IP Library Granted Patent US 9,990,506
Granted Patent B1
US 9,990,506 · App. 14/672,715 · Granted Jun 5, 2018

Systems and methods of securing network-accessible peripheral devices

Inventors: Michel Albert Brisebois (Renfrew, CA); Sawan Goyal (Kanata, CA); GuangNing Hu (Kanata, CA); Curtis T. Johnstone (Ottawa, CA)
Assignee: Quest Software Inc.
G06F21/62H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,990,506
App. No.
14/672,715
Granted
Jun 5, 2018
Kind
B1
Abstract

In one embodiment, a method is performed by a computer system. The method includes accessing information related to enterprise usage of a plurality of network-accessible peripheral devices and identifying, from the information, discrete content-imaging events that occurred on the plurality of network-accessible peripheral devices. In addition, the method includes determining particular users associated with the discrete content-imaging events on a per-event basis and determining particular content to which the discrete content-imaging events relate on a per-event basis. Further, the method includes abstracting correlated data related to the discrete content-imaging events into a standardized format, the correlated data comprising data related to the particular users and the particular content, the standardized format enabling expression of the discrete content-imaging events by user and by type of content-imaging activity.

Claims (73)

1. A method comprising, by a computer system:

accessing information related to enterprise usage of a plurality of network-accessible peripheral devices;

identifying, from the information, discrete content-imaging events that occurred on the plurality of network-accessible peripheral devices;

determining particular users associated with the discrete content-imaging events on a per-event basis;

determining information related to particular times when the discrete content-imaging events are deemed to have occurred on a per-event basis;

identifying particular content that was imaged as a result of the discrete content-imaging events on a per-event basis;

accessing stored content-based classifications of the particular content on a per-event basis, wherein the stored content-based classifications comprise topics of the particular content;

correlating the topics of the particular content to a plurality of user contexts on a per-event basis, wherein each user context of the plurality of user contexts is defined by a distinct combination of at least one of the particular users and at least one of the particular times;

associating at least one user pattern with each user context based, at least in part, on the correlating; and

generating for at least one user comparative content-imaging-pattern information for at least two user contexts of the plurality of user contexts;

performing an automated risk evaluation of the comparative content-imaging-pattern information; and

transmitting an alert to a designated user responsive to the comparative content-imaging-pattern information meeting specified criteria.

2. The method of claim 1 , wherein the accessing comprises extracting at least a portion of the information from logs produced by one or more of the plurality of network-accessible peripheral devices.

3. The method of claim 1 , wherein:

the accessing comprises accessing communications from at least one communications platform;

the identifying comprises identifying communications in which at least one network-accessible peripheral device of the plurality of network-accessible peripheral devices is a communication participant; and

the identified communications correspond to at least a portion of the discrete content-imaging events.

4. The method of claim 1 , wherein:

the at least two user contexts comprise a first user context and a second user context, wherein the first user context and the second user context are mutually exclusive; and

the comparative content-imaging-pattern information comprises:

first content-imaging-pattern information related to content-imaging events occurring in the first user context; and

second content-imaging-pattern information related to content-imaging events occurring in the second user context.

5. The method of claim 1 , wherein at least one of the at least two user contexts specifies events occurring during one or more recurring periods of time.

6. The method of claim 5 , wherein the one or more recurring periods of time comprise time periods deemed non-working hours.

7. The method of claim 1 , comprising:

activating a cross-platform data loss prevention (DLP) policy for enforcement against a plurality of users on a set of peripheral devices from the plurality of network-accessible peripheral devices;

monitoring content-imaging events of the plurality of users on each of the set of peripheral devices for violations of the cross-platform DLP policy;

responsive to a detected violation of the cross-platform DLP policy by at least one user on at least one peripheral device, the computer system dynamically acquiring context information for the detected violation using information associated with the detected violation; and

the computer system publishing violation information to one or more designated users, the violation information comprising at least a portion of the information associated with the detected violation and at least a portion of the context information.

8. The method of claim 1 , wherein the discrete content-imaging events comprise one or more of the following content-imaging events: print, scan, copy, and fax.

9. The method of claim 1 , wherein the plurality of network-accessible peripheral devices comprise one or more of the following devices: printers, scanners, copiers, and fax machines.

