IP Library › Granted Patent US 12,536,255
Granted Patent B2
US 12,536,255 · App. 17/718,565 · Granted Jan 27, 2026

Instrumenting applications to prevent abuse by privileged users

Inventors: Thomas Szigeti (Vancouver, CA); David John Zacks (Vancouver, CA); Walter Theodore Hulick, Jr. (Pearland, TX); Nagendra Kumar Nainar (Morrisville, NC); Carlos M. Pignataro (Cary, NC)
Assignee: Cisco Technology, Inc.
G06F21/31
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,536,255
App. No.
17/718,565
Granted
Jan 27, 2026
Kind
B2
Abstract

In one embodiment, a device obtains data regarding a transaction attempted by a user within an online application that is captured by instrumentation code that is inserted into the online application at runtime, wherein the user has sufficient privileges within the online application to perform the transaction; The device sends, based on the data regarding the transaction, one or more approval requests to one or more authorizers. The device receives one or more responses to the one or more approval requests. The device blocks, and based on the one or more responses, the transaction attempted by the user within the online application via the instrumentation code.

Claims (39)

1 . A method, comprising:

obtaining, by a device, data regarding a transaction attempted by a user within an online application that is captured by instrumentation code, wherein the user has sufficient privileges within the online application to perform the transaction, and wherein the instrumentation code is inserted into the online application at runtime by an agent using byte code instrumentation without requiring re-engineering of the online application and is configured to integrate with a policy enforcement system external to the online application;

sending, by the device and based on the data regarding the transaction, one or more approval requests to one or more authorizers associated with the policy enforcement system external to the online application;

receiving, at the device, one or more responses to the one or more approval requests; and

blocking, by the device and based on the one or more responses, the transaction attempted by the user within the online application by causing the instrumentation code to block the transaction within the online application.

2 . The method as in claim 1 , further comprising:

determining, by the device, whether a sufficient number or a combination of the one or more responses to the one or more approval requests indicate that the transaction is approved.

3 . The method as in claim 1 , wherein the one or more approval requests is sent to the one or more authorizers using a SMS text or MMS message.

4 . The method as in claim 1 , the one or more responses to the one or more approval requests require continuous multi-factor authentication.

5 . The method as in claim 1 , wherein sending, by the device and based on the data regarding the transaction, the one or more approval requests to the one or more authorizers comprises determining whether the transaction is in a list of privileged user tasks.

6 . The method as in claim 5 , wherein the list of privileged user tasks comprises adding or deleting a predetermined number of users, enabling or disabling one or more information technology policies, making one or more critical configuration changes to an information technology system, capturing information from the information technology system, or changing one or more security credentials to the information technology system.

7 . The method as in claim 1 , wherein the one or more approval requests are sent to the one or more authorizers based on whether the one or more authorizers are included in a list of peer authorizers.

8 . The method as in claim 1 , further comprising:

revoking, by the device and based on the one or more responses, privileges of the user within the online application to perform the transaction.

9 . The method as in claim 1 , wherein the instrumentation code is inserted by a core agent into the online application.

10 . The method as in claim 1 , wherein the device comprises an application server, sidecar proxy, or a networking device.

11 . A tangible, non-transitory, computer-readable medium having computer-executable instructions stored thereon that, when executed by a processor on a device, cause the device to perform a method comprising:

obtaining, by the device, data regarding a transaction attempted by a user within an online application that is captured by instrumentation code, wherein the user has sufficient privileges within the online application to perform the transaction, and wherein the instrumentation code is inserted into the online application at runtime by an agent using byte code instrumentation without requiring re-engineering of the online application and is configured to integrate with policy enforcement system external to the online application;

sending, by the device and based on the data regarding the transaction, one or more approval requests to one or more authorizers associated with the policy enforcement system external to the online application;

receiving, at the device, one or more responses to the one or more approval requests; and

blocking, by the device and based on the one or more responses, the transaction attempted by the user within the online application by causing the instrumentation code to block the transaction within the online application.

12 . The tangible, non-transitory, computer-readable medium as in claim 11 , the method further comprising:

determining, by the device, whether a sufficient number or a combination of the one or more responses to the one or more approval requests indicate that the transaction is approved.

