IP Library Granted Patent US 12,021,888
Granted Patent B1
US 12,021,888 · App. 18/416,350 · Granted Jun 25, 2024

Cloud infrastructure entitlement management by a data platform

Inventors: Theodore M. Reed (Berkeley Heights, NJ); Bao Nguyen (Newcastle, WA); Kenneth Beasley (Herndon, VA); Joshua L. Vertes (Venice, CA); Adin Aoki (Union, KY); Brandon Maister (New York, NY); Ravi Kiran Kumar (Pleasanton, CA); Sowmya A Karmali (Tustin, CA); Yijou Chen (Cupertino, CA)
Assignee: Lacework, Inc.
H04L63/1425G06F9/455G06F9/545G06F16/9024G06F16/9038G06F16/9535G06F16/9537G06F21/57H04L43/045H04L43/06H04L63/10H04L67/306H04L67/535G06F16/2456
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,021,888
App. No.
18/416,350
Filed
Jan 18, 2024
Granted
Jun 25, 2024
Kind
B1
Art Unit
2493
USPC
707/770
Abstract

An illustrative method includes accessing data representative of a first role associated with a set of permissions with respect to resources within the compute environment and specifying a group of identities assigned to the first role, determining that a first subgroup of one or more identities included the group of identities only uses a first subset of permissions included in the set of permissions to access the resources within the compute environment without using a second subset of permissions, and performing, based on the determining that the first subgroup of one or more identities only uses the first subset of permissions, an operation to reduce permissions usable by the one or more identities.

Claims (37)

1. A method comprising:

accessing, by a data platform configured to monitor a compute environment, data representative of a first role associated with a set of permissions with respect to resources within the compute environment and specifying a group of identities assigned to the first role, wherein the first role is assumable by each identity included in the group of identities to access the resources in accordance with the set of permissions;

determining, by the data platform, that a first subgroup of one or more identities included in the group of identities only uses a first subset of permissions included in the set of permissions to access the resources within the compute environment without using a second subset of permissions included in the set of permissions to access the resources within the compute environment;

determining, by the data platform, that a second subgroup of one or more identities included in the group of identities only uses the second subset of permissions without using the first subset to access the resources within the compute environment; and

performing, by the data platform based on the determining that the first subgroup of one or more identities only uses the first subset of permissions and that the second subgroup of one or more identities only uses the second subset of permissions, an operation to reduce permissions usable by the first and second subgroups of one or more identities, the operation comprising splitting the first role into a second role assigned to the first subgroup of one or more identities and a third role assigned to the second subgroup of one or more identities.

2. The method of claim 1 , wherein the determining the first subgroup of one or more identities comprises:

monitoring each identity included in the group of identities over a predetermined time period; and

determining, based on the monitoring, permissions used by each identity included in the group of identities during the predetermined time period.

3. The method of claim 2 , wherein the determining the first subgroup of one or more identities further comprises grouping one or more identities that only use the first subset of permissions without using the second subset of permissions into the first subgroup of one or more identities.

4. The method of claim 1 , wherein the determining the first subgroup of one or more identities comprises:

monitoring each permission included in the set of permissions over a predetermined time period; and

determining, based on the monitoring, identities using each permission during the predetermined time period.

5. The method of claim 4 , wherein the determining the first subgroup of one or more identities further comprises determining the first subset of permissions only used by one or more common identities without using the second subset of permissions and grouping the one or more common identities into the first subgroup of one or more identities.

6. The method of claim 1 , wherein the data representative of the first role is collected by an agent configuration configured to collect runtime workload data associated with one or more workloads deployed within the compute environment.

7. The method of claim 6 , further comprising:

constructing, by the data platform and based on the runtime workload data, a graph comprising a plurality of nodes connected by a plurality of edges, wherein each node of the plurality of nodes represents a logical entity associated with the runtime workload data and each edge of the plurality of edges represents a behavioral relationship between nodes connected by the edge;

wherein the determining the first subgroup of one or more identities is based on the graph.

8. The method of claim 1 , wherein the data representative of the first role is collected by an agentless workload scanning configuration configured to collect non-runtime workload data associated with one or more workloads deployed within the compute environment.

9. The method of claim 1 , wherein the performing the operation comprises removing the first subgroup of one or more identities from being assigned to the first role.

10. The method of claim 9 , wherein the removing the first subgroup of one or more identities from being assigned to the first role includes providing an exception that allows a particular identity included in the first subgroup of one or more identities to remain assigned to the first role.

