Data processing device, data processing method, and program

The data processing device enhances access control accuracy by analyzing monitoring information and policies, and selectively collecting additional data to address data insufficiency, ensuring precise access decisions while optimizing costs and response time.

JP2025127508APending Publication Date: 2025-09-02NEC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024024220
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-21
Publication Date
2025-09-02

AI Technical Summary

Technical Problem

Existing computing devices face challenges in accurately determining security functions due to insufficient data, leading to potential misjudgments in access control decisions.

Method used

A data processing device and method that includes obtaining monitoring information and access control policies, analyzing them to derive an evaluation, and selectively collecting additional data when necessary to enhance decision accuracy.

Benefits of technology

Enables accurate determination of accessibility by reducing uncertainty in access control decisions through strategic data collection, minimizing costs, response time, and maintaining user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025127508000001_ABST
    Figure 2025127508000001_ABST
Patent Text Reader

Abstract

To provide a data processing device, a data processing method, and a program that can contribute to accurate determination of accessibility.SOLUTION: The data processing device includes acquiring means for acquiring monitoring information and at least one access control policy, analyzing means for analyzing the monitoring information and at least one access control policy to derive an evaluation for determining accessibility, and determining means for determining whether to select at least one additional data source for additional data collection on the basis of the evaluation.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a data processing device, a data processing method, and a program. [Background technology]

[0002] Techniques are being developed to determine content handling with security in mind.

[0003] For example, Patent Document 1 discloses passive security for applications. Specifically, in Patent Document 1, a computing device includes a passive security engine that determines whether to perform respective security functions for at least two of the applications based on passive user information monitored by a monitoring module. A first respective security function associated with a first of the applications is different from a second respective security function associated with a second of the applications. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] JP 2016-523398 A (Translation of PCT application) Summary of the Invention [Problem to be solved by the invention]

[0005] As described above, the computing device in Patent Document 1 determines a specific security function to be processed based on monitored passive user information. However, there may be cases where there is insufficient data to determine a specific security function. In this case, the computing device may select an inaccurate security function.

[0006] An object of the present disclosure is to provide a data processing device, a data processing method, and a program that can contribute to accurate determination of accessibility. However, it should be noted that this object is only one of multiple objects that the multiple embodiments disclosed in this specification aim to achieve. Other objects or problems and new features will be apparent from the description of this specification or the accompanying drawings. [Means for solving the problem]

[0007] According to one aspect of the present disclosure, obtaining means for obtaining monitoring information and at least one access control policy; analysis means for analyzing the monitoring information and the at least one access control policy to derive an assessment for determining accessibility; determining whether to select at least one additional data source for additional data collection based on the evaluation; A data processing apparatus is provided, comprising:

[0008] According to one aspect of the present disclosure, obtaining monitoring information and at least one access control policy; analyzing the monitoring information and the at least one access control policy to derive an evaluation for determining accessibility; determining whether to select at least one additional data source for additional data collection based on the evaluation; A data processing method is provided, comprising:

[0009] According to one aspect of the present disclosure, obtaining monitoring information and at least one access control policy; analyzing the monitoring information and the at least one access control policy to derive an evaluation for determining accessibility; determining whether to select at least one additional data source for additional data collection based on the evaluation; There is a program that causes a computer to execute the above. [Effects of the Invention]

[0010] According to the present disclosure, it is possible to provide a data processing device, a data processing method, and a program that can contribute to accurate determination of accessibility. [Brief explanation of the drawings]

[0011] [Figure 1] FIG. 1 is a block diagram illustrating an example of a data processing device according to the present disclosure. [Figure 2] FIG. 2 is a flow chart illustrating an example of a method of a data processing apparatus according to the present disclosure. [Figure 3] FIG. 3 is a block diagram that schematically illustrates an example of an access management system according to the present disclosure. [Figure 4] FIG. 4 is a block diagram illustrating an example detailing an access management system according to the present disclosure. [Figure 5A] FIG. 5A shows an example of the determination result. [Figure 5B] FIG. 5B shows another example of the determination result. [Figure 6] FIG. 6 is a flow chart illustrating an example of a Policy Decision Point (PDP) method for an access management system according to the present disclosure. [Figure 7] FIG. 7 is a block diagram illustrating another example detailing an access management system according to the present disclosure. [Figure 8] FIG. 8 is a diagram illustrating an example of a hardware configuration of a computer system applicable to a data processing device and / or an access management system. DETAILED DESCRIPTION OF THE INVENTION

[0012] Embodiments according to the present disclosure will be described below with reference to the drawings. Note that the following description and drawings may be omitted or simplified as necessary for clarity of explanation. Furthermore, throughout the drawings, the same elements are represented by the same reference numerals and / or characters, and duplicate descriptions thereof may be omitted as necessary. This repetition is for the purposes of simplification and clarity, and does not in itself define a relationship between the various embodiments and / or configurations described.

