Automated policy refiner for cloud-based identity and access management systems
The policy refiner application analyzes event logs to generate more restrictive policy modification suggestions, addressing the issue of excessive permission granting in cloud provider networks and improving security and management efficiency.
Patent Information
- Application Number
- CN202380075866.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2022-09-30
- Filing Date
- 2023-09-12
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2043-09-12
AI Technical Summary
In cloud provider networks, users or administrators often grant entities more permissions than are required to perform operations, resulting in inefficient security and resource access management and a lack of automated means for policy refinement.
The policy refiner application analyzes event logs to identify and generate more restrictive policy modification suggestions, reduce the granting of permissions, and provides a graphical user interface to display the recommended modifications.
It improves security and resource access management efficiency in cloud environments, implements the least privilege policy, and enhances the security and fault tolerance of cloud-based entities and resources.
Smart Images

Figure CN120130048B_ABST
Abstract
Description
BACKGROUND
[0001] Cloud provider networks enable users to use various computing-related resources, such as computing resources, storage resources, networking resources, and the like. When a user or application interacts with a cloud provider network (e.g., using an application programming interface (API), command line interface (CLI), or web-based console provided by the cloud provider network), the user or application typically needs to provide security credentials that are used by the cloud provider to authenticate the user or application and determine whether the user or application has permission to access the requested resources or actions. Security credentials can include, for example, a username and password, an access key, and the like. BRIEF DESCRIPTION OF DRAWINGS
[0002] Various examples in accordance with the present disclosure will now be described with reference to the accompanying drawings, in which:
[0003] Figure 1 is an illustration of an environment including a policy refiner application for analyzing identity and access management policies created by users of a cloud provider network and recommending modifications to the identity and access management policies to reduce permissions granted by the policies, in accordance with some examples.
[0004] Figure 2 is an illustration of an example use of an event processor to map events contained in event logs obtained from an account activity logging service to statements contained in a policy, in accordance with some examples.
[0005] Figure 3 is an illustration of an example use of a policy refiner analyzer to generate policy refinement recommendations associated with a statement of a policy, in accordance with some examples.
[0006] Figure 4 is an example user interface displaying recommended modifications to a policy as generated by a policy refiner application, in accordance with some examples.
[0007] Figure 5 is a flowchart illustrating operations of a method for using a policy refiner application to analyze identity and access management policies created by users of a cloud provider network and recommending modifications to the identity and access management policies to reduce permissions granted by the policies, in accordance with some examples.
[0008] Figure 6 An example provider network environment is illustrated, in accordance with some examples.
[0009] Figure 7 is a block diagram of an example provider network providing storage services and hardware virtualization services to customers, in accordance with some examples.
[0010] Figure 8is a block diagram that illustrates an example computer system which can be used in some examples. DETAILED DESCRIPTION
[0011] The present disclosure relates to methods, apparatuses, systems, and non-transitory computer-readable storage media for a policy refiner application for analyzing identity and access management policies created by users of a cloud provider network and recommending modifications to these identity and access management policies to reduce the permissions granted by the policies (e.g., to move the policies toward least-privilege permissions). According to some examples, a policy refiner application (e.g., implemented as a standalone software application, a web-based service, etc.) receives a policy to analyze as input, as well as event logs related to activity associated with one or more accounts of the cloud provider network (e.g., as generated by an account activity logging service). The policy refiner application can identify actions that are permitted based on particular statements contained in the policy from the event logs. Based on field values contained in corresponding events, the policy refiner application generates abstractions of the field values, where the abstractions of the field values can represent more restrictive versions of the fields from the perspective of the policy (e.g., because it limits the associated policy statements to fewer actions, smaller IP address ranges, etc.). In some examples, these abstractions can be presented to users as recommendations to modify their policies to reduce the permissions granted by the policies.
[0012] Cloud provider networks typically include services and tools that enable users to securely control access to their resources (objects provided by the services of the cloud provider network, such as, for example, compute instances, storage resources, users or roles, etc.). For example, these services and tools widely allow users to control who is authenticated (i.e., logged in) and authorized (i.e., has permission) to access and use certain resources. Users can manage access management by creating policies and attaching these policies to identities (users, groups of users, or roles) or resources (e.g., storage resources, compute resources, etc.). As a best practice, it is often recommended that users grant only the permissions that are needed to perform the tasks that the users controlling the set of accounts desire.
[0013] However, administrators and developers sometimes grant entities (users or roles) permissions beyond what is necessary for those entities to perform the operations that those entities are expected to perform. In some examples, cloud providers provide tools that can be used to automatically create policies based on access activity recorded for one or more entities. For example, some tools can generate a policy template that contains the permissions used by an entity over a specified date range. A user can then use the template to create a policy with more granular permissions that only grants the permissions needed to support a particular use case. The assumption with such tools is that a user’s actual access to resources over time can be a better indication of what permissions should be granted. However, administrators and developers can also benefit from a continuous review of existing policies to have an opportunity to refine the permissions contained therein, which current users are unable to perform such analysis in an automated manner.
[0014] The described policy refiner application addresses these challenges and others by enabling a user to refine the permissions contained in a policy based on an analysis of event logs that reflect access activity of one or more associated entities. In some examples, the policy refiner application summarizes information contained in the event logs as predicates that can be used as field values in one or more policies being analyzed. As indicated, the recommended modifications to the policy generated by the policy refiner application can be displayed to the user in a graphical user interface (GUI), enabling the user to review the recommendations and easily implement the recommended modifications to the policy as desired. Among other benefits, the use of the policy refiner application enables a user to more efficiently arrive at a least-privilege policy based on account activity that occurs over time, thereby improving the security and fault tolerance of the user’s cloud-based entities and resources.
[0015] Figure 1is an illustration of an environment that includes a policy refiner application for analyzing identity and access management policies created by users of a cloud provider network and recommending modifications to those identity and access management policies to reduce permissions granted by the policies, in accordance with some examples. Provider network 100 (or "cloud" provider network) provides users with the ability to use one or more of various types of computing-related resources, such as compute resources (e.g., execute virtual machine (VM) instances and / or containers, execute batch jobs, execute code without provisioning servers), data / storage resources (e.g., object storage, block-level storage, data archival storage, databases and database tables, etc.), network-related resources (e.g., configure virtual networks (including compute resource groupings), content distribution networks (CDNs), domain name services (DNS)), application resources (e.g., databases, application build / deployment services), access policies or roles, identity policies or roles, machine images, routers, and other data processing resources, etc. These and other computing resources can be provided as services, such as a hardware virtualization service that can execute compute instances, a storage service that can store data objects, etc. Users (or "customers") of provider network 100 can use one or more user accounts associated with a customer account, but these items can be used somewhat interchangeably depending on the usage context. Users can interact with provider network 100 via one or more interfaces 106 across one or more intermediate networks 104 (e.g., the Internet), such as by using application programming interface (API) calls, via a console implemented as a website or application, etc. An API refers to an interface and / or communication protocol between a client and a server, such that if the client issues a request in a predefined format, the client should receive a response in a specific format or initiate a defined action. In the cloud provider network context, APIs provide gateways to enable customers to access cloud infrastructure by allowing customers to obtain data from or cause actions within the cloud provider network, thereby enabling the development of applications that interact with resources and services hosted in the cloud provider network. APIs can also enable different services of the cloud provider network to exchange data with each other. Interfaces 106 can be part of or act as a front end to a control plane 108 of provider network 100, which includes "backend" services that support and implement services that can be provided more directly to customers.
[0016] For example, a cloud provider network (or simply “the cloud”) generally refers to a large pool of accessible virtualized computing resources, such as computing, storage, and networking resources, applications, and services. The cloud can provide convenient, on-demand network access to a shared pool of configurable computing resources that can be programmatically provisioned and released in response to customer commands. These resources can be dynamically provisioned and reconfigured to adjust to variable load. Thus, cloud computing can be considered both the applications delivered as services over a publicly accessible network (e.g., the Internet, a cellular communication network) and both the hardware and software in the cloud provider data centers that provide these services.
[0017] A cloud provider network can be formed as a plurality of regions, where a region is a geographic area in which the cloud provider has gathered data centers. Each region includes a plurality (e.g., two or more) availability zones (AZs) that are connected to each other via a private high-speed network (e.g., fiber-optic communication connections). An AZ (also referred to as a “zone”) provides an isolated failure domain that includes one or more data center facilities that have separate power, separate networking, and separate cooling from data center facilities in another AZ. A data center refers to a physical building or enclosure that houses and provides power and cooling for servers of the cloud provider network. Preferably, the AZs within one region are located far enough from each other that a natural disaster (or other failure-causing event) does not simultaneously affect more than one AZ or take more than one AZ offline.
[0018] A user can connect to an AZ of the cloud provider network 100 via a publicly accessible network (e.g., the Internet, a cellular communication network), for example, through a transit center (TC). A TC is a primary backbone location that links users to the cloud provider network and can be co-located at other network provider facilities (e.g., Internet service providers (ISPs), telecommunications providers) and securely connected to the AZs (e.g., via a VPN or direct connection). Each region can operate two or more TCs for redundancy. A region is connected to a global network that includes private networking infrastructure (e.g., fiber-optic connections controlled by the cloud provider) that connects each region to at least one other region. The cloud provider network can deliver content through edge locations and regional edge cache servers from access points (or “POPs”) that are located outside of, but networked to, these regions. This division and geographic distribution of computing hardware enables the cloud provider network to provide low-latency access to resources for users with a high degree of fault tolerance and stability on a global scale.