10. An information handling system comprising at least one processor and memory, wherein the at least one processor and memory in combination are operable to implement a method comprising:

accessing information related to enterprise usage of a plurality of network-accessible peripheral devices;

identifying, from the information, discrete content-imaging events that occurred on the plurality of network-accessible peripheral devices;

determining particular users associated with the discrete content-imaging events on a per-event basis;

determining information related to particular times when the discrete content-imaging events are deemed to have occurred on a per-event basis;

identifying particular content that was imaged as a result of the discrete content-imaging events on a per-event basis;

accessing stored content-based classifications of the particular content on a per-event basis, wherein the stored content-based classifications comprise topics of the particular content;

correlating the topics of the particular content to a plurality of user contexts on a per-event basis, wherein each user context of the plurality of user contexts is defined by a distinct combination of at least one of the particular users and at least one of the particular times;

associating at least one user pattern with each user context based, at least in part, on the correlating; and

generating for at least one user comparative content-imaging-pattern information for at least two user contexts of the plurality of user contexts;

performing an automated risk evaluation of the comparative content-imaging-pattern information; and

transmitting an alert to a designated user responsive to the comparative content-imaging-pattern information meeting specified criteria.

11. The information handling system of claim 10 , wherein the accessing comprises extracting at least a portion of the information from logs produced by one or more of the plurality of network-accessible peripheral devices.

12. The information handling system of claim 10 , wherein:

the accessing comprises accessing communications from at least one communications platform;

the identifying comprises identifying communications in which at least one network-accessible peripheral device of the plurality of network-accessible peripheral devices is a communication participant; and

the identified communications correspond to at least a portion of the discrete content-imaging events.

13. The information handling system of claim 10 , wherein:

the at least two user contexts comprise a first user context and a second user context, wherein the first user context and the second user context are mutually exclusive; and

the comparative content-imaging-pattern information comprises:

first content-imaging-pattern information related to content-imaging events occurring in the first user context; and

second content-imaging-pattern information related to content-imaging events occurring in the second user context.

14. The information handling system of claim 10 , wherein at least one of the at least two user contexts specifies events occurring during one or more recurring periods of time.

15. The information handling system of claim 14 , wherein the one or more recurring periods of time comprise time periods deemed non-working hours.

16. The information handling system of claim 10 , the method comprising:

activating a cross-platform data loss prevention (DLP) policy for enforcement against a plurality of users on a set of peripheral devices from the plurality of network-accessible peripheral devices;

monitoring content-imaging events of the plurality of users on each of the set of peripheral devices for violations of the cross-platform DLP policy;

responsive to a detected violation of the cross-platform DLP policy by at least one user on at least one peripheral device, the information handling system dynamically acquiring context information for the detected violation using information associated with the detected violation; and

the information handling system publishing violation information to one or more designated users, the violation information comprising at least a portion of the information associated with the detected violation and at least a portion of the context information.

17. The information handling system of claim 10 , wherein the discrete content-imaging events comprise one or more of the following content-imaging events: print, scan, copy, and fax.

18. A computer-program product comprising a non-transitory computer-usable medium having computer-readable program code embodied therein, the computer-readable program code adapted to be executed to implement a method comprising:

accessing information related to enterprise usage of a plurality of network-accessible peripheral devices;

identifying, from the information, discrete content-imaging events that occurred on the plurality of network-accessible peripheral devices;

determining particular users associated with the discrete content-imaging events on a per-event basis;

determining information related to particular times when the discrete content-imaging events are deemed to have occurred on a per-event basis;

identifying particular content that was imaged as a result of the discrete content-imaging events on a per-event basis;

accessing stored content-based classifications of the particular content on a per-event basis, wherein the stored content-based classifications comprise topics of the particular content;

correlating the topics of the particular content to a plurality of user contexts on a per-event basis, wherein each user context of the plurality of user contexts is defined by a distinct combination of at least one of the particular users and at least one of the particular times;

associating at least one user pattern with each user context based, at least in part, on the correlating; and

generating for at least one user comparative content-imaging-pattern information for at least two user contexts of the plurality of user contexts;

performing an automated risk evaluation of the comparative content-imaging-pattern information; and

transmitting an alert to a designated user responsive to the comparative content-imaging-pattern information meeting specified criteria.

Assignments (26)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Dec 6, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044719/0565 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
RELEASE OF REEL 035860 FRAME 0878 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
Reel/Frame 040027/0158 →
RELEASE OF REEL 035860 FRAME 0797 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
Reel/Frame 040028/0551 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 035858 FRAME 0612 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
Reel/Frame 040017/0067 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Jun 9, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC; SECUREWORKS, INC.; STATSOFT, INC.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 035860/0878 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jun 9, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 035860/0797 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Jun 9, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 035858/0612 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2015
From: BRISEBOIS, MICHEL ALBERT; GOYAL, SAWAN; HU, GUANGNING; JOHNSTONE, CURTIS T.
To: DELL SOFTWARE INC.
Reel/Frame 035320/0838 →