[0013] Also, in this disclosure, unless otherwise specified, "at least one of A or B (A / B)" can mean either A or B, or both A and B. Similarly, when "at least one" is used in reference to more than two elements, it can mean any one of those elements, or any plurality of elements (including all elements). The use of the term "and / or" means that each alternative can be used individually or in combination with any or all of the other alternatives. Furthermore, it should be noted that in the description of this disclosure, elements described using the singular form "a," "an," "the," "one," etc. may refer to multiple elements unless otherwise specified.

[0014] Each figure or illustration is merely an example for illustrating one or more embodiments. Each figure may not be associated with just one particular embodiment, but may be associated with one or more other embodiments. As one skilled in the art will understand, various features or steps described with reference to any one of the figures can be combined with features or steps shown in one or more other figures to create, for example, an embodiment not explicitly shown or described. Not all features or steps shown in any one of the figures are necessarily required to describe an embodiment, and some features or steps may be omitted. The order of steps described in any of the figures may be changed as necessary.

[0015] (First embodiment) <Configuration explanation> 1, the data processing device 10 includes an acquisition unit 12, an analysis unit 14, and a determination unit 16. The data processing device 10 may be one or more computers and / or machines. As an example, at least one of the components in the data processing device 10 may be incorporated into a computer as a combination of one or more memories and one or more processors. For example, the one or more computers used as the data processing device 10 may be a management server or controller provided inside or outside a target system to be subject to access control.

[0016] The acquiring unit 12 acquires monitoring information and at least one access control policy. The monitoring information is generated by monitoring a target system that is subject to access control. Any method can be used to monitor the target system. Furthermore, the access control policy can determine whether a user action (e.g., access to a resource) is allowed or denied, and / or suggest one or more countermeasures against the user action in the target system.

[0017] The monitoring information may relate to at least one of the following parameters: device status, resource status, user status, and / or network status. Specifically, the monitoring information includes, but is not limited to, at least one of the following parameters: -security (e.g., sources of threats), -attack vectors, -Business impact, -Determining access routes, - enforcement costs, - the cost of miscontrol due to denial of access, - Urgency of access, -user roles, -Resource status, - resource confidentiality, -Network environment, and / or -Location, time, and / or other contextual attributes of the access. Additionally, after one or more Policy Enforcement Points (PEPs) are engaged, the monitoring information may include the availability of the PEP(s) and / or the workload of the PEP(s). These parameters may change over time and, therefore, may be referred to as dynamic parameters.

[0018] The monitoring information and / or the at least one access control policy acquired by the acquisition unit 12 may be stored internally or externally to the data processing device 10. Furthermore, the monitoring of the target system and the generation of the monitoring information may be performed by the data processing device 10 or by a separate computer.

[0019] The analysis unit 14 analyzes the monitoring information and at least one access control policy. Thus, the analysis unit 14 uses the analysis to derive a rating for determining accessibility. Rating refers to any form of information that indicates the degree to which access should be granted or denied. For example, the rating can take any value within a range from A to B (A>B), where A indicates that access is granted and B indicates that access is denied. In this case, if the rating value is close to (A+B) / 2, it is not possible to clearly determine whether access is granted or denied. However, the analysis unit 14 can derive a qualitative rating rather than a quantitative number.

[0020] The determining unit 16 determines whether to select at least one additional data source for additional data collection based on the evaluation. Specifically, the determining unit 16 may determine at least one additional data source for additional data collection when the evaluation indicates that it cannot be clearly determined whether access should be permitted or denied. In another example, the determining unit 16 does not need to select at least one additional data source when the evaluation clearly indicates that access should be permitted or denied. For example, when the evaluation can take values ​​from A to B (A>B), the determining unit 16 may determine at least one additional data source for additional data collection when the evaluation is less than or equal to AC (AB>C>0) and greater than or equal to B+D (AB>D>0 and AC>B+D). Furthermore, the determining unit 16 does not need to select at least one additional data source when the evaluation takes any other value.