[0019] Generally, the business and operation of a provider network can be broadly subdivided into two categories: control plane operations carried on a logical control plane and data plane operations carried on a logical data plane. The data plane represents the movement of user data through the distributed computing system, while the control plane represents the movement of control signals through the distributed computing system. The control plane typically includes one or more control plane components that are distributed across and implemented by one or more control servers. Control plane traffic typically includes management operations, such as system configuration and management (e.g., resource placement, hardware capacity management, diagnostic monitoring, system state information). The data plane includes user resources (e.g., compute instances, containers, block storage volumes, databases, file storage) implemented on the provider network. Data plane traffic typically includes non-management operations, such as transferring user data to and from user resources. The control plane components are typically implemented on a separate set of servers from the data plane servers, and control plane traffic and data plane traffic can be sent over separate / different networks.
[0020] To provide these and other computing resource services, the provider network 100 generally relies on virtualization technology. For example, virtualization technology can provide users with the ability to control or use computing resources (e.g., “compute instances,” such as VMs using a guest operating system (O / S) that operates using a hypervisor that can or can not further operate on top of an underlying host O / S; containers that can or can not operate in a VM; compute instances that can execute on “bare metal” hardware without an underlying hypervisor), where a single electronic device can be used to implement one or more computing resources. Thus, users can directly use computing resources hosted by the provider network (e.g., provided by a hardware virtualization service) to perform various computing tasks. Additionally or alternatively, users can indirectly use computing resources by submitting code to be executed by the provider network (e.g., via an on-demand code execution service), which in turn uses one or more computing resources to execute the code, typically without the user having any control or knowledge of the underlying compute instances involved.
[0021] As described herein, one type of service that a provider network can provide can be referred to as a “managed computing service,” where the managed computing service executes code or provides computing resources for its users in a managed configuration. Examples of managed computing services include, for example, an on-demand code execution service, a hardware virtualization service 110, a container service, etc.
[0022] On-demand code execution services (referred to in various examples as function compute services, function services, cloud function services, functions-as-a-service, or serverless computing services) can enable users of the provider network 100 to execute their code on cloud resources without needing to select or manage underlying hardware resources for executing the code. For example, a user can use an on-demand code execution service by uploading their code and using one or more APIs to request that the service identify, provision, and manage any resources needed to run the code. Thus, in various examples, a “serverless” function can include code that is executable on-demand by a user or other entity, such as the provider network itself. A serverless function can be maintained within the provider network by an on-demand code execution service and can be associated with a particular user or account or generally accessible by multiple users / accounts. A serverless function can be associated with a uniform resource locator (URL), uniform resource identifier (URI), or other reference that can be used to invoke the serverless function. A serverless function can be executed by a computing resource, such as a virtual machine, container, or the like, when triggered or invoked. In some examples, a serverless function can be invoked by an application programming interface (API) call or a specially formatted hypertext transfer protocol (HTTP) request message. Thus, a user can define a serverless function that is executable on-demand without requiring the user to maintain dedicated infrastructure to execute the serverless function. Instead, the serverless function can be executed on-demand using resources maintained by the provider network 100. In some examples, these resources can be maintained in a “ready” state (e.g., with a pre-initialized runtime environment configured to execute the serverless function), allowing the serverless function to be executed in near real-time.
[0023] Hardware virtualization service 110 (referred to as elastic compute service, virtual machine service, compute cloud service, compute engine, or cloud compute service in various implementations) can enable users of provider network 100 to provision and manage computing resources, such as virtual machine instances 112. Virtual machine technology can use one physical server, for example, to run many servers’ equivalent (each of which is referred to as a virtual machine) using a hypervisor that can run at least on the server’s offload card (e.g., a card connected to the physical CPU via PCI or PCIe) and other components of the host can be used for some virtualization management components. Such offload cards of the host can include one or more CPUs that are not available to user instances, but are dedicated to instance management tasks, such as virtual machine management (e.g., hypervisor), input / output virtualization of network attached storage volumes, local migration management tasks, instance health monitoring, etc.). Virtual machines are often referred to as compute instances or simply “instances.” As used herein, provisioning a virtual compute instance generally includes reserving the resources (e.g., compute and memory resources) of an underlying physical compute instance for a client (e.g., from a pool of available physical compute instances and other resources), installing or launching the required software (e.g., an operating system), and making the virtual compute instance available to the client to perform the client-specified tasks.
[0024] Another type of managed computing service can be a container orchestration and management service (referred to in various implementations as a container service, a cloud container service, a container engine, or a container cloud service) that allows users of a cloud provider network to instantiate and manage containers. In some examples, the container service can be a Kubernetes-based container orchestration and management service (referred to in various implementations as a Kubernetes container service, an Azure Kubernetes Service, an IBM Cloud Kubernetes Service, a Kubernetes engine, or a Kubernetes container engine). As referred to herein, a container packages up code and all of its dependencies, so that an application (also referred to in various container services as a task, a pod, or a cluster) can run quickly and reliably across various computing environments. A container image is a standalone, executable software package that includes everything needed to run an application process: code, runtime, system tools, system libraries, and settings. A container image becomes a container at runtime. As such, a container is an abstraction at the application layer (meaning that each container emulates a different software application process). While each container runs an isolated process, multiple containers can share a common operating system, for example, by being launched within the same virtual machine. In contrast, a virtual machine is an abstraction at the hardware layer (meaning that each virtual machine emulates a physical machine that can run software). While multiple virtual machines can run on one physical machine, each virtual machine typically has its own copy of an operating system as well as an application and its associated files, libraries, and dependencies. Some containers can run on instances that run a container agent, and some containers can run on bare metal servers or on offload cards of servers.
[0025] In some examples, the identity and access management service 114 is a service that enables users to securely control access to resources of the cloud provider network (e.g., resources 116 associated with various provider network services 118, such as storage objects 120 associated with a storage service 122, databases associated with a database service, compute instances 112 associated with a hardware virtualization service 110, etc.). The identity and access management service 114 is widely used to control who is permitted to authenticate (e.g., log in) to the cloud provider network 100 and who is authorized (e.g., has permissions) to use resources provided by the cloud provider network. Generally speaking, a resource is a concept for a domain that captures items that can be created, read, modified, or deleted by a customer in the cloud provider network 100. Examples of resources also include identities (e.g., identities 128 including example users 130A,..., 130N and roles 132A,..., 132N) and policies 134 (e.g., including identity-based policies 136, trust policies 138, and other policies 140). Figure 1Further illustrating the concept of an organization 142, the organization can include any number of associated accounts 144A, 144B,..., 144N, which can also include any number of users and roles (e.g., roles 146 associated with account 144B and roles 148 associated with account 144N).
[0026] When a person initially creates an account with cloud provider network 100, the person can typically start with a single sign-on identity that has full access to all cloud provider network services and resources associated with the account (e.g., a root user of identity 128). For example, the root user identity can be accessed by logging in with a username (e.g., an email address) and password used to create the account. Cloud provider network 100 often recommends that users avoid using the root user for most tasks and instead create additional user accounts with limited permissions (e.g., such as one or more of users 130A,..., 130N). The user can then optionally grant different user accounts different permissions for different resources. For example, a user account can be configured to allow some users full access to hardware virtualization service 110, storage service 122, and other cloud provider network 100 resources. Other user accounts can allow read-only access to some storage buckets or allow permissions to manage some instances 112, etc.
[0027] In some examples, a principal is a person or application that requests an action or operation on a resource of cloud provider network 100 (e.g., a resource 116 or a resource of identity and access management service 114) via one or more identities. The set of identities 128 associated with account 144A can include any number of users 130A,..., 130N and roles 132A,..., 132N. When a principal uses an identity (e.g., a user or a role) to send a request to act or operate on a resource, a cloud provider network request occurs. The request can include some or all of the following information: the action or operation the principal wants to perform, the resource object on which to perform the action or operation, the person or application using the identity (e.g., a user or a role) to send the request, environmental data (e.g., information about IP address, user agent, SSL enabled status, time of day, etc.), and resource data (e.g., data related to the resource being requested, such as a resource identifier or tag name). In some embodiments, identity and access management service 114 collects the information contained in the request into a request context, which is used to evaluate and authorize the request.
[0028] In some examples, for a request to be completed, the identity and access management service 114 determines whether the request subject is authorized (e.g., permitted) to complete the request. During authorization, the identity and access management service 114 uses values included in the request context to check policies (e.g., one or more of the policies 134) that apply to the request. The identity and access management service 114 uses the policies 134 to determine whether to allow or deny the request. In some examples, the policies are stored by the identity and access management service 114 as JavaScript Object Notation (JSON) documents (or using any other data format) and specify permissions for a particular identity. There can be one or more types of policies 134 that can affect whether a request is authorized, including, for example, identity-based policies 136, trust policies 138, and other possible policies 140. For example, identity-based policies can be configured to provide users with permissions to access resources in their own account, while resource-based policies can be used to grant cross-account access to resources. In general, the identity and access management service 114 checks each policy that applies to the request context. If a single policy includes an action that is denied, the identity and access management service 114 denies the entire request. In some examples, the identity and access management service 114 denies requests by default, such that a request is authorized only if each part of the request is allowed by an applicable permissions policy.
[0029] Once a request is authenticated and authorized, the identity and access management service 114 approves the action or operation in the request. Operations are defined by services (e.g., the storage service 122, the hardware virtualization service 110, the identity and access management service 114, etc.) and include actions that can be performed on or with respect to a resource, such as viewing, creating, editing, and deleting the resource. For example, the identity and access management service 114 can support actions such as creating a user, deleting a user, creating a role, and assuming a role, among many other possible actions. To allow a subject to perform an operation, the action is included in a policy that applies to the subject or the affected resource.
