IP Library Granted Patent US 11,777,948
Granted Patent B2
US 11,777,948 · App. 17/184,203 · Granted Oct 3, 2023

System and method of managing privilege escalation in cloud computing environments

Inventors: Anuraag Agarwwal (Jersey City, NJ); Irwin Emmanuel Dathala (Bayonne, NJ)
Assignee: CLOUD SECURE LABS LLC
H04L63/105H04L63/102H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,777,948
App. No.
17/184,203
Granted
Oct 3, 2023
Kind
B2
Abstract

Systems and methods of identifying over-privileged access in a computing system are disclosed. The method includes receiving configuration information for the computing system, selecting an identity that can access the computing system and determining access privileges for the selected identity using at least the received configuration information, the access privileges identifying one or more computing resource or service accessible to the selected identity, determining at least one role assumable by the identified one or more computing resource or service accessible to the selected identity, and determining whether the identified one or more computing resource or service accessible to the selected identity can elevate its privileges. In a case where it is determined that the identified one or more computing resource or service accessible to the selected identity can elevate its privileges, the method provides notification that the identity has over-privileged access to the computing system.

Claims (35)

1. A processor-executable method of identifying over-privileged access for a selected identity in a computing system, the method comprising:

receiving configuration information for the computing system;

determining access privileges to the computing system for the selected identity using at least the received configuration information, the access privileges identifying one or more computing resource or service accessible to the selected identity;

determining at least one role assumable by the identified one or more computing resource or service accessible to the selected identity;

determining whether the identified one or more computing resource or service accessible to the selected identity can elevate its privileges by (a) adding a new role assumable by the identified one or more computing resource or service, or (b) modifying the determined at least one role to access an additional resource or service, or both (a) and (b);

simulating access granted to the selected identity by the added new role or the modified at least one role to identify over-privileged access for the selected identity; and

in a case where it is determined that the identified one or more computing resource or service accessible to the selected identity can elevate its privileges, providing notification of the identified over-privileged access to the computing system.

2. The method according to claim 1 , wherein the computing system is a cloud computing system.

3. The method according to claim 1 , wherein the configuration information includes at least one of access privileges for one or more identities that can access the computing system, and information on roles that can be assumed by the computing resource or service.

4. The method according to claim 1 , wherein the selected identity includes a role, a user, or a group.

5. The method according to claim 1 , wherein the selected identity can elevate its privileges by adding a new role assumable by the identified one or more computing resource or service based on the access privileges for the selected identity or configuration information associated with the identified one or more computing resource or service.

6. The method according to claim 1 , wherein the selected identity can elevate its privileges by modifying the determined at least one role to access an additional resource or service based on the access privileges for the selected identity or configuration information associated with the identified one or more computing resource or service.

7. The method according to claim 1 , wherein the notification includes information on the new role assumable by the identified one or more computing resource or service, or the additional resource or service accessible by the selected identity based on its elevated access privileges.

8. An identity and access management system that identifies over-privileged access for a selected identity in a computing system, the identity and access management system comprising:

at least one memory configured to store instructions; and

at least one processor communicatively connected to the at least one memory and configured to execute the stored instructions to:

receive configuration information for the computing system;

determine access privileges to the computing system for the selected identity using at least the received configuration information, the access privileges identifying one or more computing resource or service accessible to the selected identity;

determine at least one role assumable by the identified one or more computing resource or service accessible to the selected identity;

determine whether the identified one or more computing resource or service accessible to the selected identity can elevate its privileges by (a) adding a new role assumable by the identified one or more computing resource or service, or (b) modifying the determined at least one role to access an additional resource or service, or both (a) and (b);

simulate access granted to the selected identity by the added new role or the modified at least one role to identify over-privileged access for the selected identity; and

in a case where it is determined that the identified one or more computing resource or service accessible to the selected identity can elevate its privileges, provide notification of the identified over-privileged access to the computing system.

9. The system according to claim 8 , wherein the computing system is a cloud computing system.

10. The system according to claim 8 , wherein the configuration information includes at least one of access privileges for one or more identities that can access the computing system, and information on roles that can be assumed by the computing resource or service.

11. The system according to claim 8 , wherein the selected identity includes a role, a user, or a group.

12. The system according to claim 8 , wherein the selected identity can elevate its privileges by adding a new role assumable by the identified one or more computing resource or service based on the access privileges for the selected identity or configuration information associated with the identified one or more computing resource or service.

13. The system according to claim 8 , wherein the selected identity can elevate its privileges by modifying the determined at least one role to access an additional resource or service based on the access privileges for the selected identity or configuration information associated with the identified one or more computing resource or service.

14. The system according to claim 8 , wherein the notification includes information on the new role assumable by the identified one or more computing resource or service, or the additional resource or service accessible by the selected identity based on its elevated access privileges.

15. A non-transitory computer readable storage medium storing a program executable by a processor to perform a method of identifying over-privileged access for a selected identity in a computing system, the method comprising:

receiving configuration information for the computing system;

determining access privileges to the computing system for the selected identity using at least the received configuration information, the access privileges identifying one or more computing resource or service accessible to the selected identity;

determining at least one role assumable by the identified one or more computing resource or service accessible to the selected identity;

determining whether the identified one or more computing resource or service accessible to the selected identity can elevate its privileges by (a) adding a new role assumable by the identified one or more computing resource or service, or (b) modifying the determined at least one role to access an additional resource or service, or both (a) and (b);

simulating access granted to the selected identity by the added new role or the modified at least one role to identify over-privileged access for the selected identity; and

in a case where it is determined that the identified one or more computing resource or service accessible to the selected identity can elevate its privileges, providing notification of the identified over-privileged access to the computing system.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 9, 2024
From: CLOUD SECURE LABS LLC
To: THREATMODELER SOFTWARE INC.
Reel/Frame 068843/0197 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 1, 2021
From: THREATMODELER SOFTWARE INC.
To: CLOUD SECURE LABS LLC
Reel/Frame 057666/0643 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2021
From: AGARWWAL, ANURAAG; DATHALA, IRWIN EMMANUEL
To: THREATMODELER SOFTWARE INC.
Reel/Frame 055395/0092 →
Continuity (2)
Continuation 17137884 · Dec 30, 2020
Related Publication 20220210162A1 · Jun 30, 2022
Cited By (2)
US 12,574,382 US 12,634,310