13 . The tangible, non-transitory, computer-readable medium as in claim 11 , wherein the one or more approval requests is sent to the one or more authorizers using a SMS text or MMS message.

14 . The tangible, non-transitory, computer-readable medium as in claim 11 , the one or more responses to the one or more approval requests require continuous multi-factor authentication.

15 . The tangible, non-transitory, computer-readable medium as in claim 11 , wherein sending, by the device and based on the data regarding the transaction, the one or more approval requests to the one or more authorizers comprises determining whether the transaction is in a list of privileged user tasks.

16 . The tangible, non-transitory, computer-readable medium as in claim 15 , wherein the list of privileged user tasks comprises adding or deleting a predetermined number of users, enabling or disabling one or more information technology policies, making one or more critical configuration changes to an information technology system, capturing information from the information technology system, or changing one or more security credentials to the information technology system.

17 . The tangible, non-transitory, computer-readable medium as in claim 11 , wherein the one or more approval requests are sent to the one or more authorizers based on whether the one or more authorizers are included in a list of peer authorizers.

18 . The tangible, non-transitory, computer-readable medium as in claim 11 , the method further comprising:

revoking, by the device and based on the one or more responses, privileges of the user within the online application to perform the transaction.

19 . The tangible, non-transitory, computer-readable medium as in claim 11 , wherein the instrumentation code is inserted by a core agent into the online application.

20 . An apparatus, comprising:

one or more network interfaces to communicate with a network;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process that is executable by the processor, the process, when executed, configured to:

obtain data regarding a transaction attempted by a user within an online application that is captured by instrumentation code, wherein the user has sufficient privileges within the online application to perform the transaction, and wherein the instrumentation code is inserted into the online application at runtime by an agent using byte c e mentation without requiring re-engineering of the online application and is configured integrate with a policy enforcement system external to the online application;

send, based on the data regarding the transaction, one or more approval requests to one or more authorizers associate with the policy enforcement system external to the online application;

receive one or more responses to the one or more approval requests; and

block, based on the one or more responses, the transaction attempted by the user within the online application by causing the instrumentation code to block the transaction within the online application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2022
From: SZIGETI, THOMAS; ZACKS, DAVID JOHN; HULICK, WALTER THEODORE, JR.; NAINAR, NAGENDRA KUMAR; PIGNATARO, CARLOS M.
To: CISCO TECHNOLOGY, INC.
Reel/Frame 059571/0816 →
Continuity (1)
Related Publication 20230325478A1 · Oct 12, 2023
References Cited (21)
US 9547847B2 · Ristock · 2017 [cited by applicant]
US 9584390B1 · Jeong · 2017 [cited by examiner]
US 11165634B2 · Medam et al. · 2021 [cited by applicant]
US 11314856B2 · Agarwal · 2022 [cited by examiner]
US 20080178285A1 · Perlman · 2008 [cited by examiner]
US 20140316984A1 · Schwartz · 2014 [cited by examiner]
US 20160050234A1 · Choyi et al. · 2016 [cited by applicant]
US 20160087957A1 · Shah et al. · 2016 [cited by applicant]
US 20160323396A1 · Margulis · 2016 [cited by examiner]
US 20170220805A1 · Ng · 2017 [cited by examiner]
US 20190205555A1 · Duffy · 2019 [cited by examiner]
US 20200213362A1 · Kruse et al. · 2020 [cited by applicant]
US 20200342094A1 · Agarwal · 2020 [cited by examiner]
US 20210243008A1 · Castinado et al. · 2021 [cited by applicant]
US 20210247966A1 · Hulick, Jr. · 2021 [cited by applicant]
US 20220027456A1 · Hulick, Jr. · 2022 [cited by examiner]
US 20220321602A1 · Szigeti · 2022 [cited by examiner]
US 20230239307A1 · Lairsey · 2023 [cited by examiner]
US 20230325478A1 · Szigeti · 2023 [cited by examiner]
US 20230334478A1 · Szigeti · 2023 [cited by examiner]
CN 112435018 · 2021 [cited by applicant]