IP Library Granted Patent US 12,289,346
Granted Patent B2
US 12,289,346 · App. 18/666,650 · Granted Apr 29, 2025

Using cached summaries for efficient access analysis for cloud provider entities

Inventors: Matthew Gladney (Boston, MA); Elizabeth Prescott (Fairfax, VA); Niluka Bamunuarachchige (Centreville, VA); Leonardo Colmenares (Washington, DC); James Martin (Washington, DC); Peter Snelgrove (Annandale, VA); Nadia Mounzih (Washington, DC)
Assignee: Rapid7, Inc.
H04L63/20G06F16/322H04L63/104H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,289,346
App. No.
18/666,650
Granted
Apr 29, 2025
Kind
B2
Abstract

An access policy analysis system may use stored policy summaries to efficiently perform access analysis. A request that causes an access analysis of an entity in a cloud service provider with respect to a resource hosted in the cloud service provider may be received. An access policy summary generated for the entity based on a set of access policies applied by an access management system of the cloud service provider may be obtained. An access policy summary generated for the resource based on the set of access policies may be obtained. A tree structure that describes a hierarchy of entities in the cloud service provider may be traversed to identify a parent node of the entity in the hierarchy of entities. The access analysis may then be generated based on the access policy summaries for the identified node in the tree structure, for the entity and for the resource.

Claims (60)

1. A system for access policy analysis, the system comprising:

one or more hardware processors; and

one or more non-transitory computer-readable storage media storing instructions, that when executed by the one or more hardware processors, cause the one or more hardware processors to perform:

receiving an electronic request that causes an access analysis of an entity in a cloud service provider with respect to a resource hosted by the cloud service provider; and

responsive to receiving the electronic request:

obtaining a first electronic access policy summary generated for the entity based on a set of access policies applied by an access management system of the cloud service provider;

obtaining a second electronic access policy summary generated for the resource based on the set of access policies applied by the access management system;

identifying, in a tree structure that describes a hierarchy of entities in the cloud service provider, a parent node of a node representing the entity in the hierarchy of entities;

obtaining a third electronic access policy summary for the parent node; and

generating the access analysis of the entity in the cloud service provider based on the third electronic access policy summary for the identified parent node in the tree structure, the first electronic access policy summary generated for the entity and the second electronic access policy summary generated for the resource.

2. The system of claim 1 , wherein identifying the parent node comprises:

identifying a root entity node in the tree structure;

adding an access policy summary for the root entity node to an analysis set of access policy summaries used to generate the access analysis; and

for one or more other entity nodes in the tree structure determined to be in a path to the entity in the hierarchy of entities, adding respective access policy summaries for the one or more other entity nodes.

3. The system of claim 2 , wherein the one or more non-transitory computer-readable storage media storing instructions store further instructions that, when executed, cause the one or more hardware processors to perform:

for one of the root entity node or the one or more other entity nodes:

evaluating one or more access policies determined to be evaluated for the one entity node; and

updating the access policy summary for the one entity node according to the evaluating before adding the access policy summary to the analysis set of access policy summaries.

4. The system of claim 1 , wherein generating the access analysis of the entity in the cloud service provider based on the third electronic access policy summary for the identified parent node, the first electronic access policy summary generated for the entity and the second electronic access policy summary generated for the resource, comprises: evaluating one or more policy conditions included in one of the access policy summaries.

5. The system of claim 1 , wherein the tree structure that describes the hierarchy of entities in the cloud service provider is generated as part of an ingestion process before receiving the electronic request.

6. The system of claim 1 , wherein obtaining the first electronic access policy summary generated for the entity based on the set of access policies applied by the access management system comprises: generating the first electronic access policy summary from one or more access policies of the set of access policies that are associated with the entity.

7. The system of claim 1 , wherein obtaining the second electronic access policy summary generated for the resource based on the set of access policies applied by the access management system comprises: generating the second electronic access policy summary from one or more access policies of the set of access policies that are associated with the resource.

8. The system of claim 1 , wherein the access management system is implemented as part of a cloud security service, wherein the electronic request that causes the access analysis of the entity in the cloud service provider is received via a user interface of the cloud security service and wherein the access management system is further configured to return the access analysis via the user interface in response to the electronic request.

