Systems and methods for data-driven infrastructure control
By using machine learning algorithms within a unified permissions framework to automatically detect user behavior and generate anomaly scores, it addresses the scaling and efficiency issues of the RBAC approach in large organizations and implements automated access control and security management.
Patent Information
- Application Number
- CN202080044925.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-04-29
- Filing Date
- 2020-04-28
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2040-04-28
AI Technical Summary
In large organizations, role-based access control (RBAC) approaches face scaling limitations, job function complexity, frequent organizational structure changes, regulatory boundaries, and cybersecurity risks, leading to inefficient manual audits of user access.
Machine learning algorithms within a unified permissions framework are used to automatically detect user behavior, generate anomaly scores, and implement automated access control through administrator review and algorithm updates.
It improves the efficiency of automated detection of user access in large organizations, reduces the tediousness of manual auditing, and enhances network security and the flexibility of access management.
Smart Images

Figure CN114981821B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to systems and methods for data-driven infrastructure control, and more particularly to automatically detecting user behavior and generating anomaly scores within a unified permissions framework. Background Art
[0002] Enterprises often use technical access management systems to provide access between users within and outside the organization. A common approach to this access management is role-based access control (RBAC), or a "role-based" approach. With RBAC, access to the system is determined based on the user's role.
[0003] However, the RBAC approach has scaling limitations in very large environments (e.g., in organizations with more than 10,000 technology assets). Disadvantages of the RBAC approach in large organizations include the scaling and complexity of job functions, frequent changes in organizational structure, regulatory boundaries and constraints, technology asset inventory management, cybersecurity risks, and the complexity of transaction logging.
[0004] Additionally, an enterprise may have internal or regulatory requirements to audit access to certain technology assets. For example, an enterprise may need to review (through manual review or other means) every instance of a user accessing a certain technology asset. Misconduct may be detected and corrective action may be taken. However, with potentially thousands of access instances per day, having a human review each instance individually can be tedious and inefficient. Summary of the Invention
[0005] A system and method for data-driven infrastructure control are disclosed. According to one embodiment, in an information processing apparatus including at least one computer processor, a computer-implemented method for automatically detecting abnormal user behavior within a unified entitlement framework may include: (1) receiving, on a computing device, a request for access to a technology asset from a user, the access request including session data, the session data including one or more of a user identifier, a user location, keystrokes, and a user computing device identifier; (2) applying an entitlement-specific machine learning algorithm to the session data to generate an anomaly score; (3) storing the session data and the associated anomaly score; (4) sending a review request to an administrator; (5) receiving a review result from the administrator; and (6) updating the entitlement-specific machine learning algorithm based on the anomaly score and the review result from the administrator.
[0006] In one embodiment, the method may further include receiving reference data associated with the access request.
[0007] In one embodiment, the reference data may include at least one of an identification of an application service hosted on the computing device, a change or incident to an access request, and information about the technology asset.
[0008] In one embodiment, the permissions-specific machine learning algorithm is based on historical session information.
[0009] In one embodiment, in response to a first request for a technical asset, the anomaly score may be higher.
[0010] In one embodiment, in response to a first request from a computing device, the anomaly score may be higher.
[0011] In one embodiment, the method may further include denying access to the technology asset in response to the review result including a rejection.
[0012] In one embodiment, the method may further include granting access to the technical asset in response to the review result comprising approval.
[0013] According to another embodiment, in a technology access management system including at least one computer processor, a method for automatically detecting user behavior within an automatable unified permissions framework may include: (1) receiving an access request to a technology asset from a user on a computing device, the access request including session data including one or more of a user identification, a user location, keystrokes, and a user computing device identification; (2) granting the access request; (3) recording session data for the user's access session to the technology asset; (4) applying a machine learning algorithm using a machine learning model based on previously recorded or historical session data for the user to identify repeatable or automatable tasks; and (5) generating an alert that the identified task is automatable.
