Managing privileged shared accounts
US-9838383-B1 · Dec 5, 2017 · US
US10834084B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10834084-B2 |
| Application number | US-201816041305-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jul 20, 2018 |
| Priority date | Jul 20, 2018 |
| Publication date | Nov 10, 2020 |
| Grant date | Nov 10, 2020 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Embodiments can provide a method for accessing an endpoint, including: receiving, from a privileged user, a request for accessing the endpoint; providing, by a user behavior analytics device, a risk score with respect to the privileged user, wherein the risk score is calculated based on at least one action performed by the privileged user. If the risk score is lower than a first predefined value, providing access to the endpoint for the privileged user. If the risk score is higher than a second predefined value, denying the request for accessing the endpoint. If the risk score is between the first predefined value and the second predefined value, performing at least one of: providing, by a privileged identity management server, a multi-factor authentication against the privileged user; and rerouting the request for accessing the endpoint for approval.
Opening claim text (preview).
What is claimed is: 1. A method for accessing an endpoint, comprising: receiving, from a privileged user, a request for accessing the endpoint; providing, by a user behavior analytics device, a risk score with respect to the privileged user, wherein the risk score is calculated based on at least one action performed by the privileged user; updating, by a user behavior analytics device, the risk score in real time based on at least one new action performed by the privileged user; if the risk score is between the first predefined value and the second predefined value, rerouting the request for accessing the endpoint to a machine learning model trained by humans for approval. 2. The method as recited in claim 1 , wherein the at least one action includes at least one of: accessing the endpoint from an unusual location; accessing the endpoint at unusual time; accessing the endpoint for the first time; at least one login failure; more than one request within a predefined time period; at least one action previously performed on the endpoint; at least one action previously performed on a network device; and at least one action previously performed using a non-privileged account. 3. The method as recited in claim 1 , further comprising: receiving, from a privileged user, a request for a credential for accessing the endpoint; forwarding, by a privileged identity management client, the request for the credential to the privileged identity management server; sending, by the privileged identity management server, a request for the risk score to the user behavior analytics device. 4. The method as recited in claim 3 , further comprising: automatically detecting, by the user behavior analytics device, that the request for the credential is from a privileged account of the privileged user. 5. The method as recited in claim 4 , further comprising: informing, by the privileged identity management server, the user behavior analytics device that the request for the credential is from the privileged account of the privileged user. 6. The method as recited in claim 3 , wherein if the risk score is lower than the first predefined value, establishing a privileged session between the privileged identity management client and the endpoint. 7. The method as recited in claim 6 , further comprising: continuously updating, by the user behavior analytics device, the risk score based on at least one action performed by the privileged user during the established privileged session; and deciding, by the privileged identity management server, whether the established privileged session is continued or terminated based on the continuously updated risk score. 8. The method as recited in claim 3 , wherein the privileged identity management client is a browser or a fat client, and the fat client is one of a Windows Remote Desktop Protocol (RDP) client, a Putty on Linux, a Database client, and a Virtual Network Computing (V.N.C.) client. 9. The method as recited in claim 3 , wherein the risk score is calculated further based on at least one action performed on the endpoint by the privileged user during one or more previous privileged sessions. 10. A method of accessing an endpoint, comprising: receiving, from a privileged user, a request for a credential for accessing the endpoint; forwarding, by a privileged identity management client, the request for the credential to the privileged identity management server; sending, by the privileged identity management server, a request for a risk score with respect to the privileged user, to a user behavior analytics device; receiving, from the user behavior analytics device, the risk score, wherein the risk score is calculated based on at least one action performed by the privileged user for an impending privileged session and at least one action performed on the endpoint by the privileged user during one or more previous privileged sessions; if the risk score is lower than a first predefined value, providing the credential, by the privileged identity management server, to the privileged identity management client, and accessing the endpoint by the privileged user through the privileged identity management client. 11. The method as recited in claim 10 , wherein the at least one action performed by the privileged user for the impending privileged session includes at least one of: accessing the endpoint from an unusual location; accessing the endpoint at unusual time; accessing the endpoint for the first time; at least one login failure; more than one request within a predefined time period; at least one action previously performed on the endpoint; at least one action previously performed on a network device; and at least one action previously performed using a non-privileged account. 12. The method as recited in claim 10 , further comprising: automatically detecting, by the user behavior analytics device, that the request for the credential is from a privileged account of the privileged user. 13. The method as recited in claim 12 , further comprising: informing, by the privileged identity management server, the user behavior analytics device that the request for the credential is from the privileged account of the privileged user. 14. The method as recited in claim 11 , wherein if the risk score is lower than the first predefined value, establishing a privileged session between the privileged identity management client and the endpoint. 15. The method as recited in claim 14 , further comprising: continuously updating, by the user behavior analytics device, the risk score based on at least one action performed by the privileged user during the established privileged session; and deciding, by the privileged identity management server, whether the established privileged session is continued or terminated based on the continuously updated risk score. 16. A system for accessing an endpoint, comprising: a privileged identity management client, configured to receive a request for a credential for accessing the endpoint, from a privileged user; a privileged identity management server, configured to receive the request for the credential forwarded by the privileged identity management client; and a security information and event management system, including a user behavior analytics device, configured to calculate a risk score based on at least one action performed by the privileged user for an impending privileged session and at least one action performed on the endpoint by the privileged user during one or more previous privileged sessions; wherein if the risk score is lower than a first predefined value, the credential is provided from the privileged identity management server to the privileged identity management client, a privileged session is established between the privileged identity management client and the endpoint, and the endpoint is configured to be accessed by the privileged user through the privileged identity management client. 17. The system as recited in claim 16 , wherein the at least one action performed by the privileged user for the impending privileged session includes at least one of: accessing the endpoint from an unusual location; accessing the endpoint at unusual time; accessing the endpoint for the first time; at least one login failure; more than one request within a predefined time period; at least one action previously performed on the endpoint; at least one action previously performed on a network device; and at least one action previously performed using a non-privileged accou
Multiple levels of security · CPC title
for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title
Vulnerability analysis · CPC title
for controlling access to devices or network resources · CPC title
wherein the security policies are location-dependent, e.g. entities privileges depend on current location or allowing specific operations only from locally connected terminals · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.