IP Library Granted Patent US 10,230,734
Granted Patent B2
US 10,230,734 · App. 14/962,211 · Granted Mar 12, 2019

Usage-based modification of user privileges

Inventors: Jake Seigel (Halifax, CA); Robert MacIntosh (Halifax, CA)
Assignee: QUEST SOFTWARE INC.
H04L63/102H04L63/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,230,734
App. No.
14/962,211
Filed
Dec 8, 2015
Granted
Mar 12, 2019
Kind
B2
Art Unit
2492
USPC
726/4
Abstract

Systems and techniques to identify and modify unused (or seldom used) access privileges are described. Group membership data may be correlated with access map data to create a user-resource access map identifying privilege levels associated with individual user accounts to access computing resources in a computing system. User activity event logs generated as a result of user accounts accessing the resources may be correlated with the user-resource access map to identify user accounts that do not use (or seldom use) particular privilege levels to access particular resources. The identified user accounts may be modified to remove the unused (or seldom used) privileges levels.

Claims (66)

1. A computer-implemented method, comprising:

correlating:

group membership data including a plurality of user accounts that includes at least a first user account belonging to a first group and a second group, and a second user account belonging to a third group; and

access map data identifying a first privilege level associated with the first group that is used to access a first resource, a second privilege level associated with the second group that is used to access the second resource, and a third privilege level associated with the third group that is used to access the first resource;

creating a user-resource access map identifying particular privilege levels corresponding to individual user accounts of the plurality of user accounts to access one or more computer-rooted resources including the first resource and the second resource;

determining a set of user activity event logs associated with one or more of the plurality of accounts accessing the one or more computer-rooted resources within a predetermined time period;

correlating the set of user activity event logs with the user-resource access map;

determining that the first user account did not use the first privilege level to access the first resource above a threshold percentage of time;

determining that the first user account used the second privilege level to access the second resource above a threshold percentage of time;

determining that removing the first privilege level from the first user account will not modify membership of the first user account in at least the second group; and

modifying the first user account to remove the first privilege level based on a determination that removing the first privilege level from the user account will not modify membership of the first user account in at least the second group.

2. The computer-implemented method of claim 1 , wherein the one or more computer-rooted resources include at least one of a database, a server, a user workstation, an email system, a directory, or a file.

3. The computer-implemented method of claim 1 , wherein the first privilege level comprises write access.

4. The computer-implemented method of claim 1 , wherein the second privilege level comprises read access.

5. The computer-implemented method of claim 1 , wherein an individual activity event log of the set of user activity event logs identifies:

a particular user account of the plurality of user accounts used to perform an activity;

a particular resource of the one or more computer-rooted resources that was accessed by the particular user account;

a particular privilege level associated with the particular user account that was used to access the particular resource; and

a date and a time at which the access to the particular resource occurred.

6. The computer-implemented method of claim 1 , wherein modifying the first user account to remove the first privilege level comprises:

removing the first user account from the first group.

7. The computer-implemented method of claim 1 , wherein modifying the first user account to remove the first privilege level comprises:

removing the first privilege level from the first group.

8. One or more non-transitory computer-readable media storing instructions that are executable by one or more processors to perform operations comprising:

correlating group membership data including a plurality of user accounts that includes at least a first user account belonging to a first group and a second group, and a second user account belonging to a third group with access map data identifying a first privilege level associated with the first group that is used to access a first resource, a second privilege level associated with the second group that is used to access a second resource, and a third privilege level associated with the third group that is used to access the first resource;

creating a user-resource access map identifying particular privilege levels corresponding to individual user accounts of the plurality of user accounts to access one or more computer-rooted resources including the first resource and the second resource;

retrieving a set of user activity event logs associated with one or more of the plurality of accounts accessing the one or more computer-rooted resources within a predetermined time period;

correlating the set of user activity event logs with the user-resource access map;

determining that the first user account did not use the first privilege level to access the first resource above a threshold percentage of time;

determining that the first user account used the second privilege level to access the second resource above a threshold percentage of time:

determining that removing the first privilege level from the user account will not modify membership of the first user account in at least the second group; and

modifying the first user account to remove the first privilege level based on a determination that removing the first privilege level from the user account will not modify membership of the first user account in at least the second group.