[0014] In one embodiment, previously recorded or historical session data may include at least one of user keystrokes, file accesses, and application executions.
[0015] In one embodiment, the previously recorded or historical session data may include previously recorded or historical session data for at least one other user.
[0016] In one embodiment, a repeatable or automatable task may include a task that is repeatedly performed by one user to another.
[0017] In one embodiment, repeatable or automatable tasks may include restarting services and sending logs.
[0018] In one embodiment, the method may further include automating repeatable or automatable tasks.
[0019] According to another embodiment, a computer-implemented system may include: a computing device associated with a user; a server including at least one computer processor and executing a computer program; and an administrator electronic device. The computing device may submit an access request from the user to access a technology asset, the access request including session data including one or more of a user identification, a user location, keystrokes, and an identification of the user's computing device. The computer program may apply a privilege-specific machine learning algorithm to the session data to generate an anomaly score; may store the session data and the associated anomaly score; may send a review request with the anomaly score to the administrator electronic device; may receive a review result from the administrator electronic device; and may update the privilege-specific machine learning algorithm based on the anomaly score and the review result from the administrator electronic device.
[0020] In one embodiment, the computer program may receive reference data associated with the access request. The reference data may include an identification of an application service hosted on the computing device, a change or event to the access request, information about the technology asset, a combination thereof, and the like.
[0021] In one embodiment, the permissions-specific machine learning algorithm may be based on historical session information.
[0022] In one embodiment, the anomaly score may be higher in response to a first request for a technology asset or in response to a first request from a computing device.
[0023] In one embodiment, access to the technical asset may be denied in response to the review results including a rejection.
[0024] In one embodiment, access to the technical asset may be granted in response to the review results including approval. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to facilitate a more complete understanding of the present invention, reference is now made to the accompanying drawings, which are not to be construed as limiting the present invention but are merely intended to illustrate various aspects and embodiments.
[0026] Figure 1 A system for automatically detecting anomalous user behavior within a unified permissions framework is described in accordance with an exemplary embodiment.
[0027] Figure 2 A method for performing review activities during a privileged access session is described in accordance with an exemplary embodiment.
[0028] Figure 3A process for automated, privilege-specific anomaly scoring during a privileged access session is described in accordance with an exemplary embodiment.
[0029] Figure 4 A method for automatically generating anomaly scores is described in accordance with an exemplary embodiment.
[0030] Figure 5 A method for automatically detecting user behavior within an automatable unified permissions framework is described in accordance with an exemplary embodiment. DETAILED DESCRIPTION
[0031] Exemplary embodiments will now be described to illustrate the various features. The embodiments described herein are not intended to be limiting in scope, but rather to provide examples of the components, uses, and operations of the invention.
[0032] Figure 1 A system for automatically detecting anomalous user behavior within a unified permissions framework is described in accordance with an exemplary embodiment.
[0033] System 100 may include a plurality of user computing devices 110, each of which may be associated with one or more users 105. According to one embodiment, user computing devices 110 may be connected to one or more networks 150, which may be a wide area network, an intranet, or any other type of network as desired. A plurality of technology assets 115 may also be connected to one or more networks 150. Technology assets 115 may include servers, computers, applications, operating systems, storage devices, data, programs or applications, and the like.
[0034] Although each technology asset 115 is depicted as a single computing device, in reality, any number of technology assets may reside on a single electronic device, may be distributed across multiple computing devices, etc., as desired.
[0035] The system 100 may also include one or more technical access computing devices 120 that execute a technical access management system computer program or application 155. An example of a technical access management system computer program is disclosed in U.S. Patent Application Serial No. 16 / 220,784, the disclosure of which is incorporated herein by reference in its entirety. For example, technical privilege assignments are disclosed as being automatically set "just in time" based on, for example, user identity, time, location, and host device.
