Invention Grant
- Patent Title: Protections against security vulnerabilities associated with temporary access tokens
-
Application No.: US16869906Application Date: 2020-05-08
-
Publication No.: US11258788B2Publication Date: 2022-02-22
- Inventor: Omer Tsarfati , Asaf Hecht
- Applicant: CyberArk Software Ltd.
- Applicant Address: IL Petach-Tikva
- Assignee: CyberArk Software Ltd.
- Current Assignee: CyberArk Software Ltd.
- Current Assignee Address: IL Petach-Tikva
- Agency: Finnegan, Henderson, Farabow, Garrett & Dunner, LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06N20/00

Abstract:
Disclosed embodiments relate to systems and methods for automatically detecting and addressing security risks in code segments. Techniques include identifying a request from a network identity for an action involving a target network resource, wherein the action requires a temporary access token. Techniques further include performing, based on a security policy, at least one of: storing the temporary access token separate from the network identity and providing the network identity with a customized replacement token having an attribute different from the temporary access token; or creating a customized replacement role for the network identity, the customized replacement role having associated permissions that are customized for the network identity based on the request.
Public/Granted literature
- US20210352064A1 PROTECTIONS AGAINST SECURITY VULNERABILITIES ASSOCIATED WITH TEMPORARY ACCESS TOKENS Public/Granted day:2021-11-11
Information query