IP Library Granted Patent US 12,335,267
Granted Patent B1
US 12,335,267 · App. 17/669,146 · Granted Jun 17, 2025

Visual exploration for efficient access analysis for cloud provider entities

Inventors: Evan Samek (Washington, DC); Nicholas Tobolski (Arlington, VA); James Martin (Washington, DC); Mohamed Chalal (Oakton, VA); Alireza Abedinzadehvatankhah (Washington, DC); Kris Rivera (Alexandria, VA)
Assignee: Rapid7, Inc.
H04L63/101H04L41/22H04L63/102H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,335,267
App. No.
17/669,146
Granted
Jun 17, 2025
Kind
B1
Abstract

An access policy analysis system may use visual exploration to efficiently perform access analysis. A request to display an effective access of an entity with respect to a resource hosted in a cloud provider may be received via a visual exploration user interface element. An analysis of a set of access policies applied by an access management system to determine an effective access of the entity with respect to the resource may be performed. One or more selectable access policy interface elements may be generated that correspond to one or more access policies of the set of access policies that are used to determine the effective access of the entity with respect to the resource. The one or more selectable access policy interface elements may be included in a display of the visual exploration user interface element along with the determined effective access of the entity with respect to the resource.

Claims (62)

1. A system for analyzing access policies controlling access by one or more entities to one or more cloud computing resources hosted by a cloud service provider, the system comprising:

one or more hardware processors configured to:

receive, via a visual exploration graphical user interface (GUI), a request to display actions that an entity is allowed to perform with respect to a cloud computing resource; and

responsive to receiving the request:

analyze a set of access policies applied by a platform of the cloud service provider to identify, from among the set of access policies, a subset of one or more access policies applicable to the entity and the cloud computing resource;

determine, using the subset of one or more access policies, a first set of one or more actions that the entity is allowed to perform with respect to the cloud computing resource; and

generate, within the visual exploration GUI:

one or more selectable GUI elements corresponding to one or more access policies in the subset of one or more access policies, and

one or more GUI elements corresponding to one or more actions in the first set of one or more actions;

simulate, within the visual exploration GUI, updating a set of controlling policies, the simulating comprising:

receiving input, via at least one of the one or more selectable GUI elements, indicating that at least one of the one or more access policies is to be added to or removed from the set of controlling policies, and

responsive to the input, updating the visual exploration GUI to display a second set of one or more actions that the entity would be allowed to perform with respect to the cloud computing resource if the at least one or more of the one or more access policies were added to or removed from the set of controlling policies, wherein the first set of one or more actions is different from the second set of one or more actions;

configure the platform of the cloud service provider to control access to the one or more cloud computing resources in accordance with an updated set of controlling policies obtained via the addition or removal of the at least one of the one or more access policies to or from the set of controlling policies; and

cause the platform of the cloud service provider to execute one or more security services in accordance with the updated set of controlling policies.

2. The system of claim 1 , wherein the one or more hardware processors are further configured to:

update the visual exploration GUI to display one or more access levels corresponding to the second set of one or more actions.

3. The system of claim 1 , wherein the input indicating that at least one of the one or more access policies is to be added or removed from the set of controlling policies indicates that the at least one of the one or more access policies is to be removed from the set of controlling policies.

4. The system of claim 1 , wherein the one or more selectable GUI elements corresponding to one or more access policies in the subset of access policies are displayed in a policy stack that organizes access policies into one or more policy types, and wherein the one or more policy types are arranged in an order of applicable scope.

5. The system of claim 1 , wherein the cloud computing resource is selected from the group consisting of: a service resource, a system resource, an application resource, a data storage resource, a networking resource, an orchestration resource, and a metrics resource.

6. The system of claim 1 , wherein the one or more hardware processors are further configured to generate, within the visual exploration GUI: one or more actions, and one or more GUI elements corresponding to one or more access levels associated with the one or more actions in the first set of one or more actions.

7. The system of claim 1 , wherein the visual exploration GUI is implemented as part of a user interface of a cloud security service.

