Invention Grant
- Patent Title: Monitoring of authorization-exceeding activity in distributed networks
- Patent Title (中): 监控分布式网络中的授权超过活动
-
Application No.: US13735210Application Date: 2013-01-07
-
Publication No.: US09130920B2Publication Date: 2015-09-08
- Inventor: Konstantin I. Pelykh
- Applicant: Zettaset, Inc.
- Applicant Address: US CA Mountain View
- Assignee: ZETTASET, Inc.
- Current Assignee: ZETTASET, Inc.
- Current Assignee Address: US CA Mountain View
- Agent Marek Alboszta
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A network security layer with a role mapping component with a current role mapping between services and access permissions is provided between a user and the services. A multi-tenancy module with current membership mapping is also provided. The security layer has a network authentication protocol for user authentication at log-in. Snapshots of a baseline role mapping between services and permissions are taken at certain times. The role mapping component verifies snapshots at set intervals, and when the user performs certain actions, the current role mapping is compared with the baseline role mapping. Upon discrepancy, the role mapping component executes a set of rules, including forceful log-out to prevent system intrusion. Comparison of current membership mapping with a baseline membership mapping can also be applied. The security layer can thus monitor authorization-exceeding modifications to baseline policies attempted by logged-in and initially authorized users.
Public/Granted literature
- US20140196115A1 Monitoring of Authorization-Exceeding Activity in Distributed Networks Public/Granted day:2014-07-10
Information query