[0021] The determining unit 16 may also determine whether to select one additional data source or multiple additional data sources according to the numerical value. For example, if the rating can take values ​​from A to B, the determining unit 16 may determine multiple additional data sources for additional data collection when the rating is less than or equal to ACE (AB>C+E>0 and E>0) and greater than or equal to B+D+F (AB>D+F>0, F>0 and ACE>B+D+F). If the rating is less than or equal to AC and greater than ACE, or if the rating is less than B+D+F and greater than or equal to B+D, the determining unit 16 may determine one additional data source for additional data collection. Furthermore, the determining unit 16 does not need to select at least one additional data source when the rating takes any other value. In this way, the determining unit 16 may change the number of additional data sources to be selected according to the rating value (and, optionally, the variability of each of the multiple additional data sources for the rating, and / or at least one of the cost, response time, or user experience of each of the multiple additional data sources).

[0022] If at least one additional data source is determined as a source for additional data collection, the analysis unit 14 may retrieve data from the additional data source via the acquisition unit 12 and use the data. As a result, the analysis unit 14 may derive an assessment again by using the additional data source. The re-derived assessment is expected to provide a clearer indication of whether to allow or deny access compared to the previously derived assessment.

[0023] <Flow description> Next, an example of the operation of the present disclosure will be described with reference to the flowchart of Fig. 2. Details of each process in Fig. 2 have already been described above, and the description thereof will be omitted as necessary.

[0024] First, the acquisition unit 12 acquires monitoring information and at least one access control policy (step S12). Next, the analysis unit 14 analyzes the monitoring information and the at least one access control policy to derive an evaluation for determining accessibility (step S14). After that, the determination unit 16 determines whether to select at least one additional data source for additional data collection based on the evaluation (step S16).

[0025] <Explanation of effect> As described above, the data processing device 10 can determine whether to select at least one additional data source for additional data collection. If an additional data source is selected, it can be used to clearly indicate whether access is permitted or denied. Thus, the data processing device 10 can contribute to an accurate determination of accessibility.

[0026] (Second embodiment) A second embodiment of the present disclosure will be described below with reference to the accompanying drawings. This second embodiment describes one of the specific examples of the first embodiment, but the specific example of the first embodiment is not limited to this embodiment.

[0027] <Configuration explanation> 3 is a block diagram illustrating an example of an access management system. Fig. 3 illustrates an example of zero-trust-based access control for communication in which a user A accesses a resource R in a target system. The access management system 100 includes a policy information point (PIP) 102, a policy administration point (PAP) 104, a policy decision point (PDP) 110, and a policy enforcement point (PEP) 120.

[0028] The PIP 102 acquires the monitoring information I and outputs it to the PDP 110. Although only one PIP 102 is shown in FIG. 3 for simplicity, multiple PIPs 102 may be provided. In this example, the multiple PIPs 102 include multiple collection agents that monitor the behavior of entities regarding access and generate the monitoring information I. The monitoring information I may be information monitored by a sensing module. Details of the monitoring information I have already been described in the first embodiment. For example, the monitoring information I includes packet headers sent by user A.

[0029] The PAP 104 outputs one or more security policies P (hereinafter, one or more security policies P are collectively referred to as security policies P) to the PDP 110. The security policies P correspond to the access control policies in the first embodiment. The PAP 104 may be configured with a database that stores the security policies P. The security policies P can be changed by the user.

[0030] PDP 110 analyzes monitoring information I and security policy P to generate one or more specific access rules (hereinafter, the one or more specific access rules are collectively referred to as specific access rules) to be applied by PEP 120. During this process, PDP 110 may convert the format of security policy P into a format that can be enforced by PEP 120. PDP 110 outputs the specific access rules to PEP 120.

[0031] PEP 120 allows or denies access by user A according to a specific access rule. For example, if monitoring information I indicates that "high CPU usage has been detected on the host" and security policy P defines that "if the CPU usage reports an abnormality, deny access from user A to resource R," PDP 110 generates a specific access rule indicating that PEP 120 should deny access by user A. Thus, in this scenario, PEP 120 denies access by user A according to the specific access rule.

[0032] Under zero-trust-based access control, each time a timed access to a target resource is attempted, a decision to grant or deny access is made using security policies and monitoring information I before granting access. The monitoring information I indicates the requestor (e.g., a user or a bot) and the status of the resource, which is continuously monitored. Also, while only one PEP 120 is shown in FIG. 3 for simplicity, multiple PEPs 120 managed by the PDP 110 may be provided.

[0033] In the example of Figure 3, if the PDP 110 does not receive sufficient monitoring information I, the PDP 110 may make an incorrect access decision (misjudgment), which may lead to miscontrol of access. Therefore, it is desirable for the PDP 110 to collect sufficient monitoring information I to accurately evaluate the behavior of the entity.