[0030] In some examples, identity-based policy 136 represents a policy attached to an identity (such as a user, group, or role in an account). Resource-based policy represents a policy attached to a resource (such as storage object 120, instance 112, role trust policy, etc.). For example, resource-based policy controls what actions a subject can perform on that resource and under what conditions. In some examples, identity and access management service 114 supports trust policies 138 that can be attached to roles (e.g., one or more roles 132A, ..., 132N). Since a role is both an identity and a resource that supports resource-based policies, both trust policies and identity-based policies can be attached to roles. Trust policy 138 defines which subject entities (accounts, users, roles, and federated users) can assume that role.
[0031] In some examples, Figure 1 At circle "1" in the diagram, one or more users use electronic device 102 to generate an organization configuration request 164 to configure a set of accounts, identities, policies, etc., optionally associated with an organization (e.g., organization 142), and further configure policies 134 associated with some or all of these resources. For example, these identities may be created to provide authentication for users and processes within accounts (e.g., accounts 144A, ..., 144N) of the cloud provider network 100. As indicated above, identities represent subjects and can be authenticated and then authorized to perform actions within the cloud provider network 100, and each identity may be associated with one or more policies 134 to determine what actions a user or role can perform on which cloud provider network resources under what conditions. The set of accounts, identities, and policies may, for example, be created by an organization intending to use various services of the cloud provider network 100 for various purposes. Furthermore, the set of accounts, subjects, and policies constituting the organization may be modified over time according to the organization's expectations.
[0032] In some implementations, at circle "2", in response to organization configuration request 164, identity and access management service 114 creates and stores data representing accounts, identities, and policies. As indicated herein, fully privileged external users of cloud provider network 100 can add, edit, and remove these identities and policies, for example, using a web-based console, API, CLI, or other interfaces provided by identity and access management service 114, and can use various types of storage resources managed by identity and access management service 114 to store data representing subjects and policies. Individual subjects can then use the created users and roles as needed over time to perform actions related to the services provided by provider network 100, including, for example, creating and starting resources, modifying resources, deleting or terminating resources, etc.
[0033] In some examples, at circle "3", the account activity logging service 154 generates an event log 156 reflecting user activity in the cloud provider network 100. For example, the account activity logging service 154 can enable auditing, security monitoring, and operational troubleshooting. In some examples, events included in the event log 156 contain information about activity associated with a user account, such as, for example, an identifier of the user / role making the request, the service used, the action performed, parameters of the action, and response elements returned by the applicable service. In some examples, the event log can be stored by the account activity logging service 154 in a user's storage object 120 provided by the storage service 122, or in any other storage location accessible to the user desiring to view the log. In some examples, the account activity logging service 154 can also log data events, providing insight into resource ("data plane") operations performed on or within the resources themselves.
[0034] In some embodiments, at circle "4", the policy refiner service 150 receives a policy refinement request 166 to analyze possible modifications to one or more policies, making the one or more policies more restrictive. A user can generate the request 166 using a web-based console, an API, a CLI, or any other interface in which the user can identify one or more policies (e.g., one or more of the policies 134) to analyze. As shown, the policy refiner service 150 can be part of a broader set of security analysis tools 152 provided by the cloud provider network 100, where other tools can include a policy properties analyzer 158, as well as many other possible tools.
[0035] In some examples, the policy property analyzer 158 implements software for converting policies into a mathematical language and then using automated reasoning tools to check properties of the policies. The tools used by the policy property analyzer 158 can include automated reasoning machines called satisfiability modulo theories (SMT) solvers that use a mix of numbers, strings, regular expressions, dates, and IP addresses to prove and disprove logical formulas. With these tools, the policy property analyzer 158 can compare a given policy A to a “probe” policy (or more generally, another policy) to determine whether the policy A is more permissive than the probe policy (and optionally identify actions that one policy permits but the other policy does not). For example, to determine whether an identity A is permitted to delete a resource B, the policy analyzer 158 can be used to compare a policy associated with the identity A to a probe policy that does permit deletion of the resource B. In this example, the policy property analyzer 158 can provide an indication of whether the policy associated with the identity A is more permissive than the probe policy. In the context of the policy refiner service 150, the policy property analyzer 158 can be used to determine whether a proposed refinement of a policy generated as described herein does indeed cause the policy to be more restrictive than the policy without the proposed refinement (e.g., to ensure that the proposed modification moves the policy toward least privilege) and identify actions that the unmodified policy permits but the policy implementing one or more modifications does not.
[0036] In some examples, the policy refinement request 166 can include identifiers of one or more policies to analyze (e.g., one or more of the policies 134, which can include an organization-wide policy such as a service control policy) and an event log to use as part of the analysis (e.g., from the event logs 156 generated by the account activity logging service 154). The user can provide identifiers of the storage location of the one or more policies and the event log within the provider network 100, upload copies of the one or more policies and the event log, or otherwise provide the information contained therein to the policy refiner service 150. In some examples, the policy refinement request 166 can include an indication of a time period in the event log 156 to analyze (e.g., only the last 30 days, the last 60 days, the last 90 days, etc.), one or more specific accounts or roles of interest, one or more services of the cloud provider network 100 whose action requests are of interest, etc., to optionally limit the scope of the analysis. Based on the policy refinement request 166 and any optional parameters provided by the user, the policy refiner service 150 can obtain the policy 160 (or optionally multiple policies) at circle “5” and the event log 162 from the event log 156 at circle “6” for the requested analysis.
[0037] In some examples, at circle "7", the policy refiner service 150 uses the event processor 168 to process events in the event log 162 to extract information relevant to the refinement analysis to be performed by the policy refinement analyzer 124. At a high level, the event processor 168 is used to parse events in the event log 162 and create mappings between individual events and one or more statements from the policy 160 that caused the identity and access management service 114 to grant the request represented by the event. For example, if an event in the event log 162 describes an action by a user account from the organization 142 to launch a compute instance 112, the event processor 168 can identify one or more statements from the policy 160 that caused the identity and access management service 114 to grant the request.
[0038] Figure 2 is an illustration of using an event processor to map events contained in an event log obtained from an account activity logging service to statements contained in a policy, according to some examples. As shown, the policy refiner service 150 provides the policy 160 and the event log 162 to the event processor 168. For example, the policy snippet 200 illustrates a portion of the policy 160. In this example, the policy snippet 200 illustrates a policy statement that indicates that one or more actions (e.g., actions matching the "ss:List*" and "ss:Put*" field values, e.g., any action beginning with the string "ss:List" or "ss:Put") are granted with respect to one or more resources (e.g., resources identified by the resource identifier "ID:ss:::test- * ", e.g., any resource whose identifier begins with the string "ID:ss:::test-"). Figure 2
[0039] The example event log snippet 202 illustrates a portion of the event log 162 that illustrates event log entries corresponding to actions performed by the user "Alice". The event log shown in the event log snippet 202 indicates that the user Alice performed actions named "ListObjects", "ListObjectVersions", and "PutObject" at various times. In this example, the statement illustrated in the policy snippet 200 grants each of the actions. Other event logs contained in the event log 162 can represent other actions that can be performed by other users, and the same or different statements contained in the policy 160 can grant.
[0040] As shown, in some examples, the event processor 168 creates event-to-policy statement mapping 204 data that identifies relationships between events in the event log 162 and statements contained in the policy 160. In this example, the event-to-policy statement mapping 204 data indicates that the event log entry for the "ListObjects" action performed by the user "Alice" at 10:00 AM on 2021- 01-01 corresponds to the statement illustrated in the policy snippet 200. Similarly, the event-to-policy statement mapping 204 data indicates that the event log entry for the "ListObjectVersions" action performed by the user "Alice" at 10:30 AM on 2021-01-01 corresponds to the statement illustrated in the policy snippet 200. The event-to-policy statement mapping 204 data also indicates that the event log entry for the "PutObject" action performed by the user "Alice" at 11:00 AM on 2021-01-01 corresponds to the statement illustrated in the policy snippet 200. Figure 2 In the illustrated example, the event processor 168 determines that the policy statement 208A permits each of the events 206A,..., 206M, while the policy statement 208N permits the event 206N). As illustrated in the figure, in some examples, two or more different policy statements contained in the policy 160 can permit an event (e.g., the event 206M is permitted based on a combination of the policy statement 208A and the policy statement 208N). The generated event-to-policy statement mapping 204 is provided back to the policy refiner service 150 for analysis described below.
[0041] Again returning to Figure 1 At circle "8", the policy refinement analyzer 124 analyzes the information generated by the event processor 168 and generates one or more policy refinement recommendations 126 at circle "9" for the one or more policies being analyzed. Figure 3 is a diagram illustrating an example use of the policy refinement analyzer 124 to generate policy refinement recommendations associated with statements of a policy in accordance with some examples. As shown, the policy refinement analyzer 124 begins with a policy 160 containing a set of field value pairs 300 (e.g., field value pairs defining actions, resources, conditions, or other components of statements that make up the policy 160) and an event-to-policy statement mapping 204 generated by the event processor 168. In Figure 3 In the illustrated example, the policy refinement analyzer 124 has further mapped the field value pairs of the events contained in the event-to-policy statement mapping 204 to corresponding field value pairs 300 in the policy 160. For example, in Figure 3 In the illustrated example, the policy refinement analyzer 125 has mapped the field value pairs corresponding to the action names (e.g., "ListObjects" and "ListObjectVersions") from the events 304A,..., 304N to the corresponding policy statement field value pairs 302 (e.g., indicating that actions beginning with the name "ss:List*" or "ss:Put*" are permitted).
