15787601 · Oct 18, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15673368 · Aug 9, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15376657 · Dec 13, 2016
Continuation In Part 15376657 · Dec 13, 2016
Continuation In Part 15343209 · Nov 4, 2016
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15229476 · Aug 5, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 14925974 · Oct 28, 2015
Related Publication 20220368726A1 · Nov 17, 2022
References Cited (58)
US 5669000A · Jessen et al. · 1997 [cited by applicant]
US 6256544B1 · Weissinger · 2001 [cited by applicant]
US 7072863B1 · Phillips et al. · 2006 [cited by applicant]
US 7657406B2 · Tolone et al. · 2010 [cited by applicant]
US 7698213B2 · Lancaster · 2010 [cited by applicant]
US 7739653B2 · Venolia · 2010 [cited by applicant]
US 8065257B2 · Kuecuekyan · 2011 [cited by applicant]
US 8145761B2 · Liu et al. · 2012 [cited by applicant]
US 8281121B2 · Nath et al. · 2012 [cited by applicant]
US 8615800B2 · Baddour et al. · 2013 [cited by applicant]
US 8788306B2 · Delurgio et al. · 2014 [cited by applicant]
US 8793758B2 · Raleigh et al. · 2014 [cited by applicant]
US 8914878B2 · Burns et al. · 2014 [cited by applicant]
US 8997233B2 · Green et al. · 2015 [cited by applicant]
US 9134966B2 · Brock et al. · 2015 [cited by applicant]
US 9141360B1 · Chen et al. · 2015 [cited by applicant]
US 9323837B2 · Zhao · 2016 [cited by examiner]
US 9424266B2 · Perlin · 2016 [cited by examiner]
US 9602530B2 · Ellis et al. · 2017 [cited by applicant]
US 9654495B2 · Hubbard et al. · 2017 [cited by applicant]
US 9672355B2 · Titonis et al. · 2017 [cited by applicant]
US 9727534B1 · Buddhiraja · 2017 [cited by examiner]
US 9762443B2 · Dickey · 2017 [cited by applicant]
US 9887933B2 · Lawrence, III · 2018 [cited by applicant]
US 9946517B2 · Talby et al. · 2018 [cited by applicant]
US 10003592B2 · Prakash · 2018 [cited by examiner]
US 10061635B2 · Elwein · 2018 [cited by applicant]
US 10210246B2 · Stojanovic et al. · 2019 [cited by applicant]
US 10210255B2 · Crabtree et al. · 2019 [cited by applicant]
US 10248910B2 · Crabtree et al. · 2019 [cited by applicant]
US 10318882B2 · Brueckner et al. · 2019 [cited by applicant]
US 10367829B2 · Huang et al. · 2019 [cited by applicant]
US 10387631B2 · Duggal et al. · 2019 [cited by applicant]
US 10528627B1 · Dunsmore · 2020 [cited by examiner]
US 20050289072A1 · Sabharwal · 2005 [cited by applicant]
US 20070088630A1 · MacLeod · 2007 [cited by examiner]
US 20100061249A1 · Rius I Riu · 2010 [cited by examiner]
US 20100250735A1 · Andersen · 2010 [cited by examiner]
US 20120264443A1 · Ng · 2012 [cited by examiner]
US 20120278453A1 · Baum · 2012 [cited by examiner]
US 20130227352A1 · Kumarasamy · 2013 [cited by examiner]
US 20130304623A1 · Kumar et al. · 2013 [cited by applicant]
US 20140207917A1 · Tock · 2014 [cited by examiner]
US 20140279762A1 · Kaypanya et al. · 2014 [cited by applicant]
US 20150058475A1 · Earl · 2015 [cited by examiner]
US 20150180984A1 · Poletto · 2015 [cited by examiner]
US 20150379424A1 · Dirac et al. · 2015 [cited by applicant]
US 20160004858A1 · Chen et al. · 2016 [cited by applicant]
US 20160080502A1 · Yadav · 2016 [cited by examiner]
US 20160099960A1 · Gerritz et al. · 2016 [cited by applicant]
US 20160140519A1 · Trepca et al. · 2016 [cited by applicant]
US 20160275123A1 · Lin et al. · 2016 [cited by applicant]
US 20160364307A1 · Garg et al. · 2016 [cited by applicant]
US 20170099182A1 · DeBolle · 2017 [cited by examiner]
WO 2014159150A1 · 2014 [cited by applicant]
WO 2017075543 · 2017 [cited by applicant]
Hess, Adam, et al. “An Architecture for Secure SOAP Remote Procedure Calls.” p. 1-9, (2002) (Year: 2002). [cited by examiner]
Bharat, Krishna. “SearchPad: Explicit capture of search context to support web search.” Computer Networks 33.1-6 (2000): 493-501. (Year: 2000). [cited by examiner]