8. A method for analyzing access policies controlling access by one or more entities to one or more cloud computing resources hosted by a cloud service provider, the method comprising:

using one or more hardware processors to perform:

receiving, via a visual exploration graphical user interface (GUI), a request to display actions that an entity is allowed to perform with respect to a cloud computing resource; and

responsive to receiving the request:

analyzing a set of access policies applied by a platform of the cloud service provider to identify, from among the set of access policies, a subset of one or more access policies applicable to the entity and the cloud computing resource;

determining, using the subset of one or more access policies, a first set of one or more actions that the entity is allowed to perform with respect to the cloud computing resource; and

generating, within the visual exploration GUI;

one or more selectable GUI elements corresponding to one or more access policies in the subset of one or more access policies, and

one or more GUI elements corresponding to one or more actions in the first set of one or more actions;

simulating, within the visual exploration GUI, updating a set of controlling policies, the simulation comprising:

receiving input, via at least one of the one or more selectable GUI elements, indicating that at least one of the one or more access policies is to be added to or removed from the set of controlling policies, and

responsive to the input, updating the visual exploration GUI to display a second set of one or more actions that the entity would be allowed to perform with respect to the cloud computing resource if the at least one of the one or more access policies were added to or removed from the set of controlling policies, wherein the first set of one or more actions is different from the second set of one or more actions;

configuring the platform of the cloud service provider to control access to the one or more cloud computing resources in accordance with an updated set of controlling policies obtained via the addition or removal of the at least one of the one or more access policies to or from the set of controlling policies; and

causing the platform of the cloud service provider to execute one or more security services in accordance with the updated set of controlling policies.

9. The method of claim 8 , further comprising:

updating the visual exploration GUI to display one or more access levels corresponding to the second set of one or more actions.

10. The method of claim 8 , wherein the input indicating that at least one of the one or more access policies is to be added or removed from the set of controlling policies indicates that the at least one of the one or more access policies is to be removed from the set of controlling policies.

11. The method of claim 8 , wherein the one or more selectable GUI elements corresponding to one or more access policies in the subset of access policies are displayed in a policy stack that organizes access policies into one or more policy types, and wherein the one or more policy types are arranged in an order of applicable scope.

12. The method of claim 8 , wherein the subset of access policies is displayed in a policy viewer portion of the visual exploration GUI.

13. The method of claim 8 , further comprising:

generating, within the visual exploration GUI, one or more GUI elements corresponding to one or more access levels associated with the one or more actions in the first set of one or more actions.

14. The method of claim 8 , wherein the visual exploration GUI is implemented as part of a user interface of a cloud security service.

15. One or more non-transitory computer-accessible storage media storing program instructions that, when executed on or across one or more hardware processors, cause the one or more hardware processors to perform:

receiving, via a visual exploration graphical user interface (GUI), a request to display actions that an entity is allowed to perform with respect to a cloud computing resource; and

responsive to receiving the request:

analyzing a set of access policies applied by a platform of a cloud service provider to identify, from among the set of access policies, a subset of one or more access policies applicable to the entity and the cloud computing resource;

determining, using the subset of one or more access policies, a first set of one or more actions that the entity is allowed to perform with respect to the cloud computing resource; and

generating, within the visual exploration GUI:

one or more selectable GUI elements corresponding to one or more access policies in the subset of access policies, and

one or more GUI elements corresponding to one or more actions in the first set of one or more actions;

simulating, within the visual exploration GUI, updating a set of controlling policies, the simulation comprising:

receiving input, via at least one of the one or more selectable GUI elements, indicating that at least one of the one or more access policies is to be added to or removed from the set of controlling policies, and

responsive to the input, updating the visual exploration GUI to display a second set of one or more actions that the entity would be allowed to perform with respect to the cloud computing resource if the at least one of the one or more access policies were added to or removed from the set of controlling policies, wherein the first set of one or more actions is different from the second set of one or more actions;

configuring the platform of the cloud service provider to control access to the one or more cloud computing resources in accordance with an updated set of controlling policies obtained via the addition or removal of the at least one of the one or more access policies to or from the set of controlling policies; and

causing the platform of the cloud service provider to execute one or more security services in accordance with the updated set of controlling policies.