11. The method of claim 10 , wherein the exception is based on a user input designating the exception.

12. The method of claim 1 , wherein the performing the operation comprises providing a recommendation to remove the first subgroup of one or more identities from being assigned to the first role.

13. The method of claim 12 , wherein the recommendation further includes generating the second role associated with the first subset of permissions and assigning to the first subgroup of one or more identities to the second role.

14. The method of claim 1 , wherein the performing the operation comprises one or both of removing the second subset of permissions from the set of permissions or providing a recommendation to remove the second subset of permissions from the set of permissions.

15. The method of claim 1 , wherein the performing the operation comprises one or both of removing the first role or providing a recommendation to remove the first role.

16. A system comprising:

a memory storing instructions; and

one or more processors communicatively coupled to the memory and configured to execute the instructions to perform a process comprising:

accessing data representative of a first role associated with a set of permissions with respect to resources within a compute environment and specifying a plurality of identities assigned to the first role, wherein the first role is assumable by each identity included in a group of identities to access the resources in accordance with the set of permissions;

determining that a first subgroup of one or more identities included in the group of identities only uses a first subset of permissions included in the set of permissions to access the resources within the compute environment without using a second subset of permissions included in the set of permissions to access the resources within the compute environment;

determining that a second subgroup of one or more identities included in the group of identities only uses the second subset of permissions without using the first subset to access the resources within the compute environment; and

performing, based on the determining that the first subgroup of one or more identities only uses the first subset of permissions and that the second subgroup of one or more identities only uses the second subset of permissions, an operation to reduce permissions usable by the first and second subgroups of one or more identities, the operation comprising splitting the first role into a second role assigned to the first subgroup of one or more identities and a third role assigned to the second subgroup of one or more identities.

17. A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

accessing data representative of a first role associated with a set of permissions with respect to resources within a compute environment and specifying a plurality of identities assigned to the first role, wherein the first role is assumable by each identity included in a group of identities to access the resources in accordance with the set of permissions;

determining that a first subgroup of one or more identities included in the group of identities only uses a first subset of permissions included in the set of permissions to access the resources within the compute environment without using a second subset of permissions included in the set of permissions to access the resources within the compute environment;

determining that a second subgroup of one or more identities included in the group of identities only uses the second subset of permissions without using the first subset to access the resources within the compute environment; and

performing, based on the determining that the first subgroup of one or more identities only uses the first subset of permissions and that the second subgroup of one or more identities only uses the second subset of permissions, an operation to reduce permissions usable by the first and second subgroups of one or more identities, the operation comprising splitting the first role into a second role assigned to the first subgroup of one or more identities and a third role assigned to the second subgroup of one or more identities.

Assignments (2)
MERGER Recorded Oct 7, 2024
From: LACEWORK, INC.
To: FORTINET, INC.
Reel/Frame 069269/0377 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2024
From: REED, THEODORE M.; NGUYEN, BAO; BEASLEY, KENNETH; VERTES, JOSHUA L.; AOKI, ADIN; MAISTER, BRANDON; KUMAR, RAVI KIRAN; KARMALI, SOWMYA A.; CHEN, YIJOU
To: LACEWORK, INC.
Reel/Frame 066178/0167 →
Continuity (9)
Continuation In Part 18517747 · Nov 22, 2023
Continuation 18119045 · Mar 8, 2023
Continuation 17510179 · Oct 25, 2021
Continuation 16786822 · Feb 10, 2020
Continuation 16134806 · Sep 18, 2018
Provisional Application 63532955 · Aug 16, 2023
Provisional Application 63440544 · Jan 23, 2023
Provisional Application 62650971 · Mar 30, 2018
Provisional Application 62590986 · Nov 27, 2017
Cited By (28)
US 12,292,991 US 12,417,822 US 12,445,474 US 12,470,565 US 12,488,138 US 12,493,473 US 12,493,540 US 12,493,829 US 12,511,458 US 12,547,680 US 12,547,681 US 12,579,298 US 12,580,936 US 12,592,928 US 12,592,934 US 12,608,732 US 12,621,288 US 12,634,213 US 12,634,350 US 12,652,287 US 12,682,101 US 12,682,296 US 12,688,263 US 12,694,125 US 12,694,147 US 12,699,639 US 12,711,263 US 12,712,727