[0042] In some examples, once the policy refinement analyzer 124 has identified a plurality of event values from a plurality of events that correspond to a particular field value in a statement of a policy 160, a field value abstractor 306 is used to generate a refined field value, where the refined field value can correspond to a value that causes the policy 160 to be more restrictive than the policy 160 with the original field value. In some examples, the field value abstractor 306 uses one or more field-specific abstraction algorithms to produce a modified field value 314, and is intended to ensure that the modified field value 314 is more restrictive than the original field value. For example, the field value abstractor 306 can implement one field-specific abstraction algorithm for action names, another field-specific abstraction algorithm for Internet Protocol (IP) addresses, etc. In some examples, the particular field value within a policy that is analyzed by the field value abstractor 306 can include any of the following: an action type that the policy allows or denies, a resource that the statement is directed to, a condition under which a permission is granted, or any other policy field.
[0043] In some examples, the field value pair analyzed by the field value abstractor 306 can include an Internet Protocol (IP) address range (e.g., part of a policy condition that specifies that access to a resource is to be limited to a limited IP address range, etc.). In this example, the field-specific abstraction algorithm implemented by the field value abstractor 306 can generate a modified field value by determining an IP address range that includes the IP addresses contained in the plurality of events that match the particular field. For example, the field value abstractor 306 can identify the individual IP addresses associated with the various events, and determine the largest IP address range required to include the IP addresses. The field value abstractor 306 can then determine whether a second IP address range includes fewer IP addresses than the initial IP address range (e.g., whether the second IP address range is more restrictive than the range specified in the original policy), and if so, can provide the second IP address range as the modified field value.
[0044] As another example, if the field value pair being analyzed identifies a first plurality of actions (e.g., the actions identified in the policy statement field value pair 302), the field value abstractor 306 can implement a field-specific abstraction algorithm that generates a modified field value by identifying one or more second actions (e.g., actions that were actually performed by one or more users that the policy 160 permitted) corresponding to the particular field that are contained in the event-to-policy statement mapping 204. The field value abstractor can then determine whether the one or more second actions is less than the originally listed set of actions, and if so, generate the modified field value by enumerating the one or more second actions, or by generating a more restrictive string identifier for the plurality of actions.
[0045] As yet another example, if the particular field value being analyzed includes a first resource identifier that identifies multiple resources, the field value abstractor 306 can implement a field-specific abstraction algorithm that generates a modified field value by identifying a plurality of second resource identifiers contained in the plurality of events corresponding to the particular field. The field value abstractor 306 can then use the plurality of second resource identifiers to identify a third resource identifier based on at least one of: a longest common prefix of the plurality of second resource identifiers, or a longest common suffix of the plurality of second resource identifiers; and determine whether the third resource identifier is more restrictive than the first resource identifier. If yes, the field value abstractor can use the third resource identifier as the modified field value.
[0046] In some examples, execution of the field-specific abstraction algorithm can be executed in parallel across any number of independent computing resources (e.g., separate processing threads, VM instances, containers, servers, etc.). For example, execution of the field-specific abstraction algorithm can be performed incrementally such that the algorithm (e.g., abstraction algorithm 310) can be executed on a first subset of events (event field values 308A,..., event field values 308M) to obtain results 312A, and separately (e.g., in parallel using separate computing resources, or sequentially using the same resources) on a second subset of events (event field values 308N,..., event field values 308Z) to obtain results 312B. The abstraction algorithm 310 can then be executed on the results from these separate analyses to obtain results 312C, and so on as needed.
[0047] As indicated, in some examples, the policy refiner service 150 can determine, using the policy property analyzer 158, that a policy including the modified field value is more restrictive than a policy without the modified field value. As indicated, the policy property analyzer can use satisfiability modulo theories (SMT) solvers and other techniques to determine that a policy including the modified field value is more restrictive than a policy without the modified field value.
[0048] Returning to Figure 1 At circle “10,” the policy refiner service 150 generates a policy refinement report 170 that identifies one or more suggested modifications generated by the policy refinement analyzer 124, or otherwise provides access to one or more modified field values (e.g., one or more downstream components that use the modified field values to perform other types of analysis). Figure 4is an example user interface displaying recommended modifications to a policy as generated by a policy refinement application according to some examples. For example, the report interface 400 includes a policy refinement analysis report detailing information about the policy refinement process. As shown, the report can include information about the differences between a user's original policy and a policy with one or more suggested modifications. For example, the modified field value comparison 402 displays a proposed edit to a field value identifying resources that are permitted to perform one or more actions. In this example, the modified field value comparison 402 indicates a change to lengthen a matching string of characters used to identify resources that are permitted (e.g., because all events from the log that the corresponding statement is permitted for include resource identifiers containing at least the modified string value), thereby further restricting the policy. The policy refinement recommendations can generally include proposed modifications to any number of field values in the policy. In other examples, as an alternative or in addition to generating a policy refinement report, the policy refiner service 150 can automatically implement one or more of the suggested modifications.
[0049] In some examples, a user can provide input requesting to accept the suggested modification to the policy 160 (e.g., by providing input to the report interface 400 requesting to implement the change identified by the modified field value comparison 402). In response to such a request, the policy refiner service 150 stores a modified version of the policy associated with the user account based on the modified field value. The identity and access management service 114 can then use the modified policy to evaluate subsequent requests associated with the user account.
[0050] Many of the examples described herein involve identifying actions that are permitted based on statements included in a policy from event logs, and refining the policy statements that permit certain actions accordingly. Similar techniques can also be used to refine "deny" statements, i.e., statements that deny one or more types of actions based on conditions specified in the policy. For example, a policy refiner can take as input a set of events (e.g., provided as an event log or in any other format), that a user desires to be denied by a policy that the user is creating. In this example, the policy refiner can use a longest common prefix, a longest common suffix, or other type of analysis to generate a deny policy statement that denies each event identified in the input. The policy refiner refines in a way such that the deny statement denies the identified events but does not overly restrict (e.g., it does not simply deny all events).
[0051] Figure 5is a flowchart of operations 500 illustrating a method of analyzing identity and access management policies created by users of a cloud provider network and recommending modifications to the identity and access management policies to reduce permissions granted by the policies, in accordance with some examples, using a policy refiner application. Some or all of the operations 500 (or other processes described herein, or variations and / or combinations thereof) are performed under the control of one or more computer systems configured with executable instructions (e.g., computer programs, one or more applications, or one or more program modules) and are implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) running on one or more processors, by hardware or combinations thereof. The code is stored on a computer-readable storage medium, for example, in the form of a computer program. The computer-readable storage medium is non-transitory. In some examples, one or more (or all) of the operations 500 are performed by the policy refiner service 150 of other figures.
[0052] The operations 500 include obtaining, at block 502, an event log related to activity associated with an account of a computing system.
[0053] The operations 500 also include identifying, at block 504, a policy associated with the account, wherein the policy includes a statement defining permissions associated with the account, and wherein the statement includes a plurality of field values defining the permissions.
[0054] The operations 500 also include identifying, at block 506, a plurality of events from the event log, the plurality of events indicating actions that are permitted based on the statement.
[0055] The operations 500 also include identifying, at block 508, a plurality of event values from the plurality of events corresponding to a particular field value of the plurality of field values in the statement.
[0056] The operations 500 also include generating, at block 510, a modified field value based on the plurality of event values, wherein the modified field value is generated using a field-specific abstraction algorithm, and wherein the modified field value is more restrictive than the particular field value.
[0057] The operations 500 also include providing, at block 512, access to the modified field value. In some examples, providing access to the modified field value includes causing a suggested modification to the policy to be displayed based on the modified field value.
[0058] In some examples, the operations also include invoking execution of the field-specific abstraction algorithm across two or more computing resources, wherein each of the two or more computing resources operates on a subset of the plurality of events; and combining results generated by the two or more computing resources to obtain the modified field value.
[0059] In some examples, the operation also includes: receiving input requesting a modification to the policy; and storing a modified version of the policy associated with an account based on the modified field values.
[0060] In some examples, the operation also includes using a policy property analyzer to determine that a policy including modified field values is more restrictive than a policy without modified field values, and wherein the policy property analyzer uses a satisfiability modulo theory (SMT) solver to determine that a policy including modified field values is more restrictive than a policy without modified field values.
[0061] In some examples, the operation also includes receiving a request for an analysis policy, wherein the request identifies at least one of the following: a time range for obtaining event logs, or an indication of one or more user accounts to be analyzed; and wherein obtaining event logs includes obtaining events within the time range or events associated with one or more user accounts.
[0062] In some examples, a specific field value among multiple field values identifies one of the following: the type of action that the policy allows or denies, the resource involved in the statement, or the conditions for granting the permission.
[0063] In some examples, a specific field value among multiple field values identifies a first Internet Protocol (IP) address range, and a field-specific abstraction algorithm generates the modified field value by: determining a second IP address range that includes IP addresses contained in multiple events corresponding to the specific field; determining that the second IP address range includes fewer IP addresses than the first IP address range; and using the second IP address range as the modified field value.
[0064] In some examples, a specific field value among multiple field values identifies a first plurality of actions, and a field-specific abstraction algorithm generates modified field values by: identifying one or more second actions contained in multiple events corresponding to a specific field; determining that one or more second actions are less than the first plurality of actions; and generating modified field values by enumerating one or more second actions.