9. The one or more non-transitory computer-readable media of claim 8 , wherein the first privilege level comprises write access.

10. The one or more non-transitory computer-readable media of claim 8 , wherein the second privilege level comprises read access.

11. The one or more non-transitory computer-readable media of claim 8 , wherein an individual activity event log of the set of user activity event logs includes:

a user account identifier associated with a user account that is used to perform an activity,

a resource identifier identifying a resource of the one or more computer-rooted resources that was accessed by the user account,

a privilege level identifier identifying a privilege level used to access the resource, and

a timestamp indicating a date and a time at which the access to the resource occurred.

12. The one or more non-transitory computer-readable media of claim 8 , wherein modifying the first user account to remove the first privilege level comprises:

removing the rust user account from the first group.

13. The one or more non-transitory computer-readable media of claim 8 , wherein modifying the first user account to remove the first privilege level comprises:

removing the first privilege level from the first group.

14. A server, comprising:

one or more processors; and

one or more non-transitory computer-readable media storing instructions that are executable by the one or more processors to:

correlating group membership data including a plurality of user accounts that includes at least a first user account belonging to a first group and a second group, and a second user account belonging to a third group with access map data identifying a first privilege level associated with the first group that is used to access a first resource, a second privilege level associated with the second group that is used to access a second resource, and a third privilege level associated with the third group that is used to access the first resource;

creating a user-resource access map identifying particular privilege levels corresponding to individual user accounts of the plurality of user accounts to access one or more computer-rooted resources including the first resource and the second resource;

retrieving a set of user activity event logs associated with one or more of the plurality of accounts accessing the one or more computer-rooted resources within a predetermined time period;

correlating the set of user activity event logs with the user-resource access map;

determining that the first user account did not use the first privilege level to access the first resource above a threshold percentage of time;

determining that the first user account used the second privilege level to access the second resource above a threshold percentage of time:

determining that removing the first privilege level from the first user account will not modify membership of the first user account in at least the second group; and

removing the first privilege level from the first user account based on a determination that removing the first privilege level from the user account will not modify membership of the first user account in at least the second group.

15. The server of claim 14 , wherein the first privilege level comprises write access.

16. The server of claim 14 , wherein the second privilege level comprises read access.

17. The server of claim 14 , wherein an individual activity event log of the set of user activity event logs includes:

a user account identifier associated with a user account that is used to perform an activity,

a resource identifier identifying a resource of the one or more computer-rooted resources that was accessed by the user account,

a privilege level identifier identifying a privilege level used to access the resource, and

a timestamp indicating a date and a time at which the access to the resource occurred.

18. The server of claim 14 , wherein removing the first privilege level from the first user account comprises:

removing the first user account from the first group.

19. The server of claim 14 , wherein removing the first privilege level from the first user account comprises:

removing the first privilege level from the first group.

20. The server of claim 14 , wherein the one or more computer-rooted resources include at least one a database, a server, a user workstation, an email system, a directory, or a file.

Assignments (27)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY NAME PREVIOUSLY RECORDED ON REEL 037236 FRAME 0222. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT TO DELL SOFTWARE INC.. Recorded Aug 10, 2017
From: SEIGEL, JAKE; MACINTOSH, ROBERT
To: DELL SOFTWARE INC.
Reel/Frame 043514/0783 →
CHANGE OF NAME Recorded Aug 10, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 043514/0804 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
RELEASE OF REEL 037848 FRAME 0210 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040031/0725 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 037848 FRAME 0001 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0152 →
RELEASE OF REEL 037847 FRAME 0843 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040017/0366 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037848/0001 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 037848/0210 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 037847/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2015
From: SEIGEL, JAKE; MACINTOSH, ROBERT
To: DELL SOFTWARE, INC.
Reel/Frame 037236/0222 →
Continuity (1)
Related Publication 20170163650A1 · Jun 8, 2017
Cited By (2)
US 12,574,379 US 12,634,293