IP Library Granted Patent US 12,003,545
Granted Patent B2
US 12,003,545 · App. 17/503,366 · Granted Jun 4, 2024

System account access manager utilizing an endpoint detection and response system

Inventors: Paul Lanzi (San Francisco, CA); Timothy Keeler (San Francisco, CA)
Assignee: Netwrix Corporation
H04L63/20H04L63/0272H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,003,545
App. No.
17/503,366
Granted
Jun 4, 2024
Kind
B2
Abstract

In one aspect, a computerized system includes an access manager server connected to one or more target computer systems. The access manager server is connected to the one or more target computer systems via an Endpoint Detection and Response (EDR) system. The EDR system continually monitors one or more target computer systems (e.g. endpoints) and responds to mitigate a cyber threat to the one or more target computer systems. The EDR system includes an EDR control plane that manages and communicates with one or more EDR agents. The EDR control plane causes a specific computer security action in the one or more target computer systems via one or more EDR agents. One or more EDR agents are installed in the one or more target computer systems. The one or more EDR agents are made available via the EDR API.

Claims (28)

1. A computerized system comprising:

an access manager server connected to one or more target computer systems, wherein the access manager server is connected to the one or more target computer systems via an Endpoint Detection and Response (EDR) system, and wherein the access manager server is configured to detect that a network line of sight is not available to one or more target computers;

an EDR system, wherein the EDR system continually monitors and responds to mitigate a cyber threat to the one or more target computer systems, wherein the EDR comprises:

an EDR control plane that manages and communicates with one or more EDR agents, wherein the EDR control plane causes a specified action in the one or more target computer systems via one or more EDR agents,

one or more EDR agents that are installed in the one or more target computer systems, wherein the one or more EDR agents are made available via the EDR API, and wherein through the EDR API, the access manager server communicates a request to the EDR control plane to implement various actions, and

an EDR API that communicates the specified action from the access manager server to the EDR control plane;

the one or more target computer systems compromises computer devices protected by a set of cyber security specified functionalities implemented by the access manager server.

2. The computer system of claim 1 ,

wherein the specified action comprises a specified computer system security action,

wherein the computer devices comprises a computer hardware device or a computer virtual device, and

where the set of specified functionalities comprises a set of cyber security functionalities.

3. The computer system of claim 1 , wherein the access manager server is configured to detect that the target computer is not using a virtual private network (VPN) to connect to a specified network from a remote location.

4. The computer system of claim 3 , wherein the one or more target computers remains exposed to the EDR control plane via an indirect computer network when the access manager server detects that the network line of sight is not available to the one or more target computers.

5. The computer system of claim 4 , wherein the access manager server interfaces with the EDR system to execute a specified computer system security action through EDR API.

6. The computer system of claim 4 , wherein the access manager server leverages the EDR system to implement an application allow-listing in the one or more target computer systems.

7. The computer system of claim 4 , wherein the access manager server leverages the EDR system to implement and/or retrieve data from a process level monitoring and logging operation in the one or more target computer systems.

8. The computer system of claim 4 , wherein the access manager server leverages the EDR system to add and remove accounts from permission to access an application in the one or more target computer systems.

9. The computer system of claim 4 , wherein the access manager server leverages the EDR system to implement a dynamic privilege management that temporarily gives privileges to a specified user in the one or more target computer systems.

10. The computer system of claim 4 , wherein the access manager server leverages the EDR system to implement an account management operation in the one or more target computer systems.

11. The computer system of claim 4 , wherein the access manager server leverages the EDR system to implement and/or determine a specified cyber security health state in the one or more target computer systems.

12. The computer system of claim 4 , wherein the access manager server leverages the EDR system to implement a geofencing operation in the one or more target computer systems.

13. The computer system of claim 4 , wherein the access manager server leverages the EDR system to implement a specified discovery of a risk event operation in the one or more target computer systems.

14. The computerized system of claim 13 , wherein the access manager server periodically calls on the EDR API and collects a set of risk event data from the one or more target computer systems using the one or more EDR agents.

15. The computerized system of claim 13 , wherein the access manager server causes the EDR system to set an event trigger in the one or mar target computer systems and to notify the access manager server about any specific security events that are detected by EDR agents in the one or more target computer systems that are related to the event trigger.

16. The computer system of claim 4 , wherein the access manager server leverages the EDR system to register new endpoints when any new computer systems are added to the one or more EDR systems.

17. The computer system of claim 4 , wherein the access manager server leverages the EDR system to provide reports about current managed target computer systems in the one or more EDR systems.

18. The computer system of claim 4 , wherein the access manager server leverages the EDR system to revoke Just-In-Time Privileged Access Management (JITA) rights of systems that access the one or more target computer systems.

19. The computer system of claim 1 , wherein the access manager server is configured to request that the one or more EDR agents implement the specified task on the target computer when the access manager server detects that the network line of sight is not available to the one or more target computers.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2023
From: REMEDIANT, INC.
To: NETWRIX CORPORATION
Reel/Frame 062576/0629 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 17, 2022
From: TIMOTHY KEELER;; PAUL LANZI
To: REMEDIANT, INC.
Reel/Frame 061817/0022 →
Continuity (2)
Provisional Application 63131056 · Dec 28, 2020
Related Publication 20220210199A1 · Jun 30, 2022