[0065] In some examples, a particular field value among multiple field values is a first resource identifier that identifies multiple resources, and a field-specific abstraction algorithm generates the modified field value by: identifying multiple second resource identifiers contained in multiple events corresponding to the particular field; using the multiple second resource identifiers to identify a third resource identifier based on at least one of the following: the longest common prefix of the multiple second resource identifiers, or the longest common suffix of the multiple second resource identifiers; determining that the third resource identifier is more restrictive than the first resource identifier; and using the third resource identifier as the modified field value.
[0066] In some examples, the operations further include obtaining, using a policy property analyzer, an identifier of an action that is permitted by a policy without the modified field value but is not permitted by a policy with the modified field value, wherein the policy property analyzer determines that the action is permitted by a policy without the modified field value but is not permitted by a policy with the modified field value using a satisfiability modulo theories (SMT) solver; and causing display of the identifier of the action.
[0067] In some examples, the suggested modification to the policy is displayed in a graphical user interface (GUI) that displays a difference between the policy with the particular field value and the policy with the modified field value.
[0068] Figure 6 An example provider network (or "service provider system") environment according to some examples is illustrated. Provider network 600 can provide resource virtualization to customers via one or more virtualization services 610 that allow customers to purchase, lease, or otherwise obtain instances 612 of virtualized resources (including, but not limited to, compute resources and storage resources) implemented on devices within one or more provider networks in one or more data centers. Local Internet Protocol (IP) addresses 616 can be associated with resource instances 612; local IP addresses are internal network addresses for resource instances 612 on provider network 600. In some examples, provider network 600 can also provide public IP addresses 614 and / or ranges of public IP addresses (e.g., Internet Protocol version 4 (IPv4) or Internet Protocol version 6 (IPv6) addresses) that customers can obtain from provider 600.
[0069] Conventionally, the provider network 600 can allow customers of the service provider (e.g., customers operating one or more customer networks 650A-650C (or "client networks") comprising one or more customer devices 652) to dynamically associate at least some public IP addresses 614 assigned or allocated to the customer with particular resource instances 612 assigned to the customer via the virtualization service 610. The provider network 600 can also allow the customer to remap a public IP address 614 previously mapped to one virtualized computing resource instance 612 allocated to the customer to another virtualized computing resource instance 612 also allocated to the customer. Using the virtualized computing resource instances 612 and public IP addresses 614 provided by the service provider, customers of the service provider, such as operators of customer networks 650A-650C, can, for example, implement customer-specific applications and present the customer's applications on an intermediate network 640, such as the Internet. Other network entities 620 on the intermediate network 640 can then generate traffic to a destination public IP address 614 published by the customer networks 650A-650C; the traffic is routed to the service provider data center and, at the data center, via a network substrate to a local IP address 616 of a virtualized computing resource instance 612 currently mapped to the destination public IP address 614. Similarly, response traffic from the virtualized computing resource instance 612 can be routed back via the network substrate to the source entity 620 on the intermediate network 640.
[0070] A local IP address, as used herein, refers to an internal or "private" network address of, for example, a resource instance in a provider network. A local IP address can be within an address block reserved by Internet Engineering Task Force (IETF) Request for Comments (RFC) 1918 and / or have an address format specified by IETF RFC 4193, and can be mutable within the provider network. Network traffic originating from outside the provider network is not directly routed to a local IP address; rather, the traffic uses a public IP address that is mapped to the local IP address of the resource instance. The provider network can include networking equipment or devices that provide network address translation (NAT) or similar functionality to perform the mapping from public IP addresses to local IP addresses and vice versa.
[0071] A public IP address is an Internet-routable network address assigned to a resource instance by a service provider or customer. Traffic routed to a public IP address is, for example, translated via 1:1 NAT to a corresponding local IP address of a resource instance, and forwarded to the resource instance.
[0072] Some public IP addresses can be assigned by the provider network infrastructure to particular resource instances; these public IP addresses can be referred to as standard public IP addresses, or simply standard IP addresses. In some examples, the mapping of standard IP addresses to local IP addresses of resource instances is a default launch configuration for all resource instance types.
[0073] At least some public IP addresses can be allocated to, or obtained by, customers of the provider network 600; a customer can then assign its allocated public IP addresses to particular resource instances allocated to the customer. These public IP addresses can be referred to as customer public IP addresses, or simply customer IP addresses. Rather than being assigned to resource instances by the provider network 600 as in the case of standard IP addresses, customer IP addresses can be assigned to resource instances by the customer, e.g., via an API provided by the service provider. Unlike standard IP addresses, customer IP addresses are allocated to a customer account, and can be remapped to other resource instances as needed or desired by the respective customer. A customer IP address is associated with a customer account rather than a particular resource instance, and the customer controls the IP address until the customer chooses to release the IP address. Unlike conventional static IP addresses, customer IP addresses allow a customer to mask resource instance or availability zone failures by remapping the customer's public IP addresses to any resource instance associated with the customer account. For example, a customer IP address enables a customer to resolve a problem with the customer's resource instance or software by remapping the customer IP address to an alternate resource instance.
[0074] Figure 7 is a block diagram of an example provider network environment providing storage services and hardware virtualization services to customers according to some examples. The hardware virtualization services 720 provide a plurality of computing resources 724 (e.g., compute instances 725 such as VMs) to customers. The computing resources 724 can be provided to customers of the provider network 700 (e.g., customers implementing customer networks 750) as a service, for example. Each computing resource 724 can be provisioned with one or more local IP addresses. The provider network 700 can be configured to route packets from the local IP addresses of the computing resources 724 to public internet destinations, and to route packets from public internet sources to the local IP addresses of the computing resources 724.
[0075] Provider network 700 can provide customers network 750, coupled to intermediate network 740 via local network 756, for example, the ability to implement virtual computing systems 792 via hardware virtualization services 720 coupled to intermediate network 740 and provider network 700. In some examples, hardware virtualization services 720 can provide one or more APIs 702, such as web service interfaces, via which customers network 750 can access functionality provided by hardware virtualization services 720, for example, via a console 794 (e.g., a web-based application, a standalone application, a mobile application, etc.) of a customer device 790. In some examples, at provider network 700, each virtual computing system 792 at customers network 750 can correspond to computing resources 724 that are leased, rented, or otherwise provided to customers network 750.
[0076] From instances of virtual computing systems 792 and / or another customer device 790 (e.g., via console 794), a customer can access functionality of storage services 710, for example, via one or more APIs 702, to access data from and store data to storage resources 718A-718N of virtual data stores 716 (e.g., folders or "buckets," virtualized volumes, databases, etc.) provided by provider network 700. In some examples, a virtualized data store gateway (not shown) can be provisioned at customers network 750, which can locally cache at least some data (e.g., frequently accessed data or critical data) and can communicate with storage services 710 via one or more communication channels to upload new or modified data from the local cache, such that a master data store (virtualized data stores 716) is maintained. In some examples, a user, via virtual computing systems 792 and / or another customer device 790, can install and access volumes of virtual data stores 716 via storage services 710 acting as a storage virtualization service, and these volumes can appear local (virtualized) storage 798 to the user.
[0077] While Figure 7 While not shown in FIG. 7, virtualization services can also be accessed from resource instances within provider network 700 via APIs 702. For example, a customer, a device service provider, or other entity can access virtualization services from within a respective virtual network on provider network 700 via APIs 702 to request allocation of one or more resource instances within the virtual network or within another virtual network.
[0078] In some examples, a system implementing some or all of the technology described herein can include a general-purpose computer system (such as Figure 8The computer system 800 is shown as a single computing device, but in various examples, the computer system 800 can include one computing device or any number of computing devices configured to work together as the single computer system 800. Figure 8 The computer system 800 is shown as a single computing device, but in various examples, the computer system 800 can include one computing device or any number of computing devices configured to work together as the single computer system 800.
[0079] In various examples, the computer system 800 can be a uniprocessor system including one processor 810 or a multiprocessor system including several processors 810 (e.g., two, four, eight, or another suitable number). The processor(s) 810 can be any suitable processor capable of executing instructions. For example, in various examples, the processor(s) 810 can be general- purpose or embedded processors implementing any of a variety of instruction set architectures (ISAs), such as the x86, ARM, PowerPC, SPARC, or MIPS ISAs, or any other suitable ISA. In multiprocessor systems, each of the processor(s) 810 can often, but not always, implement the same ISA.
[0080] The system memory 820 can store instructions and data accessible by the processor(s) 810. In various examples, the system memory 820 can be implemented using any suitable memory technology, such as random-access memory (RAM), static RAM (SRAM), synchronous dynamic RAM (SDRAM), nonvolatile / Flash-type memory, or any other type of memory. In the illustrated example, program instructions and data used to implement one or more desired functions, such as those methods, techniques, and data described above, are shown to be stored within the system memory 820 as policy refiner service code 825 (e.g., executable to implement, in whole or in part, the policy refiner service 150) and data 826.
[0081] In some examples, I / O interface 830 can be configured to coordinate I / O traffic between processor 810, system memory 820, and any peripheral devices in the device, including network interface 840 and / or other peripheral interfaces (not shown). In some examples, I / O interface 830 can perform any necessary protocol, timing or other data transformations to convert data signals from one component (e.g., system memory 820) into a format suitable for use by another component (e.g., processor 810). In some examples, I / O interface 830 can include support for devices attached through various types of peripheral buses, such as a variant of the Peripheral Component Interconnect (PCI) bus standard or the Universal Serial Bus (USB) standard, for example. In some examples, for example, I / O interface 830 can be configured to
[0082] For example, network interface 840 can be configured to allow data to be exchanged between computer system 800 and other devices 860 attached to a network 850 (e.g., according to a Figure 1 protocol (e.g., Internet Protocol Suite) over the network 850. In various examples, network interface 840 can support communication via wired or wireless general data networks, such as any suitable type of Ethernet network, for example. Additionally, network interface 840 can support communication via telecommunication / telcommunication networks such as analog voice networks or digital fiber communications networks, via storage area networks (SAN) such as Fibre Channel SANs, or via any other suitable type of network and / or protocol.
