IP Library Granted Patent US 11,070,516
Granted Patent B2
US 11,070,516 · App. 16/774,507 · Granted Jul 20, 2021

Directory service state manager

Inventors: Guy Teverovsky (Kefar Sava, IL); Dan Croitoru (Haifa, IL); Matan Liberman (Ramat Gan, IL); Michael Bresman (Hoboken, NJ); Darren Mar-Elia (San Anselmo, CA)
Assignee: Semperis
H04L61/1552H04L61/1523H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,070,516
App. No.
16/774,507
Granted
Jul 20, 2021
Kind
B2
Abstract

Technology for analyzing and tracking states of a directory service by correlating changes from multiple different data sources related to the directory service. A first data source may be based on synchronization data of the directory service and a second data source may be based on security data of one or more domain controllers hosting the directory service. The synchronization data and security data may both correspond to changes to the directory service but may include different information. For example, synchronization data may provide the content of a modification to the directory service and the security data may provide an entity that initiated the modification. The multiple sources may be compared to identify inconsistencies (e.g., detect malicious activity).

Claims (53)

1. A method comprising:

receiving a plurality of change events of a directory service, wherein the plurality of change events comprise synchronization data of the directory service;

accessing a plurality of change events of a computing device, wherein the computing device is associated with the directory service and the plurality of change events of the computing device comprise log data of the computing device;

correlating the synchronization data of the directory service and the log data of the computing device to identify correlated changes;

generating enriched modification data based on the synchronization data of the directory service and the correlated changes; and

detecting an inconsistency of the directory service using the enriched modification data, wherein the detecting comprises identifying a modification of the directory service that is absent a corresponding change event from the computing device.

2. The method of claim 1 , wherein the computing device provides the directory service to a plurality of client devices and the directory service comprises a lightweight directory access protocol (LDAP).

3. The method of claim 1 , wherein the directory service comprises an active directory domain and the computing device comprises a domain controller.

4. The method of claim 1 , further comprising:

determining a state of the directory service at a first time based on change events of the directory service;

determining a state of the directory service at a second time; and

comparing the state of the directory service at the first time with the state of the directory service at the second time, wherein the state at the first time and the state at the second time are different from a current state of the directory service.

5. The method of claim 4 , wherein determining the state of the directory service at the first time comprises determining a state of at least one domain object of the directory service by analyzing a portion of the synchronization data that relates to the domain object, wherein the state of the at least one domain object is different from a current state of the at least one domain object.

6. The method of claim 1 , wherein detecting the inconsistency of the directory service is in response to correlating the synchronization data of the directory service with a subset of the plurality of the change events of the computing device.

7. The method of claim 1 , wherein the plurality of change events of the directory service comprise synchronization packets received from a domain controller providing the directory service and wherein the plurality of change events of the computing device comprise security events from a log of the domain controller.

8. The method of claim 1 , wherein the synchronization data indicates a particular modification to the directory service and the log data comprises security data that indicates an entity initiating the particular modification to the directory service.

9. The method of claim 8 ,

wherein the generating comprises associating a portion of the synchronization data of the directory service with the entity initiating the particular modification to the directory service.

10. The method of claim 1 , wherein correlating the synchronization data and the log data comprises:

performing event aggregation on the plurality of change events of the directory service to produce a first aggregate event comprising the synchronization data;

performing event aggregation on the plurality of change events of the computing device associated with the directory service to produce a second aggregate event comprising the log data; and

detecting a relationship between the first aggregate event and the second aggregate event, wherein the relationship is based on a common feature within the synchronization data and the log data.

11. The method of claim 10 , wherein detecting a relationship between the first aggregate event and the second aggregate event comprises detecting a globally unique identifier (GUID) of the first aggregate event that matches a GUID of the second aggregate event.

12. The method of claim 1 , further comprising:

transmitting to a domain controller a synchronization request comprising a change value;

receiving multiple change events of the directory service with change values exceeding the change value; and

extracting the synchronization data from the multiple change events without applying the synchronization data to an instance of the directory service.