[0036] Computing devices 110 , 115 , and 120 may be any suitable electronic devices, including, for example, smart phones, smart watches, portable computers, notebook computers, desktop computers, tablet computers, workstations, kiosks, terminals, Internet of Things (IoT) appliances, and the like.
[0037] The technical access management application 125 can record complete session data for each instance of a user 105 accessing one or more technical assets 115. The technical access management application 125 can record information about the access to one or more technical assets 115, such as the time of access, user identification, device identification (e.g., an identifier associated with the computing device 110 being used), the location from which the user accessed, and any other desired session information. The technical access management application 125 can further record what the user did during the session, such as keystrokes, file deletions, copies, accesses, edits, or application runs, and any other desired session information.
[0038] According to one embodiment, user 105 may use computing device 110 to request access to one or more technology assets 115 from technology access computing device 120. Technology access computing device 120 may grant access and record complete session data until the user ends. Technology access computing device 120 may utilize permission-specific machine learning models of user behavior to detect abnormal behavior for a particular session (e.g., Figure 3 shown, and described below).
[0039] The technical access computing device 120 can generate an anomaly score for a session based on the session data and a permission-specific machine learning model. Access during a specific time period or from a specific location or device can be weighted toward anomalous behavior. Based on the anomaly score, a user's access to one or more technical assets 115 can be denied or restricted, or a prompt can be sent to other people or systems for investigation.
[0040] Grouping data by permissions can help identify similarities between different users 105 and different job functions. For example, users 105 with similar job functions may perform similar activities.
[0041] According to another embodiment, the technical access computing program 125 may detect behavior during the session itself, for example, based on keystrokes, user identification, user location, user computing device, time, files being accessed, copied and / or deleted, and so forth.
[0042] According to another embodiment, the technical access calculation program 125 may utilize data from multiple users or groups of users to build or update permission-specific machine learning models of behavior to help detect anomalies and drive automation.
[0043] According to one embodiment, the technical access computing program 125 can save time by, for example, detecting duplicate commands and alerting the automation team or the team using that authority to indicate that the activities they are performing can be made into automated microservices for future use.
[0044] Figure 2 A method for performing review activities during a privileged access session is described in accordance with an exemplary embodiment. Figure 2 The method may involve a requester, a reviewer, and / or an entity responsible for taking corrective action, such as a cybersecurity or human resources individual or team at an organization.
[0045] A requestor (eg, a privileged access user) may obtain proxy privileged access to a technology asset in step 205. An example of this is described in US patent application Ser. No. 16 / 220,784.
[0046] In one embodiment, privileged session activity may be collected. The format and / or content may depend on, for example, the platform on which the recording occurs. For example, Unix TM Platforms may allow text capture of standard input / output / error, and Windows TM The platform allows for logging, etc. However, the metadata for both is equivalent and depends on the reference data.
[0047] In step 210 , a reviewer (eg, administrator, supervisor, etc.) may review session data for activities performed by the requester after the privileged session has begun.
[0048] According to one embodiment, the technical access computing device may apply a permission-specific machine learning model to the session data to generate an anomaly score for the user session. This will be discussed below with respect to Figure 3 Discuss in more detail.
[0049] According to one embodiment, reviewers may review only sessions with anomaly scores above a certain threshold.
[0050] In another embodiment, the automated system can also approve or deny sessions based on a threshold score threshold. For example, a score in the range of 0.00 to 1.00 can be received, and a threshold (e.g., at 0.80) can be set to approve sessions above the threshold.
[0051] In step 215, the reviewer may determine whether the activities performed by the requester during the privileged session were appropriate, inappropriate, or whether additional information is required. For example, if the reviewer requires additional information or feedback from the requester, in step 220, the reviewer may request that the requester update a request ticket with such information. The requester may then return the request ticket to the reviewer along with the requested information.
[0052] If the reviewer determines that the activities performed by the requester during the privileged session were appropriate, then in step 225 the reviewer may indicate in the review system that the activities were appropriate.