[0034] However, if all the monitoring data is collected by the PDP 110 at once, the following problems may arise. -Increased costs -Excess data from data sources -Increased response time - Reduced user experience / usability issues Therefore, it is also desirable for the PDP 110 to collect as much monitoring information I as necessary when making an access decision (i.e., to collect monitoring information I sequentially). The access management system 100 can achieve this solution as described in more detail below.

[0035] 4 is a block diagram illustrating an example of a detailed access management system 100. Specifically, FIG. 4 illustrates details of the PDP 110. The PDP 110 includes a decision engine 112, a decision score analyzer 114, a metric derivation unit 116, and a data source selection unit 118. The detailed processes performed by each unit are described below.

[0036] The decision engine 112 receives current monitoring information I and a security policy P regarding the target access. Based on the current monitoring information I and the security policy P, the decision engine 112 determines whether the target access should be permitted or denied. Specifically, the decision engine 112 generates a decision score for determining whether the target access should be permitted or denied. The decision score is an example of the evaluation value described in the first embodiment. The decision score can take a value from 1 to 0, where 1 indicates that the access is definitely permitted and B indicates that the access is definitely denied. If the decision score is 0.5 or close to 0.5, it cannot be clearly determined whether the access is permitted or denied. If the decision score is 0.5, this is a state in which the decision on the action on the access is most uncertain. The decision score can indicate the reliability of the action on the access.

[0037] The decision engine 112 also generates specific access rules based on the allow or deny decision and outputs them to the PEP 120. As described above, the PEP 120 allows or denies access according to the specific access rules.

[0038] Additionally, the decision engine 112 outputs the decision score for the target access, the outcome of the decision, the current monitoring information I, and the security policy P to the decision score analyzer 114 .

[0039] The decision engine 112 may utilize an algorithm or a table that uses, for example, rule matching, risk score-based, etc. As one example, an access decision may be made by inputting a combination of attributes to be determined into an algorithm and outputting information regarding the access decision for that combination. As another example, an access decision may be made by comparing the combination of attributes to be determined with combinations of attributes listed in a table and extracting access decision information corresponding to the combination to be determined in the table.

[0040] Alternatively, the decision engine 112 may be implemented by a pre-trained artificial intelligence (AI) model. The AI ​​model is trained by inputting training data including, for example, multiple sets of attribute combinations as samples and information indicating accessibility as a correct label. After training, the information of the attribute combination to be determined is input to the AI ​​model. In response to the input, the AI ​​model outputs information indicating accessibility corresponding to the information to be determined. The decision engine 112 can obtain the information on accessibility output by the inference process.

[0041] The decision score analyzer 114 analyzes the decision score information, the decision results, the current monitoring information I and the security policy P, and considers at least the following three analysis points for the metrics: (1) Reasons for approval / rejection, (2) Missing attributes, and (3) Score analysis. (1) indicates the reason why access is considered to be allowed / denied by the decision engine 112. (2) indicates which data is missing from the data required for the decision engine 112 to make a specific decision to allow or deny. (3) indicates how much information from which perspective would change (or improve) the decision score. Here, a change (or improvement) in the decision score means that the decision score approaches either 1 or 0 from its current value.

[0042] For example, the decision score analyzer 114 generates information (1) to (3) as follows: (1): Access is denied due to authentication failure, (2): The authentication flag was missing, and (3) If a verification flag / result is obtained, the decision score can be improved by 60%. Furthermore, if the decision score analyzer 114 does not find any missing attributes, the decision score analyzer 114 defines the information (2) as "no missing attributes found." Furthermore, if the decision score analyzer 114 determines that none of the information can improve the decision score, the decision score analyzer 114 defines the information (3) as "none of the information can improve the decision score." The decision score analyzer 114 outputs the information (1) to (3) and the decision score to the metric derivation unit 116.

[0043] The decision score analyzer 114 may utilize an algorithm to analyze the received information and take into account the analysis points of the metrics. As an example, an access decision may be made by inputting the received information into an algorithm and outputting the information of the analysis points of the metrics.

[0044] Alternatively, the decision score analyzer 114 may be implemented by a pre-trained AI model. The AI ​​model is trained by inputting training data including, for example, a decision score as sample information, a decision result, current monitoring information I, and security policy P, as well as information indicating a metric analysis point as a correct label. After training, the received information to be decided is input to the AI ​​model. In response to the input, the AI ​​model outputs information indicating a metric analysis point corresponding to the information to be decided. The decision score analyzer 114 can acquire the information on the metric analysis point through an inference process.