13. A system comprising:

a memory; and

a processing device communicatively coupled to said memory, said processing device configured to:

receive a plurality of change events of a directory service, wherein the plurality of change events comprise synchronization data of the directory service;

access a plurality of change events of a computing device that is associated with the directory service, wherein the plurality of change events of the computing device comprise log data of the computing device;

correlate the synchronization data of the directory service and the log data of the computing device to identify correlated changes;

generate enriched modification data based on the synchronization data of the directory service and the correlated changes; and

detect an inconsistency of the directory service using the enriched modification data, wherein the detecting comprises identifying a modification of the directory service that is absent a corresponding change event from the computing device.

14. The system of claim 13 , wherein the computing device provides the directory service to a plurality of client devices and the directory service comprises a lightweight directory access protocol (LDAP).

15. The system of claim 13 , wherein the directory service comprises an active directory domain and the computing device comprises a domain controller.

16. The system of claim 13 , wherein the processing device is further to:

determine a state of the directory service at a first time based on change events of the directory service;

determining a state of the directory service at a second time; and

compare the state of the directory service at the first time with the state of the directory service at the second time, wherein the state at the first time and the state at the second time are different from a current state of the directory service.

17. A non-transitory computer readable storage medium comprising instructions to cause a processor to:

receive a plurality of change events of a directory service, wherein the plurality of change events comprise synchronization data of the directory service;

access a plurality of change events of a computing device that is associated with the directory service, wherein the plurality of change events of the computing device comprise log data of the computing device;

correlate the synchronization data of the directory service and the log data of the computing device to identify correlated changes;

generate enriched modification data based on the synchronization data of the directory service and the correlated changes; and

detect an inconsistency of the directory service using the enriched modification data, wherein the detecting comprises identifying a modification of the directory service that is absent a corresponding change event from the computing device.

18. The non-transitory computer readable storage medium of claim 17 , wherein the computing device provides the directory service to a plurality of client devices and the directory service comprises a lightweight directory access protocol (LDAP).

19. The non-transitory computer readable storage medium of claim 17 , wherein the directory service comprises an active directory domain and the computing device comprises a domain controller.

20. The non-transitory computer readable storage medium of claim 17 , wherein the processor is further to:

determine a state of the directory service at a first time based on change events of the directory service;

determine a state of the directory service at a second time; and

compare the state of the directory service at the first time with the state of the directory service at the second time, wherein the state at the first time and the state at the second time are different from a current state of the directory service.

Assignments (8)
SUPPLEMENT NO. 3 TO INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 9, 2025
From: SEMPERIS LTD.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 073057/0979 →
SUPPLEMENT NO. 2 TO INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 8, 2025
From: SEMPERIS LTD
To: HERCULES CAPITAL, INC., AS AGENT
Reel/Frame 073061/0392 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NAME OF ASSIGNEE PREVIOUSLY RECORDED ON REEL 51854 FRAME 75. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2025
From: TEVEROVSKY, GUY; CROITORU, DAN; LIBERMAN, MATAN; BRESMAN, MICHAEL; MAR-ELIA, DARREN
To: SEMPERIS TECHNOLOGIES, INC. (US)
Reel/Frame 070497/0436 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY TYPE FROM APPLICATION NO. 11070516 TO PATENT NO. 11070516 PREVIOUSLY RECORDED ON REEL 69852 FRAME 497. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 15, 2025
From: SEMPERIS TECHNOLOGIES INC.
To: SEMPERIS LTD.
Reel/Frame 069928/0926 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 14, 2025
From: SEMPERIS TECHNOLOGIES INC.
To: SEMPERIS LTD.
Reel/Frame 069852/0497 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 23, 2024
From: SEMPERIS INC.
To: HERCULES CAPITAL, INC., AS ADMINISTRATIVE AND COLLATERAL AGENT
Reel/Frame 067203/0725 →
SECURITY INTEREST Recorded Oct 2, 2023
From: SEMPERIS TECHNOLOGIES INC.; SEMPERIS INC.; SEMPERIS GOVERNMENT SOLUTIONS LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 065089/0564 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2020
From: TEVEROVSKY, GUY; CROITORU, DAN; LIBERMAN, MATAN; BRESMAN, MICHAEL; MAR-ELIA, DARREN
To: SEMPERIS
Reel/Frame 051854/0075 →
Continuity (2)
Continuation 15915943 · Mar 8, 2018
Related Publication 20200169529A1 · May 28, 2020