[0053] For example, the reviewer may compare the activity to laws, rules, regulations, organizational policies, the reviewer's knowledge of the task for which access is being requested, and so on.
[0054] If the reviewer determines that the activities performed by the requester during the privileged session are inappropriate, such as not in compliance with laws, rules, regulations, organizational policies, etc., then in step 230, the reviewer may notify the entity responsible for taking corrective action, such as security (e.g., network security), human resources, etc. at the organization. In one embodiment, the action taken may depend on the reason why the activity was inappropriate. Examples of actions may include suspending or limiting the requester's access, notifying the user's supervisor, annotating the requester's performance evaluation, dismissing the requester from the organization, etc.
[0055] In one embodiment, after the review is complete, the technical access computing device may feed the results of the review as input to a privilege-specific machine learning model as additional training data.
[0056] Figure 3 A process for privileged access session-specific anomaly scoring is described in accordance with an exemplary embodiment.
[0057] Requester 305 (eg, a privileged access user) can obtain proxy privileged access to technology assets 310, such as by using a technology access management system. An example of this is disclosed in U.S. patent application Ser. No. 16 / 220,784.
[0058] Logs of agent privileged access can be recorded in a log server 315. The logs can include, for example, keystrokes, user identification, user location, user computing device and time, or which files are being accessed, copied, or deleted. From there, the log data can enter a real-time processing pipeline for attribute enrichment 320, anomaly scoring 330, and storage for further review 340.
[0059] In one embodiment, the log data may be combined with other information about what was accessed via attribute enrichment 320. For example, the log data may be extracted and, based on the contents of the log, other reference data about the privileged access session may be extracted from a reference store 325. For example, data such as the application services hosted on the device, the changes or incidents that led to the access, and other reference information about the server itself (e.g., the server's environment, location, operating system, etc.) may be collected from the reference store 325 based on, for example, the resources accessed and the permissions used in the access log.
[0060] The log data, along with other reference data, can then be processed for anomaly scoring 330. Anomaly scoring 330 can apply a machine learning algorithm to generate an anomaly score. Depending on the one or more permissions recorded in the log data, the anomaly scoring step can use one of a number of different permission-specific machine learning models 335.
[0061] According to one embodiment, the anomaly score may be a binary result. According to another embodiment, the anomaly score may be provided as a number within a range (e.g., 0-10, 0-100, etc.). Other ways of presenting the anomaly score may be used as needed and / or desired.
[0062] According to one embodiment, different permission models 335 may include, for example, an "administrative" model and an "application support" model based on administrative permissions and application support permissions. According to one embodiment, a different permission model may be used for each type of permission.
[0063] Once an anomaly score is generated, the resulting score, log data, and other reference data can be sent to repository 340 for further review by a reviewer. Reviewers 350 can access the data in repository 340 via portal 345 and an electronic device (not shown). Reviewers 350 can review a specific privileged access session and its anomaly score and other reference data, and can use this information to determine whether the user's actions were appropriate.
[0064] Reference information can include information that can be collected about the person using the requested privilege or about the asset associated with the privilege. The type of reference information can vary depending on the organization and / or asset. Examples of such information include, for example, whether the access is covered by regional regulations, whether the asset can hold personally identifiable information (PII), etc.
[0065] According to one embodiment, the results of the review can be provided as input to one or more privilege-specific models 335 as additional training data for supervised machine learning. For example, if a reviewer marks a privileged access session with a high anomaly score as inappropriate, the training model can use this data as a positive example. On the other hand, if a reviewer marks a privileged access session with a high anomaly score as appropriate, the training model can use this data as a negative example. This can create a feedback loop where the privilege-specific model gets better at detecting anomalous behavior with each review iteration.
[0066] According to one embodiment, in order to assign a score to each conversation, a classification model (e.g., multinomial naive Bayes) may be used to perform text classification. Other classifiers may be used as desired, for example, a logistic regression classifier may be used.