[0045] The metric derivation unit 116 receives the information (1) to (3), the decision scores, and the table from the source database 106. Data sources that are not currently used as the PIP(s) 102 are listed as additional data sources in the table in the source database 106. Based on the received information, the metric derivation unit 116 evaluates, for each additional data source listed in the table, the perspectives (1) to (3) of the additional data source and the data cost incurred by using the additional data source.

[0046] Consider the case where a table in the source database 106 indicates the following as additional data sources: (a) applying malware signature checks; (b) data encryption checks; (c) the application of MFA (multi-factor authentication); and (d) Checking the history log. In this case, the decision score analyzer 114 generates information (1) through (3) as follows: (1): Access is denied due to a suspicious IP address, (2): The authentication flag and TLS (Transport Layer Security) were missing, and (3): If DPI (Deep Packet Inspection) is performed, the decision score will be improved.

[0047] In this example, for each additional data source, the metric derivation unit 116 evaluates the perspectives (1) to (3) of the additional data source and the data cost incurred by using the additional data source. For example, the metric derivation unit 116 evaluates the perspectives (1) to (3) for (a) “apply malware signature check” as follows: (1) Reason: High, (2') Missing attributes: low, and (3') Analysis: Good. (1') means that (a) is highly relevant to the reason for rejection (i.e., suspicious IP address). (2') means that (a) is less relevant to the authentication flag and TLS in (2). (3') means that (a) is highly relevant to DPI and is effective in improving the decision score. The evaluation results of (1') to (3') can be called the data value of (a).

[0048] Furthermore, the metric derivation unit 116 evaluates the data cost of (a) "applying malware signature checks" as follows: (i) Response time: slow, (ii) computational cost: high, and (iii) User Experience: No impact on users. As described above, the data cost information includes response time, computational cost, and user experience aspects. However, the information may include at least one of these aspects, and may further include any kind of information related to costs.

[0049] The metric derivation unit 116 also evaluates the data values ​​and data costs of (b) to (d). The evaluations of the data values ​​and data costs of (a) to (d) can be referred to as "metric information" for the data source selection unit 118 to select one or more valid additional data sources. In this example, the metric derivation unit 116 evaluates these items based on qualitative evaluations (e.g., adjectives such as high, low, good, etc.). However, at least one of the evaluations (1) to (3) or the data cost evaluations may be based on quantitative numbers. The metric derivation unit 116 outputs the metric information to the data source selection unit 118.

[0050] Also, if the metric derivation unit 116 receives at least one of the information (2) that "no missing attributes are found" or the information (3) that "no information can improve the decision score" from the decision score analyzer 114, the metric derivation unit 116 does not need to evaluate the data values ​​and data costs for the additional data sources. In at least one of these two cases, the metric derivation unit 116 outputs information to the data source selection unit 118 indicating that it is not necessary to output metric information to the data source selection unit 118 or that it is not necessary to select one or more additional data sources.

[0051] The metric derivation unit 116 may utilize an algorithm to analyze the received information and evaluate data values ​​and data costs. As an example, an access decision may be made by inputting the received information into an algorithm and outputting data value and data cost information.

[0052] Alternatively, the metric derivation unit 116 may be implemented by a pre-trained AI model. The AI ​​model is trained by inputting training data including, for example, the information (1) to (3) and the decision score and a table from the source database 106 as sample information, and information indicating a data value and a data cost as a correct answer label. After training, the received information to be determined is input to the AI ​​model. In response to the input, the AI ​​model outputs information indicating a data value and a data cost corresponding to the information to be determined. The metric derivation unit 116 can obtain the information on the data value and the data cost through an inference process.

[0053] The data source selection unit 118 receives metric information from the metric derivation unit 116. As described above, the metric information includes data values ​​and data costs of the additional data sources. The data source selection unit 118 uses the metric information to select one or more valid additional data sources for additional data collection.

[0054] One specific example of an algorithm executed on the data source selection unit 118 is to select one or more additional data sources to maximize the confidence in the decision (i.e., minimize the uncertainty in the decision) when the additional data sources are used under a given condition of data cost. Maximizing the confidence in the decision means that the decision score changes the most from the current score when the additional data sources are used. In this case, the current score may be close to 0.5, and it is not possible to clearly determine whether access is allowed or denied. When the algorithm is performed, the decision score will be closer to 1 or 0.

[0055] Furthermore, the given condition on data cost is any condition on data cost. In this example, the given condition is that when using additional data sources, the total response time required is less than a time threshold T and the total computational cost is less than a cost threshold C. The total response time is the sum of the time required for each additional data source to be used, and the total computational cost is the sum of the computational costs required for each additional data source to be used. In other words, the given condition effectively limits the number of additional data sources to be used.

