IP Library Patent Application 18251819
Patent Application
App. No. 18/251,819

Agentless User Session Management for Remote Servers

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/251,819
Abstract

An orchestrator performs user session management of bare metal servers that lack an agent cooperating with the orchestrator. Log data is pulled from the servers, such as using a vector agent. The log data is processed to obtainer user session records (e.g., PID, username, start time, and end time). The user session records are processed to detect malicious or suspicious activity or violations of policies. The orchestrator may invoke performance of a workflow to perform session management actions such as blocking, limiting, or logging off users. The workflow executes remote from the server and may communicate instructions to the server through a secure command line interface.

Claims (34)

1 . A method comprising:

receiving, by a first computer system, log data from a remote server connected to the first computer system by a network;

processing, by the first computer system, the log data to obtain a record of a user session conducted on the server; and

invoking, by the first computer system, execution of a workflow to manage the user session on the server, the workflow not being executed on the server.

2 . The method of claim 1 , further comprising:

evaluating, by the first computer system, the record of the user session; and

determining, by the first computer system, in response to the evaluating, that an action should be taken with respect to the user session;

wherein invoking execution of the workflow is performed in response to determining that the action should be taken with respect to the user session.

3 . The method of claim 2 , wherein the action comprises ending the user session.

4 . The method of claim 2 , wherein the action comprises preventing future logins using a username associated with the user session.

5 . The method of claim 2 , wherein the action comprises limiting access associated with a username associated with the user session.

6 . The method of claim 1 , wherein processing, by the first computer system, the log data to obtain the record of the user session comprises obtaining a process identifier (PID) of a user session process from the log data.

7 . The method of claim 6 , wherein processing, by the first computer system, the log data to obtain the record of the user session comprises obtaining a start time, end time, and username associated with the PID.

8 . The method of claim 1 , wherein invoking execution of the workflow comprises selecting a worker from a worker pool and instructing the worker to execute the workflow.

9 . The method of claim 1 , wherein execution of the workflow includes establishing a secure command line interface to the server and transmitting instructions through the secure command line interface.

10 . The method of claim 9 , wherein the secure command line interface includes a secure shell (SSH) connection to the server.

11 . A system comprising:

a computing device including one or more processing devices and one or more memory devices operably coupled to the one or more processing devices, the one or more memory devices storing executable code that, when executed by the one or more processing devices, causes the one or more processing devices to:

receive log data from a remote server connected to the computing device by a network;

process the log data to obtain a record of a user session conducted on the server; and

invoke execution of a workflow to manage the user session on the server, the workflow not being executed on the server.

12 . The system of claim 11 , where the executable code, when executed by the one or more processing devices, further causes the one or more processing devices to:

evaluate the record of the user session;

determine, in response to the evaluating, that an action should be taken with respect to the user session; and

invoke execution of the workflow in response to determining that the action should be taken with respect to the user session.

13 . The system of claim 12 , wherein the action comprises ending the user session.

14 . The system of claim 12 , wherein the action comprises preventing future logins using a username associated with the user session.

15 . The system of claim 12 , wherein the action comprises limiting access associated with a username associated with the user session.

16 . The system of claim 11 , wherein the executable code, when executed by the one or more processing devices, further causes the one or more processing devices to process the log data to obtain the record of the user session by obtaining a process identifier (PID) of a user session process from the log data.

17 . The system of claim 16 , wherein the executable code, when executed by the one or more processing devices, further causes the one or more processing devices to process the log data to obtain the record of the user session by obtaining a start time, end time, and username associated with the PID.

18 . The system of claim 11 , where the executable code, when executed by the one or more processing devices, further causes the one or more processing devices to: invoke execution of the workflow by selecting a worker from a worker pool and instructing the worker to execute the workflow.

19 . The system of claim 11 , where the executable code, when executed by the one or more processing devices, further causes the one or more processing devices to:

execute the workflow by establishing a secure command line interface to the server and transmitting instructions through the secure command line interface.

20 . The system of claim 19 , wherein the secure command line interface includes a secure shell (SSH) connection to the server.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2024
From: ROBIN SYSTEMS, INC.
To: RAKUTEN SYMPHONY, INC.
Reel/Frame 068193/0367 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2023
From: ATUR, SREE NANDAN; PHISAKE, ADITYA
To: ROBIN SYSTEMS, INC
Reel/Frame 063540/0572 →