[0067] Figure 4 Methods for automatically detecting anomalous user behavior and taking appropriate action within a unified permissions framework are described in accordance with exemplary embodiments.
[0068] In step 405 , the technical access management system may receive a request for access to a technical asset from a user on a computing device.
[0069] According to one embodiment, the technical access management system may collect some or all of keystrokes, user identification, user location, user computing device, and time. The technical access management system may also have access to historical session information from the same user, other users within the organization, other users within the user's business group, and any other desired historical session information.
[0070] According to one embodiment, the technical access management system may also have access to other reference data, such as application services hosted on the device, changes or incidents that led to access, and other reference information about the server itself (e.g., the server's environment, location, operating system, etc.).
[0071] In step 410 , the technical access management system may apply a machine learning algorithm to the session information to generate an anomaly score.
[0072] According to one embodiment, the model may be based on historical session information. For example, a higher anomaly score may be generated when a user requests a technology asset outside of normal times, in a new location, using a new device, etc.
[0073] According to one embodiment, the model established can be permission-specific. For example, there can be different models depending on one or more permissions used during a session.
[0074] According to one embodiment, the technical access management system may also use other reference data for sessions or users as input to the machine learning algorithm.
[0075] In step 415 , the technical access management system may await further review of the session data by, for example, an administrator, supervisor, or the like.
[0076] According to one embodiment, the technical access management system may generate an alert signal when a session is ready for review, such as in the form of an electronic message (e.g., email, SMS, in-app message, push message, etc.) to one or more systems or individuals, such as individuals in the IT department. The alert signal may include an anomaly score.
[0077] In step 420, the technical access management system may grant or deny user access based on the results of the administrator's review. According to one embodiment, user access may be denied before further authorization is required. For example, after reviewing the generated prompt signal, authorization from other systems or individuals may be required. According to one embodiment, the user may be granted limited access before further authorization is required.
[0078] In step 425 , the technical access management system may update its machine learning model with the new data based on the results of the administrator review.
[0079] According to one embodiment, the technical access management system may update the permissions-specific model based on the results of the administrator review.
[0080] Figure 5 A method for automatically detecting user behavior within an automatable unified permissions framework is described in accordance with an exemplary embodiment.
[0081] In step 505, the technical access management system may receive a request for access to a technical asset from a user on a computing device. This may be similar to the above Figure 4 Step 405 in .
[0082] In step 510 , the technical access management system may grant the user access to the technical asset.
[0083] In step 515, the technical access management system may record session data for the user, including, for example, keystrokes, access times, user identification, device identification, locations accessed by the user, file deletions, file copies, file accesses, file edits or applications run, and any other session information needed and / or desired.
[0084] In step 520, the technical access management system can use the machine learning model to apply a machine learning algorithm based on previously recorded or historical session data for the user. In one embodiment, the historical session data can also include session data for other users (e.g., other users within a user group or business unit).
[0085] According to one embodiment, the machine learning model may be permissions specific.
[0086] According to one embodiment, the technical access management system may update the machine learning model based on current session data.
[0087] In step 525, the technical access management system may use the machine learning model to detect repeatable or automatable tasks within the permission. According to one embodiment, the repeatable or automatable task may be a task that is repeatedly performed by the current user or a task that is repeatedly performed across multiple users using the permission. According to one embodiment, the repeatable task may be restarting a service on a computer device, sending logs to a predetermined destination, etc.
[0088] In step 530, the technical access management system can alert the automation team or the team using the privilege to indicate that the task being performed can be made into an automated microservice for future use. This can reduce the use of privileged access by automating the tasks performed during the privilege period.
[0089] The task may be automated in step 535. In one embodiment, as part of the automation process, testing may be performed to verify that the automated task performs as expected.
[0090] Hereinafter, general aspects of implementation of the systems and methods of the embodiments will be described.
