US2019207772A1PendingUtilityA1

Network scan for detecting compromised cloud-identity access information

Assignee: CYBERARK SOFTWARE LTDPriority: Jan 2, 2018Filed: Mar 20, 2018Published: Jul 4, 2019
Est. expiryJan 2, 2038(~11.4 yrs left)· nominal 20-yr term from priority
H04L 63/126H04L 63/0807H04L 63/10H04L 63/1408H04L 63/083H04L 63/20H04L 9/14H04L 9/3247H04L 9/3226H04L 9/3234H04L 9/30
44
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods are provided for scanning a network to identify potentially compromised cloud-based access information. Techniques include actively scanning a plurality of network resources; identifying a first access token in a first location on a first network resource that a first identity can use to request access to a first cloud application executable in the cloud environment; identifying a second access token in a second location on a second network resource that a second identity can use to request access to a second cloud application executable in the cloud environment; accessing a secure registry of approved access token location information, the secure registry identifying a plurality of access tokens and a plurality of corresponding locations where the plurality of access tokens are permitted to be stored; determining that the first location is an approved storage location for the first access token; and determining that the second location is not an approved storage location for the second access token.

Claims

exact text as granted — not AI-modified
What is claimed: 
     
         1 . A non-transitory computer readable medium including instructions that, when executed by at least one processor, cause the at least one processor to perform operations for scanning a network to identify potentially compromised cloud-based access information, the operations comprising:
 actively scanning a plurality of network resources in a network that is separate from a cloud environment, the plurality of network resources being configured to request access to one or more cloud applications executable in the cloud environment;   identifying, based on the active scan of the plurality of network resources, a first access token in a first location on a first network resource that a first identity can use to request access to a first cloud application executable in the cloud environment;   identifying, based on the active scan of the plurality of network resources, a second access token in a second location on a second network resource that a second identity can use to request access to a second cloud application executable in the cloud environment;   accessing a secure registry of approved access token location information, the secure registry identifying a plurality of access tokens and a plurality of corresponding locations where the plurality of access tokens are permitted to be stored;   determining, based on the secure registry, that the first location is an approved storage location for the first access token; and   determining, based on the secure registry, that the second location is not an approved storage location for the second access token.   
     
     
         2 . The non-transitory computer readable medium of  claim 1 , wherein the active scanning of the plurality of network resources occurs independent of any attempt by the plurality of network resources to request access to the one or more cloud applications executable in the cloud environment. 
     
     
         3 . The non-transitory computer readable medium of  claim 1 , wherein the plurality of corresponding locations in the secure registry identify a plurality of IP addresses where the plurality of access tokens are permitted to be stored. 
     
     
         4 . The non-transitory computer readable medium of  claim 1 , wherein the plurality of corresponding locations in the secure registry identify a plurality of MAC addresses where the plurality of access tokens are permitted to be stored. 
     
     
         5 . The non-transitory computer readable medium of  claim 1 , wherein the plurality of corresponding locations in the secure registry identify a plurality of names of network resources on which the plurality of access tokens are permitted to be stored. 
     
     
         6 . The non-transitory computer readable medium of  claim 1 , wherein the secure registry is a secure credential vault. 
     
     
         7 . The non-transitory computer readable medium of  claim 1 , wherein the secure registry is maintained by a host of the cloud environment. 
     
     
         8 . The non-transitory computer readable medium of  claim 1 , further comprising generating an alert, the alert identifying the second location of the second access token. 
     
     
         9 . The non-transitory computer readable medium of  claim 1 , further comprising invalidating the second access token. 
     
     
         10 . The non-transitory computer readable medium of  claim 1 , further comprising monitoring attempted communications activity from the second network resource to the cloud environment. 
     
     
         11 . The non-transitory computer readable medium of  claim 1 , further comprising investigating the second network resource's past use of the second access token in communications with the cloud environment. 
     
     
         12 . The non-transitory computer readable medium of  claim 1 , wherein the plurality of corresponding locations where the plurality of access tokens are permitted to be stored are determined as part of a process that created the plurality of access tokens. 
     
     
         13 . A computer-implemented method for scanning a network to identify potentially compromised cloud-based access information, the method comprising:
 actively scanning a plurality of network resources in a network that is separate from a cloud environment, the plurality of network resources being configured to request access to one or more cloud applications executable in the cloud environment;   identifying, based on the active scan of the plurality of network resources, a first access token in a first location on a first network resource that a first identity can use to request access to a first cloud application executable in the cloud environment;   identifying, based on the active scan of the plurality of network resources, a second access token in a second location on a second network resource that a second identity can use to request access to a second cloud application executable in the cloud environment;   accessing a secure registry of approved access token location information, the secure registry identifying a plurality of access tokens and a plurality of corresponding locations where the plurality of access tokens are permitted to be stored;   determining, based on the secure registry, that the first location is an approved storage location for the first access token; and   determining, based on the secure registry, that the second location is not an approved storage location for the second access token.   
     
     
         14 . The computer-implemented method of  claim 13 , wherein the first access token and the second access token are the same access token, and the first storage location and the second storage location are different storage locations. 
     
     
         15 . The computer-implemented method of  claim 13 , wherein the first access token and the second access token are different access tokens, and the first storage location and the second storage location are the same storage location. 
     
     
         16 . The computer-implemented method of  claim 13 , wherein the active scanning of the plurality of network resources occurs independent of any attempt by the plurality of network resources to request access to the one or more cloud applications executable in the cloud environment. 
     
     
         17 . The computer-implemented method of  claim 13 , wherein the plurality of corresponding locations in the secure registry identify a plurality of IP addresses where the plurality of access tokens are permitted to be stored. 
     
     
         18 . The computer-implemented method of  claim 13 , wherein the plurality of corresponding locations in the secure registry identify a plurality of MAC addresses where the plurality of access tokens are permitted to be stored. 
     
     
         19 . The computer-implemented method of  claim 13 , wherein the plurality of corresponding locations in the secure registry identify a plurality of names of network resources on which the plurality of access tokens are permitted to be stored. 
     
     
         20 . The computer-implemented method of  claim 13 , wherein the plurality of corresponding locations where the plurality of access tokens are permitted to be stored are determined as part of a process that created the plurality of access tokens.

Join the waitlist — get patent alerts

Track US2019207772A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.