[0083] In some examples, computer system 800 includes one or more offload cards 870A or 870B (including one or more processors 875, and possibly one or more network interfaces 840) that are connected using I / O interface 830 (e.g., a bus that implements a version of the Peripheral Component Interconnect Express (PCI-E) standard or another interconnect such as QuickPath Interconnect (QPI) or UltraPath Interconnect (UPI)). For example, in some examples, computer system 800 can act as a host electronic device that hosts computing resources such as compute instances (e.g., operating as part of a hardware virtualization service), and one or more offload cards 870A or 870B execute a virtualization manager that can manage compute instances executing on the host electronic device. As an example, in some examples, offload card 870A or 870B can perform compute instance management operations such as suspending and / or unsuspending compute instances, starting and / or terminating compute instances, performing memory transfer / copy operations, etc. In some examples, these management operations can be performed by offload card 870A or 870B in cooperation with a hypervisor (e.g., at the request of the hypervisor) executed by other processors 810A-810N of computer system 800. However, in some examples, the virtualization manager implemented by offload card 870A or 870B can accommodate requests from other entities (e.g., from the compute instances themselves), and can not cooperate with (or serve) any separate hypervisor.
[0084] In some examples, system memory 820 can be one example of a computer- accessible medium configured to store program instructions and data as described above. However, in other examples, program instructions and / or data can be received, sent or stored upon different types of computer-accessible media. Generally speaking, a computer-accessible medium can include any non-transitory storage media or memory media, such as magnetic or optical media, e.g., disk or DVD / CD coupled to computer system 800 via I / O interface 830. A non-transitory computer-accessible storage medium can also include any volatile or non-volatile media, such as RAM (e.g., SDRAM, double data rate (DDR) SDRAM, SRAM, etc.), read only memory (ROM), etc., that can be included in some examples of computer system 800 as system memory 820 or another type of memory. Further, a computer-accessible medium can include transmission media or signals such as electrical, electromagnetic, or digital signals, conveyed via a communication medium such as a network and / or a wireless link, such as can be implemented via network interface 840.
[0085] The various examples discussed or presented herein can be implemented in a wide variety of operating environments, which in some cases can include one or more user computers, computing devices, or processing devices which can be used to operate any of a number of applications. User or client devices can include any of a number of general purpose personal computers, such as desktop or laptop computers running a standard operating system, as well as cellular, wireless, and handheld devices running mobile software and capable of supporting a number of networking and messaging protocols. Such a system also can include a number of workstations running any of a variety of commercially-available operating systems, and other known applications for purposes such as development and database management. These devices also can include other electronic devices, such as dummy terminals, thin-clients, gaming systems, and / or other devices capable of communicating via a network.
[0086] Most examples utilize at least one network to facilitate communication between the various system components. This can facilitate, amongst other things, retrieving, automatically updating, and / or otherwise managing data associated with the various examples. This can be implemented using at least one network in communication with one another. This can be facilitated via at least one network in communication with one another. This network can include the Internet, intranets, extranets, effectuated private networks, etc., which are used by electronic devices and computers to communicate with one another. Such networks can use a variety of technologies and protocols to communicate, including, but not limited to, transmission control protocol / internet protocol (TCP / IP), file transfer protocol (FTP), universal plug and play (UPnP), network file system (NFS), common internet file system (CIFS), extensible messaging and presence protocol (XMPP), AppleTalk, etc. The network can include, for example, a local area network (LAN), a wide area network (WAN), a virtual private network (VPN), an intranet, an extranet, the Internet, a public switched telephone network (PSTN), an infrared network, a wireless network, and any combination thereof.
[0087] In examples utilizing a web server, the web server can run any of a variety of server or mid-tier applications, including HTTP servers, File Transfer Protocol (FTP) servers, Common Gateway Interface (CGI) servers, data servers, Java servers, business application servers, etc. The server(s) also can be capable of executing programs or scripts in response requests from user devices, such as by executing one or more Web applications that can be implemented as one or more scripts or programs written in any programming language, such as Java, C, C# or C++, or any scripting language, such as Perl, Python, PHP, or TCL, as well as combinations thereof. The server(s) can also include database servers, including without limitation those commercially available from Oracle(R), Microsoft(R), Sybase(R), IBM(R), etc.
[0088] The environments disclosed herein can include various data stores and other memory and storage media as discussed above. These can reside in a variety of locations, such as on a storage medium local to (and / or resident in) one or more of the computers or remote from any or all of the computers across the network. In a particular set of embodiments, the information can reside in a storage-area network (SAN) familiar to those skilled in the art. Similarly, any necessary files for performing the functions attributed to the computers, servers, or other network devices can be stored locally and / or remotely, as appropriate. Where a system includes computers in communication with each other, peer computers can exchange data, such as files, sy stems, programs, applications, or applets, and other computer executable instructions. These data can be transferred or conveyed using a storage means communicated over the network. The data stores can also be stored on other types of storage means such as a hard disk drive, a magnetic floppy disk, a magnetic hard disk, an optical disk, a tape, a flash memory card, or a memory array.
[0089] Such devices also can include a computer-readable storage media reader, a communications device (e.g., a modem, a network card (wireless or wired), an infrared communication device, etc.), and working memory as described above. The computer- readable storage media reader can be connected with a computer-readable storage medium, or media, such as a memory, a removable memory card or disc, or an optical disk. It will be appreciated that the computer-readable storage media can be inserted into the computer-readable storage media reader in a variety of different ways, including but not limited to, by way of example, through a port or drive or an interface. Additionally, it is contemplated that the computer-readable storage media reader can be connected with, or removed from, the computing device as needed. The computing device can also include other removable media, such as a floppy disk drive for floppy disks or other removable disk unit, a magnetic hard disk drive for magnetic hard disks or other magnetic storage media, an optical disk drive for optical disks or other optical storage media, a flash drive or other solid state memory, or an array of solid state memory devices. The computing device can further include devices, such as a universal serial bus (USB) adapter or port, a Bluetooth® device, a memory card reader, or a wireless local area network (WLAN) device, such as an 802.11 device, a Wi-Fi device, a WiMax device, or a cellular device, e.g., a Global System for Mobile Communications (GSM) device, a code division multiple access (CDMA) device, a Long-Term Evolution (LTE) device, or a 5G device.
[0090] Storage media and computer readable media for containing code, or portions of code, can include any appropriate media known or used in the art, including storage media and communication media, such as but not limited to volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage and / or transmission of information such as computer readable instructions, data structures, program modules or other data, including RAM, ROM, Electrically Erasable Programmable Read-Only Memory (EEPROM), flash memory or other memory technology, compact disc - read-only memory (CD-ROM), digital versatile disk (DVD), or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other medium which can be used to store the desired information and which can be accessed by a system device. Based on the disclosure and teachings provided herein, a person of ordinary skill in the art will appreciate other ways and / or methods to implement the various examples.
[0091] In the foregoing description, various examples have been described. For purposes of explanation, specific configurations and details have been set forth in order to provide a thorough understanding of the examples. However, it will also be apparent to one skilled in the art that the examples can be practiced without the specific details presented herein. Furthermore, well known features can have been omitted or simplified in order not to obscure the illustrative examples being described.
[0092] Parenthetical text is used herein, as well as boxes with dashed lines borders (e.g., large dashes, small dashes, dot dashes, and dots), to illustrate optional aspects that add additional features to some examples. However, this notation should not be taken to mean that these are the only options or optional actions, and / or that boxes with solid lines borders are not optional in some examples.
[0093] Reference numerals with a suffix letter (e.g., 718A through 718N) can be used to indicate one or more instances of a referenced entity can be present in various examples, and when multiple instances are present, each instance need not be identical, but can share some general characteristics or act in a common form. Further, unless explicitly indicated to the contrary, the use of a particular suffix does not imply a particular quantity of the entity. Thus, in various examples, two entities using the same or different suffix letters can or can not have the same quantity of instances.
[0094] Reference to "one example," "an example," etc., indicates that the example described can include a particular feature, structure, or characteristic, but every example can not necessarily include the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same example. Further, where a particular feature, structure, or characteristic is described in connection with an example, it is submitted that it is within the knowledge of one of ordinary skill in the art to effect such feature, structure, or characteristic in connection with other examples whether or not explicit
[0095] Further, in the various examples described above, unless otherwise specifically noted, disjunctive language such as the phrase “at least one of’ is meant to convey that the listed terms are included, individually or in any combination of one or more terms. Similarly, the phrases “one or more of’ or “at least one of’ or “one or more” are each intended to convey that the listed terms are included, individually or in any combination of one or more terms. Thus, the disjunctive language is not intended to be limiting, excluding, or otherwise precluding any of the listed terms from being utilized in the given example.
[0096] As used herein, the term “based on” (or similar) is an open term that is used to describe one or more factors that affect a determination or other action. It should be understood that this term is not intended to mean that additional factors cannot be involved in the determination or action. For example, a determination can be based on one or more factors listed, or based on the factors listed and one or more additional factors. Thus, if an action A is “based on” B, it should be understood that B is one factor that affects the action A, but it does not exclude the possibility of other factors also affecting the action. In some cases, the action A can be completely based on B.