[0056] The example algorithm above is V under the condition that the total response time required is less than T and the total computational cost is less than C. gain can be expressed as maximizing V gain is expressed as follows:

number

[0057] The data source selection unit 118 may calculate the reliability gain using an algorithm or a table. As an example, the calculation may be performed by inputting the evaluated data value into the algorithm and outputting the reliability gain information. As another example, the calculation may be performed by comparing the evaluated data value with data values ​​listed in a table and extracting the reliability gain corresponding to the evaluated data value in the table.

[0058] The data source selection unit 118 may utilize, for example, but not limited to, one of the following algorithms: Integer Linear Programming (ILP), Satisfiability (SAT) algorithms, AI / Machine Learning (ML) based algorithms, and Heuristics.

[0059] Alternatively, the data source selection unit 118 may calculate the reliability gain using a pre-trained AI model. The AI ​​model is trained by inputting training data including, for example, multiple sets of data values ​​as samples and reliability gains as correct labels. After training, the evaluated data values ​​are input to the AI ​​model. In response to the input, the AI ​​model outputs information indicating the reliability gains corresponding to the evaluated data values. The data source selection unit 118 can obtain the reliability gain information through an inference process.

[0060] The data source selection unit 118 can select one or more of the additional data sources to achieve the most effective way to clearly determine whether access is allowed or denied. For example, consider a case where the data source selection unit 118 determines whether to select at least one of (a) "apply malware signature check" and (c) "apply MFA" above. In this case, the current decision score is 0.4, which makes it somewhat difficult to make a final decision between allow and deny.

[0061] Furthermore, the range of the decision score that involves uncertainty in the decision between allow and deny is 0.35 to 0.65. If the decision score is within this range (hereinafter also referred to as the uncertainty range), there may be uncertainty in the decision to allow or deny. Therefore, it is desirable for the data source selection unit 118 to select one or more additional data sources to bring the decision score outside the uncertainty range so that the decision can be made with certainty. The data source selection unit 118 may obtain information about the uncertainty range from a memory (not shown in FIGS. 3 and 4). The information about the uncertainty range can be created and / or updated by a user or automatically by the PDP 110.

[0062] As described above, the metric derivation unit 116 evaluates the data values ​​of (a)(1) through (3) as follows: (1) Reason: High, (2') Missing attributes: low, and (3') Analysis: Good. Furthermore, the metric derivation unit 116 evaluates the data cost of (a) as follows: (i) Response time: slow, (ii) computational cost: high, and (iii) User Experience: No impact on users. Specifically, in the case of (a), the response time is T1 and the computation cost is C1.

[0063] Furthermore, in this case, the metric derivation unit 116 evaluates the data values ​​of (c)(1) through (3) as follows: (1) Reason: High, (2') Missing attributes: high, and (3') Analysis: Good. Furthermore, the metric derivation unit 116 evaluates the data cost of (c) as follows: (i) Response time: fast, (ii) computational cost: medium, and (iii) User experience: Low. Specifically, in the case of (c), the response time is T2, the calculation cost is C2, T1>T2, and C1>C2.

[0064] The data source selection unit 118 uses the information of the data values ​​(1') to (3') to calculate the reliability gains of (a) and (c). In this example, the data source selection unit 118 calculates the reliability gain of (a) as 0.4 and the reliability gain of (c) as 0.6. Based on the reliability gain calculation results, the data source selection unit 118 determines that the possible decision scores when using (a) are 0.6 or 0.2, and the possible decision scores when using (c) are 0.7 or 0.1. The range of 0.6 to 0.2 is the reliability gain value of (a), and the range of 0.7 to 0.1 is the reliability gain value of (c).

[0065] The data source selection unit 118 determines whether the possible decision scores for (a) and (c) are outside the uncertainty range. For (a), 0.2 is outside the uncertainty range, but 0.6 is within the uncertainty range. However, for (c), both 0.7 and 0.1 are outside the uncertainty range.

[0066] 5A and 5B show the determination results of (a) and (c), respectively. 5A and 5B show the current decision score, the uncertainty range, and the reliability gain (i.e., the possible decision scores). 5A shows that one possible decision score is 0.6, which is within the uncertainty range, while 5B shows that the possible decision scores are outside the uncertainty range. Taking the determination results into consideration, the data source selection unit 118 determines that (c) should be selected in preference to (a).

