IP Library Granted Patent US 9,760,713
Granted Patent B1
US 9,760,713 · App. 14/191,648 · Granted Sep 12, 2017

System and method for content-independent determination of file-system-object risk of exposure

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,760,713
App. No.
14/191,648
Granted
Sep 12, 2017
Kind
B1
Abstract

In one embodiment, a method is performed by a computer system comprising computer hardware. The method includes monitoring a file system for risk-assessment events. The method further includes, responsive to a real-time determination of at least one risk-assessment event, determining a content-independent risk of exposure for a file-system object associated with the risk-assessment event. The determining of the content-independent risk of exposure is based, at least in part, on a depth of the file-system object in the file system and a set of users who can access the file-system object.

Claims (51)

1. A method comprising, by a computer system comprising a processing unit, wherein the processing unit is operable to implement the method:

monitoring, by a file-system auditing component comprising a computer server, file-system events of a file system for risk-assessment events;

responsive to a real-time determination of at least one risk-assessment event:

determining an age of a file-system object associated with the risk-assessment event, wherein the age comprises at least one of a creation date of the file-system object and a time elapsed since the creation date;

counting a number of individual users who have permission to access the file-system object;

measuring a depth of the file-system object in the file system;

determining, by an exposure-assessment module comprising a computer server, a content-independent risk of exposure of the file-system object;

wherein the content-independent risk of exposure is determined as a function of at least the determined age, the counted number of individual users and the measured depth;

wherein the content-independent risk of exposure increases in response to a greater determined age of the file-system object, a greater counted number of individual users who have permission to access the file-system object, and lesser values of the measured depth of the file-system object; and

wherein the determining the content-independent risk of exposure is performed without scanning data within the file system for sensitive information.

2. The method of claim 1 , comprising:

evaluating the determined content-independent risk of exposure against one or more notification rules; and

responsive to a notification determination, notifying one or more users of the determined content-independent risk of exposure.

3. The method of claim 1 , wherein the at least one risk-assessment event is selected from the group consisting of: a permissions change, a read access, and a write access.

4. The method of claim 1 , wherein the file-system object comprises a plurality of files.

5. The method of claim 1 , wherein the file-system object comprises a folder.

6. The method of claim 1 , wherein the determining of the content-independent risk of exposure is based, at least in part, on a user-access count and a group-access count.

7. The method of claim 1 , wherein the determining of the content-independent risk of exposure is based, at least in part, on file-system-object variables selected from the group consisting of: age of permissions, number of write accesses, number of read accesses, number of changes to user permissions over a certain period of time, number of changes to user-group permissions over a certain period of time, number of file-creation events, number of explicit individual-user accesses, and number of group accesses.

8. An information handling system comprising:

a computing device comprising a processor, wherein the processor is operable to implement a method, the method comprising:

monitoring, by a file-system auditing component comprising a computer server, file-system events of a file system for risk-assessment events;

responsive to a real-time determination of at least one risk-assessment event:

determining an age of a file-system object associated with the risk-assessment event, wherein the age comprises at least one of a creation date of the file-system object and a time elapsed since the creation date;

counting a number of individual users who have permission to access the file-system object;

measuring a depth of the file-system object in the file system;

determining, by an exposure-assessment module comprising a computer server, a content-independent risk of exposure of the file-system object;

wherein the content-independent risk of exposure is determined as a function of at least the determined age, the counted number of individual users and the measured depth;

wherein the content-independent risk of exposure increases in response to a greater determined age of the file-system object, a greater counted number of individual users who have permission to access the file-system object, and lesser values of the measured depth of the file-system object; and

wherein the determining the content-independent risk of exposure is performed without scanning data within the file system for sensitive information.

9. The information handling system of claim 8 , the method comprising:

evaluating the determined content-independent risk of exposure against one or more notification rules; and

responsive to a notification determination, notifying one or more users of the determined content-independent risk of exposure.

10. The information handling system of claim 8 , wherein the at least one risk-assessment event is selected from the group consisting of: a permissions change, a read access, and a write access.

11. The information handling system of claim 8 , wherein the file-system object comprises a plurality of files.

12. The information handling system of claim 8 , wherein the file-system object comprises a folder.

13. The information handling system of claim 8 , wherein the determining of the content-independent risk of exposure is based, at least in part, on a user-access count and a group-access count.

14. The information handling system of claim 8 , wherein the determining of the content-independent risk of exposure is based, at least in part, on file-system-object variables selected from the group consisting of: age of permissions, number of write accesses, number of read accesses, number of changes to user permissions over a certain period of time, number of changes to user-group permissions over a certain period of time, number of file-creation events, number of explicit individual-user accesses, and number of group accesses.

15. A computer-program product comprising a non-transitory computer-usable medium having computer-readable program code embodied therein, the computer-readable program code adapted to be executed to implement a method comprising:

monitoring, by a file-system auditing component comprising a computer server, file-system events of a file system for risk-assessment events;

responsive to a real-time determination of at least one risk-assessment event:

determining an age of a file-system object associated with the risk-assessment event, wherein the age comprises at least one of a creation date of the file-system object and a time elapsed since the creation date;

counting a number of individual users who have permission to access the file-system object;

measuring a depth of the file-system object in the file system;

determining, by an exposure-assessment module comprising a computer server, a content-independent risk of exposure of the file-system object;

wherein the content-independent risk of exposure is determined as a function of at least the determined age, the counted number of individual users and the measured depth;

wherein the content-independent risk of exposure increases in response to a greater determined age of the file-system object, a greater counted number of individual users who have permission to access the file-system object, and lesser values of the measured depth of the file-system object; and

wherein the determining the content-independent risk of exposure is performed without scanning data within the file system for sensitive information.

16. The computer-program product of claim 15 , the method comprising:

evaluating the determined content-independent risk of exposure against one or more notification rules; and

responsive to a notification determination, notifying one or more users of the determined content-independent risk of exposure.

17. The computer-program product of claim 15 , wherein the at least one risk-assessment is selected from the group consisting of: a permissions change, a read access, and a write access.

Assignments (26)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Dec 6, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044800/0848 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
RELEASE OF REEL 032809 FRAME 0987 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, INC.
Reel/Frame 040026/0953 →
RELEASE OF REEL 032810 FRAME 0038 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, INC.
Reel/Frame 040027/0686 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 032810 FRAME 0023 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, INC.
Reel/Frame 040014/0320 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded May 1, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 032810/0038 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded May 1, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032810/0023 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded May 1, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 032809/0987 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2014
From: SEDLACK, TIMOTHY CHARLES; WARDWELL, LESLIE G.
To: DELL SOFTWARE INC.
Reel/Frame 032342/0370 →