[0097] Unless specifically stated otherwise, a reference to “a” or “an” item should be construed as including one or more items. For example, a phrase such as “a device configured to” or “a computing device” is intended to include one or more items of the recited item. Such one or more recited items can collectively be configured to perform the recited operation. For example, a “processor configured to perform operations A, B, and C” can include a first processor configured to perform operation A and a second processor configured to perform operations B and C, where the first and second processors are collectively configured to perform operations A, B, and C.
[0098] Furthermore, the words "may" and "can" are used in a permissive sense (i.e., meaning having the potential to), rather than the mandatory sense (i.e., meaning must). The words "include," "including," and "includes" are used in an open-ended way and, therefore, indicate the inclusion of, but not limitation to, what follows the word. Similarly, the words "have," "having," and "has" are also used in an open-ended way and, therefore, indicate the having of, but not limitation to, what follows the word. The terms "first," "second," "third," and the like are used as labels for nouns that they follow, such that the noun they modify can be identified as the object or matter to which such label is assigned, but such designation should not be taken to mean that the label has any numerical implication. Similarly, such numerical labels are generally not used to indicate a required quantity of a particular noun in the claims hereof, and thus a "fifth" element generally does not mean that there are four other elements, unless such elements are explicitly included in the claims or otherwise sufficiently clearly indicated to be present.
[0099] At least some embodiments of the disclosed technology can be described in view of the following clauses:
[0100] 1. A computer-implemented method comprising:
[0101] obtaining, by a policy refiner service of a cloud provider network, an event log related to activity associated with an account of the cloud provider network, wherein an event of the event log indicates an action performed with respect to a resource of the cloud provider network;
[0102] identifying a policy associated with the account, wherein the policy comprises a statement defining a permission associated with the account, wherein the statement comprises a plurality of field values defining the permission, and wherein a particular field value of the plurality of field values identifies one of: a type of action that the policy allows or denies, a resource to which the statement pertains, or a condition under which the permission is granted;
[0103] identifying, from the event log, a plurality of events indicating actions that were permitted based on the statement;
[0104] identifying, from the plurality of events, a plurality of event values corresponding to the particular field value in the statement;
[0105] generating a modified field value based on the plurality of event values, wherein the modified field value is generated using a field-specific abstraction algorithm, and wherein the modified field value is more restrictive than the particular field value; and
[0106] causing display of a suggested modification to the policy based on the modified field value.
[0107] 2. The computer-implemented method of clause 1, further comprising:
[0108] invoking execution of the field-specific abstraction algorithm across two or more computing resources, wherein each of the two or more computing resources operates on a subset of the plurality of events; and
[0109] combining results generated by the two or more computing resources to obtain the modified field value.
[0110] 3. The computer-implemented method of any of clauses 1-2, further comprising:
[0111] receiving input requesting acceptance of the proposed modification to the policy; and
[0112] storing a modified version of the policy including the modified field value in association with the account.
[0113] 4. A computer-implemented method comprising:
[0114] obtaining an event log related to activity associated with an account of a computing system;
[0115] identifying a policy associated with the account, wherein the policy includes a statement defining a permission associated with the account, and wherein the statement includes a plurality of field values defining the permission;
[0116] identifying a plurality of events from the event log that indicate actions that are permitted based on the statement;
[0117] identifying a plurality of event values from the plurality of events that correspond to a particular field value of the plurality of field values in the statement;
[0118] generating a modified field value based on the plurality of event values, wherein the modified field value is generated using a field-specific abstraction algorithm, and wherein the modified field value is more restrictive than the particular field value; and
[0119] providing access to the modified field value.
[0120] 5. The computer-implemented method of clause 4, further comprising:
[0121] invoking execution of the field-specific abstraction algorithm across two or more computing resources, wherein each of the two or more computing resources operates on a subset of the plurality of events; and
[0122] combining results generated by the two or more computing resources to obtain the modified field value.
[0123] 6. The computer-implemented method of any of clauses 4-5, further comprising:
[0124] receiving input requesting acceptance of the proposed modification to the policy; and
[0125] storing a modified version of the policy including the modified field value in association with the account.
[0126] 7. The computer-implemented method of any of clauses 4-6, further comprising determining, using a policy property analyzer, that the policy including the modified field value is more restrictive than the policy without the modified field value, and wherein the policy property analyzer uses a satisfiability modulo theories (SMT) solver to determine that the policy including the modified field value is more restrictive than the policy without the modified field value.
[0127] 8. The computer-implemented method of any of clauses 4-7, further comprising:
[0128] receiving a request to analyze the policy, wherein the request identifies a time range for which to obtain the event log; and
[0129] wherein obtaining the event log comprises obtaining events within the time range.
[0130] 9. The computer-implemented method of any of clauses 4-8, wherein a particular field value of the plurality of field values identifies one of: a type of action that the policy allows or denies, a resource to which the statement pertains, or a condition under which the permission is granted.
[0131] 10. The computer-implemented method of clause 4, wherein the particular field value of the plurality of field values identifies a first Internet Protocol (IP) address range, and wherein the field-specific abstraction algorithm generates the modified field value by:
[0132] determining a second IP address range, the second IP address range including IP addresses contained in the plurality of events that correspond to the particular field value;
[0133] determining that the second IP address range includes fewer IP addresses than the first IP address range; and
[0134] using the second IP address range as the modified field value.
[0135] 11. The computer-implemented method of clause 4, wherein the particular field value of the plurality of field values identifies a first plurality of actions, and wherein the field-specific abstraction algorithm generates the modified field value by:
[0136] identifying one or more second actions contained in the plurality of events corresponding to the particular field value;
[0137] determining that the one or more second actions are fewer than the first plurality of actions; and
[0138] generating the modified field value by enumerating the one or more second actions in the modified field value.
[0139] 12. The computer-implemented method of clause 4, wherein the particular field value of the plurality of field values is a first resource identifier that identifies a plurality of resources, and wherein the field-specific abstraction algorithm generates the modified field value by:
[0140] identifying a plurality of second resource identifiers contained in the plurality of events corresponding to the particular field value;
[0141] using the plurality of second resource identifiers, identifying a third resource identifier based on at least one of: a longest common prefix of the plurality of second resource identifiers, or a longest common suffix of the plurality of second resource identifiers;
[0142] determining that the third resource identifier is more restrictive than the first resource identifier; and
[0143] using the third resource identifier as the modified field value.
[0144] 13. The computer-implemented method of any of clauses 4 to 12, further comprising:
[0145] obtaining, using a policy property analyzer, an identifier of an action that is permitted by the policy without the modified field value but is not permitted by the policy with the modified field value, wherein the policy property analyzer determines that the action is permitted by the policy without the modified field value but is not permitted by the policy with the modified field value using a satisfiability modulo theories (SMT) solver; and
[0146] causing display of the identifier of the action.
[0147] 14. The computer-implemented method of any of clauses 4-13, wherein the suggested modification to the policy is displayed in a graphical user interface (GUI) that displays differences between the policy with the particular field value and the policy with the modified field value.
[0148] 15. A system comprising:
[0149] first one or more electronic devices to implement a policy refiner service in a cloud provider network, wherein the policy refiner service comprises instructions that, upon execution, cause the policy refiner service to:
[0150] obtain, from an account activity logging service of the cloud provider network, an event log related to activity associated with an account of a computing system;
[0151] identify a policy associated with the account, wherein the policy comprises a statement that defines permissions associated with the account, and wherein the statement comprises a plurality of field values that define the permissions;
[0152] identify, from the event log, a plurality of events that indicate actions that were permitted based on the statement;
[0153] identify, from the plurality of events, a plurality of event values that correspond to a particular field value of the plurality of field values in the statement;
[0154] generate a modified field value based on the plurality of event values, wherein the modified field value is generated using a field-specific abstraction algorithm, and wherein the modified field value is more restrictive than the particular field value; and
[0155] cause display of a suggested modification to the policy based on the modified field value; and
[0156] second one or more electronic devices to implement the account activity logging service in the cloud provider network, the account activity logging service comprising instructions that, upon execution, cause the account activity logging service to:
[0157] generate the event log related to activity associated with an account of the cloud provider network; and
[0158] provide the event log to the policy refiner service.
[0159] 16. The system of clause 15, wherein the policy refiner service further comprises instructions that, upon execution, cause the policy refiner service to:
[0160] invoking execution of the field-specific abstract algorithm across two or more computing resources, wherein each of the two or more computing resources operates on a subset of the plurality of events; and
[0161] combining results generated by the two or more computing resources to obtain the modified field value.
[0162] 17. The system of any of clauses 15-16, wherein the policy refiner service further comprises instructions that, when executed, cause the policy refiner service to:
[0163] receive input requesting acceptance of the proposed modification to the policy; and
[0164] store a modified version of the policy that includes the modified field value in association with the account.
[0165] 18. The system of any of clauses 15-17, wherein the policy refiner service further comprises instructions that, when executed, cause the policy refiner service to determine, using a policy property analyzer, that the policy including the modified field value is more restrictive than the policy without the modified field value, and wherein the policy property analyzer uses a satisfiability modulo theories (SMT) solver to determine that the policy including the modified field value is more restrictive than the policy without the modified field value.
[0166] 19. The system of any of clauses 15-18, wherein the policy refiner service further comprises instructions that, when executed, cause the policy refiner service to:
[0167] receive a request to analyze the policy, wherein the request identifies at least one of: a time range to obtain the event log, or an indication of one or more user accounts to analyze; and
[0168] wherein obtaining the event log comprises obtaining events within the time range or events associated with the one or more user accounts.