9. A method for access policy analysis, the method comprising:

using one or more one or more hardware processors to perform:

receiving an electronic request that causes an access analysis of an entity in a cloud service provider with respect to a resource hosted by the cloud service provider; and

responsive to receiving the electronic request:

obtaining a first electronic access policy summary generated for the entity based on a set of access policies applied by an access management system of the cloud service provider;

obtaining a second electronic access policy summary generated for the resource based on the set of access policies applied by the access management system;

identifying, in a tree structure that describes a hierarchy of entities in the cloud service provider, a parent node of a node representing the entity in the hierarchy of entities;

obtaining a third electronic access policy summary for the parent node; and

generating the access analysis of the entity in the cloud service provider based on the third electronic access policy summary for the identified parent node in the tree structure, the first electronic access policy summary generated for the entity and the second electronic access policy summary generated for the resource.

10. The method of claim 9 , wherein identifying the parent node comprises:

identifying a root entity node in the tree structure;

adding an access policy summary for the root entity node to an analysis set of access policy summaries used to generate the access analysis; and

for one or more other entity nodes in the tree structure determined to be in a path to the entity in the hierarchy of entities, adding respective access policy summaries for the one or more other entity nodes.

11. The method of claim 10 , further comprising:

for one of the root entity node or the one or more other entity nodes:

evaluating one or more access policies determined to be evaluated for the one entity node; and

updating the access policy summary for the one entity node according to the evaluating before adding the access policy summary to the analysis set of access policy summaries.

12. The method of claim 9 , wherein generating the access analysis of the entity in the cloud service provider based on the respective access policy summary for the identified parent node in the tree structure, the access policy summary generated for the entity and the access policy summary generated for the resource, comprises evaluating one or more policy conditions included in one of the access policy summaries.

13. The method of claim 9 , wherein the tree structure that describes the hierarchy of entities in the cloud service provider is generated as part of an ingestion process before receiving the electronic request.

14. The method of claim 9 , wherein obtaining the first electronic access policy summary generated for the entity based on the set of access policies applied by the access management system comprises generating the first electronic access policy summary from one or more access policies of the set of access policies that are associated with the entity.

15. The method of claim 9 , wherein the access management system is implemented as part of a cloud security service, wherein the electronic request that causes the access analysis of the entity in the cloud service provider is received via a user interface of the cloud security service and wherein the method further comprises returning the access analysis via the user interface in response to the electronic request.

16. One or more non-transitory computer-accessible storage media storing program instructions that, when executed by at least one computer hardware processor, causes the at least one computer hardware processor to perform a method for access policy analysis, the method comprising:

receiving an electronic request that causes an access analysis of an entity in a cloud service provider with respect to a resource hosted by the cloud service provider; and

responsive to receiving the electronic request:

obtaining a first electronic access policy summary generated for the entity based on a set of access policies applied by an access management system of the cloud service provider;

obtaining a second electronic access policy summary generated for the resource based on the set of access policies applied by the access management system;

identifying, in a tree structure that describes a hierarchy of entities in the cloud service provider, a parent node of a node representing the entity in the hierarchy of entities;

obtaining a third electronic access policy summary for the parent node; and

generating the access analysis of the entity in the cloud service provider based on the third electronic access policy summary for the identified parent node in the tree structure, the first electronic access policy summary generated for the entity and the second electronic access policy summary generated for the resource.

17. The one or more non-transitory computer-accessible storage media of claim 16 , wherein identifying the parent node comprises:

identifying a root entity node in the tree structure;

adding an access policy summary for the root entity node to an analysis set of access policy summaries used to generate the access analysis; and

for one or more other entity nodes in the tree structure determined to be in a path to the entity in the hierarchy of entities, adding respective access policy summaries for the one or more other entity nodes.

18. The one or more non-transitory computer-accessible storage media of claim 16 , wherein, in generating the access analysis of the entity in the cloud service provider based on the respective access policy summary for the identified parent node in the tree structure, the access policy summary generated for the entity and the access policy summary generated for the resource, the program instructions further cause the at least one computer hardware processor to perform:

evaluating one or more policy conditions included in one of the access policy summaries.