[0067] The data source selection unit 118 also determines whether at least one of (a) and (c) satisfies a given condition. Specifically, the data source selection unit 118 determines whether the response time and computation cost of (a) and (c) are equal to or less than a time threshold T and a cost threshold C, respectively. The data source selection unit 118 determines not to select (a) if at least the response time T1 is greater than the time threshold T or the computation cost C1 is greater than the cost threshold C. The data source selection unit 118 also determines whether to select (c) as well as (a).

[0068] In this example, since the relationships T>T1>T2 and C>C1>C2 hold, the data source selection unit 118 determines that at least (a) or (c) can be selected. Therefore, the data source selection unit 118 determines that both (a) and (c) can be selected, taking into account the total response time and total calculation cost of (a) and (c).

[0069] In this example, because at least one of the relationship T1 + T2 > T or the relationship C1 + C2 > C holds, the data source selection unit 118 determines that both (a) and (c) cannot be selected. Therefore, in this case, only one of (a) and (c) can be selected. As described above, it is determined that (c) should be selected in preference to (a), and therefore the data source selection unit 118 selects (c) rather than (a). However, if the relationships T > T1 + T2 and C > C1 + C2 hold, the data source selection unit 118 can select both (a) and (c). In this way, the data source selection unit 118 can derive one or more effective data sources by considering the balance between the data cost and the ability (gain) of each candidate additional data source to collect valuable data required for access decisions.

[0070] If the data source selection unit 118 determines to select (c), the data source selection unit 118 provides an instruction to the decision engine 112 as feedback. The instruction indicates that the decision engine 112 should further receive the monitoring information I of (c) regarding the target access in addition to the current monitoring information I and security policy P.

[0071] Furthermore, the data source selection unit 118 can display the content of the monitoring information I in (c) or the content of the monitoring information I in (c) together with the current monitoring information I on a display unit connected to the PDP 110.

[0072] In accordance with the instruction, the decision engine 112 begins to receive (c) current monitoring information I from one or more corresponding collection agents. In other words, the decision engine 112 selects one or more corresponding collection agents as new PIPs 102.

[0073] After the decision engine 112 begins to receive the current monitoring information I of (c), the decision engine 112 may access the source database 106 and remove one or more corresponding collection agents from a table in the source database 106. In essence, the decision engine 112 may update the contents of the table. This process ensures that the metric derivation unit 116 does not evaluate additional data sources that are currently being used, thus reducing unnecessary processing.

[0074] The decision engine 112 then determines whether the target access should be permitted or denied based on the (c) current monitoring information I together with the monitoring information I and the security policy P. At the time of decision, the decision engine 112 is expected to determine whether the target access should be permitted or denied with a higher degree of confidence than in the absence of the (c) current monitoring information I.

[0075] Specifically, if the decision engine 112 receives current monitoring information I of (c) indicating that the MFA has failed, the decision score generated by the decision engine 112 decreases from 0.4 to 0.1. In this case, the decision engine 112 can make a decision to block access with a high degree of confidence. Furthermore, if the decision engine 112 receives current monitoring information I of (c) indicating that the MFA has succeeded, the decision score generated by the decision engine 112 increases from 0.4 to 0.7. In this case, the decision engine 112 can make a decision to allow access with a slightly higher degree of confidence.

[0076] The analysis of (a) and (c) and the decision based on the analysis made by the data source selection unit 118 have been described above. However, if adding at least one of (b) and (d) further changes (improves) the decision score and satisfies a given condition, the data source selection unit 118 may further select at least one of (b) and (d) in addition to (c). The addition of at least one of (b) and (d) satisfying the given condition means that the total response time and total computation cost of (c) and ((b) and / or (d)) are less than or equal to a time threshold T and a cost threshold C, respectively. This process can further reduce the uncertainty of the decision.

[0077] In the above example, the data source selection unit 118 analyzes the relationship between the possible decision scores and the uncertainty range and whether the given condition is met to select at least one of (a) or (c). However, the data source selection unit 118 can analyze either the above relationship and the item indicating whether the given condition is met to select at least one of (a) or (c). Consider a case in which the data source selection unit 118 analyzes the relationship between the possible decision scores and the uncertainty range. If the data source selection unit 118 determines that a single (a) or (c) is to be selected, at least one of the possible decision scores of (a) or (c) will be within the uncertainty range. However, if (a) and (c) are selected, all possible decision scores of (a) and (c) will be outside the uncertainty range. In this case, the data source selection unit 118 selects (a) and (c) to ensure greater certainty in the decision made by the decision engine 112.