[0091] The system of an embodiment or a portion of the system of an embodiment may be in the form of a "processor", such as, for example, a general-purpose computer. As used herein, the term "processor" will be understood to include at least one processor using at least one memory. The at least one memory stores an instruction set. The instructions may be stored permanently or temporarily in one or more memories of the processor. The processor executes the instructions stored in the one or more memories in order to process data. The instruction set may include various instructions for performing one or more specific tasks (such as those described above). Such an instruction set for performing specific tasks may be characterized as a program, a software program, or simply as software.
[0092] In one embodiment, the processing machine may be a dedicated processor.
[0093] As mentioned above, the processing machine executes instructions stored in one or more memories to process data. This processing of data may, for example, be in response to commands by one or more users of the processing machine, in response to previous processing, in response to a request by another processing machine, and / or any other input.
[0094] As mentioned above, the processing machine used to implement the embodiments can be a general-purpose computer. However, the processing machine described above can also utilize any of a variety of other technologies, including special-purpose computers, computer systems (including, for example, microcomputers, minicomputers, or mainframe computers), programmed microprocessors, microcontrollers, peripheral integrated circuit components, CSICs (customer-specific integrated circuits) or ASICs (application-specific integrated circuits) or other integrated circuits, logic circuits, digital signal processors, programmable logic devices (such as FPGAs, PLDs, PLAs, or PALs), or any other device or arrangement of devices capable of implementing the steps of the processes of the embodiments.
[0095] The processor used to implement the embodiments may utilize a suitable operating system. Thus, embodiments of the embodiments may include processors running: iOS operating system, OSX operating system, Android operating system, Microsoft Windows TM Operating system, Unix operating system, Linux operating system, Xenix operating system, IBM ATX TM Operating system, Hewlett-Packard UX TM Operating system, Novell Netware TM Operating system, Sun Microsystems Solaris TM Operating system, OS / 2 TM Operating system, BeOS TM Operating system, Macintosh operating system, Apache operating system, OpenStep TM operating system or another operating system or platform.
[0096] It should be understood that in order to practice the method described above, the processor and / or memory of the processing machine do not have to be physically located in the same geographical location. That is, each of the processor and memory used by the processing machine can be located in geographically different locations and connected to communicate in any suitable manner. In addition, it should be understood that each of the processor and / or memory can be composed of different physical pieces of equipment. Therefore, the processor does not have to be a single piece of equipment in one location, and the memory does not have to be another single piece of equipment in another location. In other words, it is contemplated that the processor can be two pieces of equipment in two different physical locations. The two different pieces of equipment can be connected in any suitable manner. In addition, the memory can include two or more portions of memory in two or more physical locations.
[0097] For further clarification, as described above, processing is performed by various components and various memories. However, it should be understood that, according to alternative embodiments, processing performed by two different components as described above may be performed by a single component. Alternatively, processing performed by one different component as described above may be performed by two different components. Similarly, according to alternative embodiments, memory storage performed by two different memory portions as described above may be performed by a single memory portion. Alternatively, memory storage performed by one different memory portion as described above may be performed by two memory portions.
[0098] In addition, various technologies may be used to provide communication between the various processors and / or memories, as well as to allow the processors and / or memories to communicate with another entity; that is, for example, to obtain additional instructions or access and use remote memory storage. For example, such technologies for providing such communication may include a network (Internet, intranet, extranet, LAN, Ethernet), wireless communication via cellular towers or satellites, or any client-server system that provides communication. Such communication technologies may use any suitable protocol, such as, for example, TCP / IP, UDP, or OSI.
[0099] As described above, an instruction set may be used in the processing of the embodiments. The instruction set may be in the form of a program or software. For example, the software may be in the form of system software or application software. For example, the software may be in the form of a collection of separate programs, a program module within a larger program, or a portion of a program module. The software used may also include modular programming in the form of object-oriented programming. The software tells the processor what to do with the data being processed.