19. The one or more non-transitory computer-accessible storage media of claim 16 , wherein, in obtaining the first electronic access policy summary generated for the entity based on the set of access policies applied by the access management system, the program instructions further cause the at least one computer hardware processor to perform: generating the first electronic access policy summary from one or more access policies of the set of access policies that are associated with the entity.

20. The one or more non-transitory computer-accessible storage media of claim 16 , wherein the access management system is implemented as part of a cloud security service, wherein the electronic request that causes the access analysis of the entity in the cloud service provider is received via a user interface of the cloud security service and wherein the one or more non-transitory computer-accessible storage media store further program instructions that when executed on or across one or more processors further cause the at least one computer hardware processor to perform: returning the access analysis via the user interface in response to the electronic request.

Assignments (3)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNOR EXECUTION DATE PREVIOUSLY RECORDED ON REEL 70505 FRAME 81. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 14, 2025
From: GLADNEY, MATTHEW; PRESCOTT, ELIZABETH; BAMUNUARACHCHIGE, NILUKA; COLMENARES, LEONARDO; MARTIN, JAMES; SNELGROVE, PETER; MOUNZIH, NADIA
To: RAPID7, INC.
Reel/Frame 071572/0714 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2025
From: GLADNEY, MATTHEW; PRESCOTT, ELIZABETH; BAMUNUARACHCHIGE, NILUKA; COLMENARES, LEONARDO; MARTIN, JAMES; SNELGROVE, PETER; MOUNZIH, NADIA
To: RAPID7, INC.
Reel/Frame 070505/0081 →
Continuity (2)
Continuation 17543599 · Dec 6, 2021
Related Publication 20240305670A1 · Sep 12, 2024
References Cited (29)
US 6202066B1 · Barkley et al. · 2001 [cited by applicant]
US 9218502B1 · Doermann et al. · 2015 [cited by applicant]
US 9516028B1 · Andruschuk et al. · 2016 [cited by applicant]
US 10129344B2 · Pogrebinsky et al. · 2018 [cited by applicant]
US 10880189B2 · Martinez et al. · 2020 [cited by applicant]
US 12021900B1 · Gladney · 2024 [cited by examiner]
US 20050262132A1 · Morita et al. · 2005 [cited by applicant]
US 20080104393A1 · Glasser et al. · 2008 [cited by applicant]
US 20110131275A1 · Maida-Smith et al. · 2011 [cited by applicant]
US 20130219156A1 · Sears · 2013 [cited by applicant]
US 20130290500A1 · Narendra et al. · 2013 [cited by applicant]
US 20140280961A1 · Martinez et al. · 2014 [cited by applicant]
US 20170054757A1 · Siswick et al. · 2017 [cited by applicant]
US 20170141961A1 · Cao et al. · 2017 [cited by applicant]
US 20180091583A1 · Collins et al. · 2018 [cited by applicant]
US 20180268347A1 · Benedetti et al. · 2018 [cited by applicant]
US 20190121989A1 · Mousseau et al. · 2019 [cited by applicant]
US 20190327271A1 · Saxena et al. · 2019 [cited by applicant]
US 20200225655A1 · Cella et al. · 2020 [cited by applicant]
US 20220156631A1 · Kanso et al. · 2022 [cited by applicant]
US 20220210201A1 · Kastroulis · 2022 [cited by applicant]
US 20220263835A1 · Pieczul et al. · 2022 [cited by applicant]
US 20220353289A1 · Witschey et al. · 2022 [cited by applicant]
US 20230019705A1 · Zettel, II et al. · 2023 [cited by applicant]
US 20230090828A1 · Patro et al. · 2023 [cited by applicant]
US 20230148158A1 · Bandarupalli et al. · 2023 [cited by applicant]
CN 102307185A · 2012 [cited by applicant]
KR 20030057263A · 2003 [cited by applicant]
Majumdar et al., Security compliance auditing of identity and access management in the cloud: Application to OpenStack. 2015 IEEE 7th International Conference on Cloud Computing Technology and Science (CloudCom). Nov. 3… [cited by applicant]