16. The one or more non-transitory computer-accessible storage media of claim 15 , storing further program instructions that further cause the one or more hardware processors to perform:

updating the visual exploration GUI to display one or more access levels corresponding to the second set of one or more actions.

17. The one or more non-transitory computer-accessible storage media of claim 15 , wherein the input indicating that the at least one of the one or more access policies is to be added or removed from the set of controlling policies indicates that the at least one of the one or more access policies is to be removed from the set of controlling policies.

18. The one or more non-transitory computer-accessible storage media of claim 15 , wherein the one or more selectable GUI elements corresponding to the one or more access policies in the subset of one or more access policies are displayed in a policy stack that organizes access policies into one or more policy types, and wherein the one or more policy types are arranged in an order of applicable scope.

19. The one or more non-transitory computer-accessible storage media of claim 15 , wherein the subset of one or more access policies is displayed in a policy viewer portion of the visual exploration GUI.

20. The one or more non-transitory computer-accessible storage media of claim 15 , wherein the visual exploration GUI is implemented as part of a user interface of a cloud security service.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 17, 2022
From: SAMEK, EVAN; TOBOLSKI, NICHOLAS; MARTIN, JAMES; CHALAL, MOHAMED; ABEDINZADEHVATANKHAH, ALIREZA; RIVERA, KRIS
To: RAPID7, INC.
Reel/Frame 059039/0636 →
References Cited (30)
US 6202066B1 · Barkley · 2001 [cited by examiner]
US 9218502B1 · Doermann et al. · 2015 [cited by applicant]
US 9516028B1 · Andruschuk et al. · 2016 [cited by applicant]
US 10129344B2 · Pogrebinsky et al. · 2018 [cited by applicant]
US 10880189B2 · Martinez et al. · 2020 [cited by applicant]
US 12015635B2 · Witschey et al. · 2024 [cited by applicant]
US 12021900B1 · Gladney et al. · 2024 [cited by applicant]
US 20050262132A1 · Morita · 2005 [cited by examiner]
US 20080104393A1 · Glasser et al. · 2008 [cited by applicant]
US 20110131275A1 · Maida-Smith et al. · 2011 [cited by applicant]
US 20130219156A1 · Sears · 2013 [cited by applicant]
US 20130290500A1 · Narendra et al. · 2013 [cited by applicant]
US 20140280961A1 · Martinez et al. · 2014 [cited by applicant]
US 20170054757A1 · Siswick · 2017 [cited by examiner]
US 20170141961A1 · Cao et al. · 2017 [cited by applicant]
US 20180091583A1 · Collins et al. · 2018 [cited by applicant]
US 20180268347A1 · Benedetti et al. · 2018 [cited by applicant]
US 20190121989A1 · Mousseau · 2019 [cited by examiner]
US 20190327271A1 · Saxena et al. · 2019 [cited by applicant]
US 20200225655A1 · Cella et al. · 2020 [cited by applicant]
US 20220156631A1 · Kanso et al. · 2022 [cited by applicant]
US 20220210201A1 · Kastroulis · 2022 [cited by applicant]
US 20220263835A1 · Pieczul et al. · 2022 [cited by applicant]
US 20220353289A1 · Witschey et al. · 2022 [cited by applicant]
US 20230019705A1 · Zettel, II et al. · 2023 [cited by applicant]
US 20230090828A1 · Patro et al. · 2023 [cited by applicant]
US 20230148158A1 · Bandarupalli et al. · 2023 [cited by applicant]
CN 102307185A · 2012 [cited by applicant]
KR 20030057263A · 2003 [cited by applicant]
U.S. Appl. No. 17/543,599, filed Dec. 6, 2021, Matthew Gladney et al. [cited by applicant]
Cited By (1)
US 12,705,373