[0100] In addition, it should be understood that the instructions or instruction sets used in the implementation and operation of the embodiments can be in suitable form so that the processing machine can read the instructions. For example, the instructions forming the program can be in the form of a suitable programming language, which is converted into machine language or object code to allow one or more processors to read the instructions. In other words, the programming code or source code lines written in a specific programming language are converted into machine language using a compiler, assembler or interpreter. Machine language is a binary coded machine instruction specific to a particular type of processing machine (i.e., for example, specific to a particular type of computer). Computers understand machine language.
[0101] Any suitable programming language may be used in accordance with various embodiments. Illustratively, for example, the programming languages used may include assembly language, Ada, APL, Basic, C, C++, COBOL, dBase, Forth, Fortran, Java, Modula-2, Pascal, Prolog, REXX, Visual Basic, and / or JavaScript. Furthermore, it is not necessary to utilize a single type of instruction or a single programming language in conjunction with the operation of the systems and methods of the embodiments. Rather, any number of different programming languages may be utilized as needed and / or desired.
[0102] Furthermore, the instructions and / or data used in the practice of the embodiments can utilize any compression or encryption technology or algorithm, as can be expected. An encryption module can be used to encrypt data. Additionally, for example, files or other data can be decrypted using a suitable decryption module.
[0103] As described above, the embodiment can be illustratively embodied in the form of a processor including, for example, a computer or a computer system, and the computer or computer system includes at least one memory. It should be understood that, as desired, the instruction set (i.e., software) that enables the computer operating system to implement the operation described above can be included in any of a variety of media. In addition, the data processed by the instruction set can also be included in any of a variety of media. That is, for example, the specific medium (i.e., the memory in the processor) for preserving the instruction set and / or data used in the embodiment can take any of a variety of physical forms or transmissions. Illustratively, the medium can be paper, paper transparency, optical disc, DVD, integrated circuit, hard disk, floppy disk, optical disc, magnetic tape, RAM, ROM, PROM, EPROM, wire, cable, optical fiber, communication channel, satellite transmission, memory card, SIM card or other remote transmission and the form of any other medium or data source that can be read by the processor of the embodiment.
[0104] Additionally, as desired, the one or more memories used in a processor implementing an embodiment may be in any of a variety of forms to allow the memory to store instructions, data, or other information. Thus, the memory may be in the form of a database for storing data. The database may use any desired file arrangement, such as, for example, a flat file arrangement or a relational database arrangement.
[0105] In the system and method of an embodiment, a variety of "user interfaces" can be used to allow the user to be connected with one or more processing machine interfaces for implementing an embodiment. As used herein, a user interface comprises any hardware, software, or a combination of hardware and software used by a processing machine that allows the user to interact with the processing machine. For example, a user interface can be in the form of a dialogue screen. The user interface can also comprise any one of the following: a mouse, touch screen, keyboard, keypad, voice reader, voice recognizer, dialogue screen, menu box, list, check box, toggle switch, button, or any other device that allows the user to receive information about the operation of the processing machine when it processes an instruction set and / or provides information to the processing machine. Therefore, a user interface is any device that provides the communication between the user and the processing machine. For example, the information provided to the processing machine by the user through the user interface can be the form of a command, the selection of data, or some other input.
[0106] As discussed above, the processing machine that is implemented by the instruction set utilizes user interface so that the processing machine processes the data of the user.User interface is usually used by the processing machine, for interacting with the user, to carry information or to receive information from the user. However, it should be appreciated that, according to some embodiments, the human user actually does not need to interact with the user interface used by the processing machine. On the contrary, it is also possible to expect that the user interface can interact with another processing machine rather than the human user, that is, to carry and receive information. Therefore, other processing machines can be characterized as users. In addition, it is possible to expect that the user interface utilized in the system and method of the embodiment can interact with another processing machine or a plurality of processing machine parts, while also interacting with the human user part.