[0169] 20. The system of any of clauses 15-19, wherein a particular field value of the plurality of field values identifies one of: a type of action that the policy allows or denies, a resource involved in the statement, or a condition under which the permission is granted.
[0170] The description and drawings are, accordingly, to be regarded as illustrative rather than restrictive. However, it will be apparent that various modifications and changes can be contributed by those skilled in the art without departing from the broader aspects of the disclosure as set forth in the claims that follow.
Claims
1. A computer-implemented method comprising: obtaining, by a policy refiner service of a cloud provider network, an event log related to activity associated with an account of the cloud provider network, wherein events in the event log indicate actions performed with respect to resources of the cloud provider network; identifying a policy associated with the account, wherein the policy comprises a statement defining a permission associated with the account, wherein the statement comprises a plurality of field values defining the permission, and wherein a particular field value of the plurality of field values identifies one of: a type of action that the policy allows or denies, a resource to which the statement pertains, or a condition under which the permission is granted; identifying a plurality of events from the event log by: parsing the plurality of events from the event log, and mapping individual events from the event log to a statement from the policy that causes an identity and access management service to grant a request represented by the individual event based on the statement, the plurality of events indicating actions that are granted based on the statement; identifying a plurality of event values from the plurality of events that correspond to the particular field value in the statement; generating a modified field value based on the plurality of event values, wherein the modified field value is generated using a field-specific abstraction algorithm, and wherein the modified field value is more restrictive than the particular field value; determining, using a policy property analyzer, that a modified policy comprising the modified field value is more restrictive than a policy having the particular field value, wherein the policy property analyzer determines that the modified policy comprising the modified field value is more restrictive than a policy having the particular field value using a satisfiability modulo theories (SMT) solver; and causing display of a suggested modification to the policy based on the modified field value, wherein the suggested modification to the policy results in the modified policy comprising the modified field value.
2. The computer-implemented method of claim 1, further comprising: invoking execution of the field-specific abstraction algorithm across two or more computing resources, wherein each of the two or more computing resources operates on a subset of the plurality of events; and combining results generated by the two or more computing resources to obtain the modified field value.
3. The computer-implemented method of claim 1, further comprising: receiving input requesting acceptance of the suggested modification to the policy; and storing a modified version of the policy comprising the modified field value in association with the account.
4. A computer-implemented method comprising: obtaining an event log related to activity associated with an account of a computing system; identifying a policy associated with the account, wherein the policy comprises a statement defining a permission associated with the account, and wherein the statement comprises a plurality of field values defining the permission; identifying a plurality of events from the event log by: parsing the plurality of events from the event log and mapping individual events from the event log to a statement from the policy that causes an identity and access management service to grant a request represented by the individual event, the plurality of events indicating actions that are granted based on the statement; identifying, from the plurality of events, a plurality of event values that correspond to a particular field value of the plurality of field values in the statement; generating a modified field value based on the plurality of event values, wherein the modified field value is generated using a field-specific abstraction algorithm, and wherein the modified field value is more restrictive than the particular field value; determining, using a policy property analyzer, that a modified policy that includes the modified field value is more restrictive than a policy that has the particular field value, wherein the policy property analyzer determines that the modified policy that includes the modified field value is more restrictive than the policy that has the particular field value using a satisfiability modulo theories (SMT) solver; and causing display of a suggested modification to the policy based on the modified field value, wherein the suggested modification to the policy results in the modified policy that includes the modified field value.
5. The computer-implemented method of claim 4, further comprising: invoking execution of the field-specific abstraction algorithm across two or more computing resources, wherein each of the two or more computing resources operates on a subset of the plurality of events; and combining results generated by the two or more computing resources to obtain the modified field value.
6. The computer-implemented method of claim 4, further comprising: receiving input requesting acceptance of the suggested modification to the policy; and storing a modified version of the policy that includes the modified field value in association with the account.
7. The computer-implemented method of claim 4, further comprising: receiving a request to analyze the policy, wherein the request identifies a time range for which to obtain the event log; and wherein obtaining the event log comprises obtaining events within the time range.
8. The computer-implemented method of claim 4, wherein a particular field value of the plurality of field values identifies one of: a type of action that the policy allows or denies, a resource to which the statement pertains, or a condition under which the permission is granted.
9. The computer-implemented method of claim 4, wherein the particular field value of the plurality of field values identifies a first Internet Protocol (IP) address range, and wherein the field-specific abstraction algorithm generates the modified field value by: determining a second IP address range, the second IP address range including IP addresses contained in the plurality of events that correspond to the particular field value; determining that the second IP address range includes fewer IP addresses than the first IP address range; and using the second IP address range as the modified field value.
10. The computer-implemented method of claim 4, wherein the particular field value of the plurality of field values identifies a first plurality of actions, and wherein the field-specific abstraction algorithm generates the modified field value by: identifying one or more second actions contained in the plurality of events corresponding to the particular field value; determining that the one or more second actions are fewer than the first plurality of actions; and generating the modified field value by enumerating the one or more second actions in the modified field value.
11. The computer-implemented method of claim 4, wherein the particular field value of the plurality of field values is a first resource identifier that identifies a plurality of resources, and wherein the field-specific abstraction algorithm generates the modified field value by: identifying a plurality of second resource identifiers contained in the plurality of events corresponding to the particular field value; using the plurality of second resource identifiers, identifying a third resource identifier based on at least one of: a longest common prefix of the plurality of second resource identifiers, or a longest common suffix of the plurality of second resource identifiers; determining that the third resource identifier is more restrictive than the first resource identifier; and using the third resource identifier as the modified field value.
12. The computer-implemented method of claim 4, further comprising: obtaining, using the policy property analyzer, an identifier of an action that is permitted by the policy without the modified field value but is not permitted by the modified policy including the modified field value, wherein the policy property analyzer determines that the action is permitted by the policy without the modified field value but is not permitted by the modified policy including the modified field value using the SMT solver; and causing display of the identifier of the action.
13. The computer-implemented method of claim 4, wherein the suggested modification to the policy is displayed in a graphical user interface (GUI) that displays differences between the policy with the particular field value and the modified policy including the modified field value.
14. A system comprising: a first one or more electronic devices to implement a policy refiner service in a cloud provider network, wherein the policy refiner service includes instructions that, when executed, cause the policy refiner service to: obtain, from an account activity logging service of the cloud provider network, event logs related to activity associated with an account of a computing system; identify a policy associated with the account, wherein the policy includes a statement that defines a permission associated with the account, and wherein the statement includes a plurality of field values that define the permission; identifying a plurality of events from the event log by: parsing the plurality of events from the event log and mapping individual events from the event log to a statement from the policy that causes an identity and access management service to grant a request represented by the individual event, the plurality of events indicating actions that are granted based on the statement; identifying, from the plurality of events, a plurality of event values that correspond to a particular field value of the plurality of field values in the statement; generating a modified field value based on the plurality of event values, wherein the modified field value is generated using a field-specific abstraction algorithm, and wherein the modified field value is more restrictive than the particular field value; determining, using a policy property analyzer, that a modified policy that includes the modified field value is more restrictive than a policy that has the particular field value, wherein the policy property analyzer determines that the modified policy that includes the modified field value is more restrictive than the policy that has the particular field value using a satisfiability modulo theories (SMT) solver; and causing display of a suggested modification to the policy based on the modified field value, wherein the suggested modification to the policy results in the modified policy that includes the modified field value; and a second one or more electronic devices to implement the account activity logging service in the cloud provider network, the account activity logging service including instructions that, when executed, cause the account activity logging service to: generate the event log related to activity associated with an account of the cloud provider network; and provide the event log to the policy refiner service.
15. The system of claim 14, wherein the policy refiner service further includes instructions that, when executed, cause the policy refiner service to: invoke execution of the field-specific abstraction algorithm across two or more computing resources, wherein each of the two or more computing resources operates on a subset of the plurality of events; and combine results generated by the two or more computing resources to obtain the modified field value.
16. The system of claim 14, wherein the policy refiner service further includes instructions that, when executed, cause the policy refiner service to: receive input requesting acceptance of the suggested modification to the policy; and store a modified version of the policy that includes the modified field value in association with the account.
17. The system of claim 14, wherein the policy refiner service further includes instructions that, when executed, cause the policy refiner service to: receive a request to analyze the policy, wherein the request identifies at least one of: a time range for which to obtain the event log, or an indication of one or more user accounts to analyze; and wherein obtaining the event log includes obtaining events within the time range or events associated with the one or more user accounts.
18. The system of claim 14, wherein a particular field value of the plurality of field values identifies one of: an action type that the policy allows or denies, a resource to which the statement pertains, or a condition under which the permission is granted.
19. The system of claim 14, wherein the particular field value of the plurality of field values identifies a first Internet Protocol (IP) address range, and wherein the field-specific abstraction algorithm generates the modified field value by: determining a second IP address range, the second IP address range comprising IP addresses contained in the plurality of events corresponding to the particular field value; determining that the second IP address range comprises fewer IP addresses than the first IP address range; and using the second IP address range as the modified field value.
20. The system of claim 14, wherein the particular field value of the plurality of field values identifies a first plurality of actions, and wherein the field-specific abstraction algorithm generates the modified field value by: identifying one or more second actions contained in the plurality of events corresponding to the particular field value; determining that the one or more second actions is less than the first plurality of actions; and generating the modified field value by enumerating the one or more second actions in the modified field value.
Citation Information
Patent Citations
Log monitoring method, system and device and storage medium
CN111708679A
Automatic development and enforcement of least-privilege security policies
US10148701B1
Security policy analyzer service and satisfaibility engine
US20190007443A1