IP Library Granted Patent US 12,244,621
Granted Patent B1
US 12,244,621 · App. 17/858,866 · Granted Mar 4, 2025

Using activity monitored by multiple data sources to identify shadow systems

Inventors: Vikram Kapoor (Cupertino, CA); Harish Kumar Bharat Singh (Pleasanton, CA); Weifei Zeng (Sunnyvale, CA); Vimalkumar Jeyakumar (Los Altos, CA); Theron Tock (Mountain View, CA); Ying Xie (Cupertino, CA); Yijou Chen (Cupertino, CA)
Assignee: Fortinet, Inc.
H04L63/1425G06F9/455G06F9/545G06F16/9024G06F16/9038G06F16/9535G06F16/9537G06F21/57H04L43/045H04L43/06H04L63/10H04L67/306H04L67/535G06F16/2456
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,244,621
App. No.
17/858,866
Granted
Mar 4, 2025
Kind
B1
Abstract

Using activity monitored by multiple data sources to identify shadow systems, the method comprising: gathering first information describing access to one or more resources by one or more user devices of a user; gathering, from at least a subset of the one or more user devices, second information describing access to the one or more resources; and identifying one or more shadow systems based on a discrepancy between the first information and the second information.

Claims (31)

1. A method of using activity monitored by multiple data sources to identify shadow systems, the method comprising:

gathering, from one or more resources or providers of the one or more resources, first information describing access to the one or more resources by one or more user devices of a user;

gathering, from one or more client applications of at least a subset of the one or more user devices, second information describing access to the one or more resources; and

identifying one or more shadow systems based on a discrepancy between the first information and the second information, wherein the one or more shadow systems comprise one or more of the at least a subset of the one or more user devices engaging in shadow information technology (IT) activity, wherein identifying the one or more shadow systems comprises identifying one or more accesses described in the first information but not described in the second information and identifying, as one or more shadow systems, one or more user devices corresponding to the one or more accesses.

2. The method of claim 1 wherein the first information is gathered from one or more identity providers.

3. The method of claim 1 wherein the first information is gathered from one or more applications of the one or more resources or of the providers.

4. The method of claim 1 further comprising generating a polygraph indicating the one or more shadow systems.

5. The method of claim 1 further comprising generating an alert in response to identifying the one or more shadow systems.

6. The method of claim 1 further comprising directing the user to a remediation workflow in response to identifying the one or more shadow systems.

7. The method of claim 1 wherein the first information is not gathered from the one or more user devices.

8. The method of claim 1 wherein the second information is gathered via the one or more client applications including one or more proxy applications executed on the at least a subset of the one or more user devices.

9. A non-transitory computer readable storage medium storing instructions which, when executed, cause a processing device to:

gather, from one or more resources or providers of the one or more resources, first information describing access to the one or more resources by one or more user devices of a user;

gather, from one or more client applications of at least a subset of the one or more user devices, second information describing access to the one or more resources; and

identify one or more shadow systems based on a discrepancy between the first information and the second information, wherein the one or more shadow systems comprise one or more of the at least a subset of the one or more user devices engaging in shadow information technology (IT) activity, wherein identifying the one or more shadow systems comprises identifying one or more accesses described in the first information but not described in the second information and identifying, as one or more shadow systems, one or more user devices corresponding to the one or more accesses.

10. The non-transitory computer readable storage medium of claim 9 wherein the first information is gathered from one or more identity providers.

11. The non-transitory computer readable storage medium of claim 9 wherein the first information is gathered from one or more applications of the one or more resources or providers.

12. The non-transitory computer readable storage medium of claim 9 further comprising generating a polygraph indicating the one or more shadow systems.

13. The non-transitory computer readable storage medium of claim 9 wherein the instructions, when executed, further cause the processing device to generate an alert in response to identifying the one or more shadow systems.

14. The non-transitory computer readable storage medium of claim 9 wherein the instructions, when executed, further cause the processing device to direct the user to a remediation workflow in response to identifying the one or more shadow systems.

15. The non-transitory computer readable storage medium of claim 9 wherein the first information is gathered from the one or more resources or the providers of the one or more resources other than the one or more user devices.

16. The non-transitory computer readable storage medium of claim 9 wherein the second information is gathered via one or more proxy applications executed on the at least a subset of the one or more user devices.

17. A system comprising:

a memory; and

a processing device, operatively coupled to the memory, the processing device configured to:

gather, from one or more resources or providers of the one or more resources, first information describing access to the one or more resources by one or more user devices of a user;

gather, from one or more client applications of at least a subset of the one or more user devices, second information describing access to the one or more resources; and

identify one or more shadow systems based on a discrepancy between the first information and the second information, wherein the one or more shadow systems comprise one or more of the at least a subset of the one or more user devices engaging in shadow information technology (IT) activity, wherein identifying the one or more shadow systems comprises identifying one or more accesses described in the first information but not described in the second information and identifying, as one or more shadow systems, one or more user devices corresponding to the one or more accesses.

18. The system of claim 17 wherein the first information is gathered from one or more identity providers.

19. The system of claim 17 wherein the first information is gathered from one or more applications of the one or more resources or the providers of the one or more resources.

20. The system of claim 17 wherein the processing device is further configured to generate a polygraph indicating the one or more shadow systems.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2024
From: LACEWORK, INC.
To: FORTINET, INC.
Reel/Frame 069888/0611 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 6, 2022
From: KAPOOR, VIKRAM; SINGH, HARISH KUMAR BHARAT; ZENG, WEIFEI; JEYAKUMAR, VIMALKUMAR; TOCK, THERON; XIE, YING; CHEN, YIJOU
To: LACEWORK, INC.
Reel/Frame 060415/0986 →
Cited By (1)
US 12,706,953