[0107] Those skilled in the art will readily appreciate that the present embodiments are susceptible to widespread utilization and application. Many embodiments and adaptations besides those described herein, as well as many variations, modifications, and equivalent arrangements will be apparent from the embodiments and the foregoing description thereof, or will reasonably be suggested by the embodiments and the foregoing description thereof, without departing from the spirit or scope of the embodiments.
[0108] Therefore, although the present exemplary embodiment has been described in detail herein, it should be understood that the present disclosure is merely illustrative and exemplary and is used to provide an enabling disclosure of the present disclosure. Therefore, the foregoing disclosure is not intended to interpret or limit the present embodiment or otherwise exclude any other such embodiments, adaptations, variations, modifications, or equivalent arrangements.
Claims
1. A computer-implemented method for automatically detecting abnormal user behavior within a unified permissions framework, the method comprising the following steps: In an information processing device comprising at least one computer processor: receiving, on a computing device, a request from a user for access to a technology asset, the access request including session data, the session data including one or more of a user identification, a user location, keystrokes, and a user computing device identification, wherein the technology asset includes a server, a computer, an application, an operating system, a storage device; applying a permission-specific machine learning algorithm to the session data to generate an anomaly score, the permission-specific machine learning algorithm being based on a permission category of the access request; storing the session data and the associated anomaly score; sending a review request to an administrator, the review request including session activity data associated with the session data; receiving a review result from the administrator in response to the review request; as well as The permission-specific machine learning algorithm is updated based on the anomaly score and the review result from the administrator.
2. The method according to claim 1, further comprising: Reference data associated with the access request is received. 3 . The method of claim 2 , wherein the reference data comprises at least one of an identification of an application service hosted on the computing device, a change or occurrence to the access request, and information about the technology asset.
4. The method of claim 1 , wherein the permissions-specific machine learning algorithm is based on historical session information. The method of claim 1 , wherein the anomaly score is higher in response to a first request for a technology asset. The method of claim 1 , wherein the anomaly score is higher in response to a first request from a computing device.
7. The method according to claim 1, further comprising: In response to the review result including a rejection, access to the technical asset is denied.
8. The method according to claim 1, further comprising: In response to the review result including approval, access to the technical asset is granted.
9. A computer-implemented system comprising: a computing device associated with a user; a server comprising at least one computer processor and executing a computer program; as well as Administrator electronic equipment; in: The computing device submits an access request from a user to access a technology asset, the access request including session data, the session data including one or more of a user identification, a user location, keystrokes, and a user computing device identification, wherein the technology asset includes a server, a computer, an application, an operating system, a storage device; the computer program applying a permission-specific machine learning algorithm to the session data to generate an anomaly score, the permission-specific machine learning algorithm being based on a permission category of the access request; the computer program storing the session data and associated anomaly scores; The computer program sends a review request with the anomaly score to the administrator electronic device; The computer program receives the review result from the administrator electronic device; as well as The computer program updates the privilege-specific machine learning algorithm based on the anomaly score and the review results from the administrator electronic device.
10. The system of claim 9, wherein the computer program can receive reference data associated with the access request, wherein the reference data includes at least one of an identification of an application service hosted on the computing device, a change or occurrence to the access request, and information about the technology asset.
11. The system of claim 9, wherein the permissions-specific machine learning algorithm is based on historical session information. 12 . The system of claim 9 , wherein the anomaly score is higher in response to a first request for a technical asset or in response to a first request from a computing device.
13. The system of claim 9, wherein access to the technical asset is denied in response to the review result comprising a rejection.
14. The system of claim 9, wherein access to the technical asset is granted in response to the review result comprising approval.
Citation Information
Patent Citations
Systems and methods for data driven infrastructure access control
US10951624B2
Supervised data transfer
US20140101750A1
Graph-Based Network Security Threat Detection Across Time and Entities
US20180219888A1