[0078] The algorithms executed on the data source selection unit 118 are not limited to those mentioned above. For example, an example of an algorithm is to select V that exceeds a predetermined threshold under a given condition. gain The predetermined threshold may be set manually by a user or automatically by the data source selection unit 118. Furthermore, an example of the given condition is not limited thereto, and the given condition may include at least one of a response time, a computation cost, or a user experience.

[0079] As a result of the analysis of the above relationships performed by the data source selection unit 118, it is possible that the data source selection unit 118 determines that the additional data sources listed in the tables of the source database 106 do not need to be selected because they do not lead to a change (improvement) in the decision score. Alternatively / additionally, as a result of the analysis of matters indicating whether a given condition is satisfied, it is also possible that the data source selection unit 118 determines that the additional data sources listed in the tables do not need to be selected because the given condition is not satisfied. Furthermore, if the current decision score already has no uncertainty range, the data source selection unit 118 may determine that the additional data sources listed in the tables of the source database 106 do not need to be selected. Also, if the data source selection unit 118 does not receive metric information from the metric derivation unit 116 or receives information indicating that one or more additional data sources do not need to be selected, the data source selection unit 118 does not need to select one or more additional data sources.

[0080] In at least one of these cases, the data source selection unit 118 does not need to provide an instruction to the decision engine 112, or provides an instruction to the decision engine 112 indicating that there is no change in the current monitoring information I received by the decision engine 112. Thus, even after receiving this instruction, the decision engine 112 continues to receive the same current monitoring information I and makes an allow or deny decision based on that information. In this way, if the situation is such that the decision engine 112 does not need to receive new monitoring information, the decision engine 112 does not need to receive new monitoring information. In this case, the data source selection unit 118 can reduce the cost associated with receiving the monitoring information I.

[0081] Furthermore, the data source selection unit 118 can display, on a display unit connected to the PDP 110, information indicating that there is no change in the current monitoring information I. Alternatively, the data source selection unit 118 can also display the information of the current monitoring information I on the display.

[0082] The monitoring information received by the decision engine 112 may change dynamically. Therefore, the presence and / or type of monitoring information determined to be additionally acquired by the data source selection unit 118 also changes dynamically. This allows the data source selection unit 118 to change its determination in response to changing conditions.

[0083] Furthermore, the data source selection unit 118 may determine one or more control plane configurations for the one or more additional data sources selected by the data source selection unit 118. Specifically, the data source selection unit 118 may determine one or more control plane configuration files for the one or more additional data sources related to at least any one of an initialization, an operation, or a termination of the one or more additional data sources.

[0084] Additionally, the one or more control plane files include routing information from the PDP 110 to one or more additional data sources. The routing information may indicate one or more data planes for routing communications between the PDP 110 and the one or more additional data sources.

[0085] <Flow description> Next, an example of the operation of the PDP 110 will be described with reference to the flowchart of Fig. 6. The details of each process in Fig. 6 have already been described above, and the description thereof will be omitted as necessary.

[0086] First, the decision engine 112 receives current monitoring information I and security policies P regarding the target access (step S22). The decision engine 112 generates a decision score and specific access rules based on the received information (step S24).

[0087] Next, the decision score analyzer 114 considers the analysis points of the metric based on, for example, the information generated by the decision engine 112 (step S26). Thereafter, the metric derivation unit 116 evaluates the metric information based on, for example, the analysis points (step S28). The data source selection unit 118 uses the metric information to select valid additional data sources for additional data collection (step S30). The decision engine 112 selects a new collection agent based on the selection and begins receiving additional information corresponding to the new collection agent (step S32).

[0088] <Explanation of effect> For the same reasons as those explained in the first embodiment, the access management system 100 can contribute to accurate determination of accessibility.

[0089] As an example of the related art, a procedure for collecting additional information is determined based on statically configured triggers and rules. In this example, a system receives monitored data (e.g., packet headers) and compares the data with configured triggers. If the data matches one of the configured triggers, the system determines that collection of additional information is necessary.

[0090] However, this technique has the problem that configured triggers are static and not scalable, requiring precise definitions to cover all possible situations. Therefore, it is time-consuming to create precise definitions of configured triggers. Furthermore, because configured triggers are static, they cannot respond to changing conditions. In short, configured triggers do not adapt to dynamic environments.

[0091] In contrast to the above-mentioned related art, the PDP 110 analyzes the monitoring information I and the security policy P. As the monitoring information changes dynamically, the decision to select one or more additional data sources also changes dynamically. In other words, the method by the PDP 110 has adaptability in a dynamic environment.

[0092] Furthermore, the data source selection unit 118 may select at least one additional data source from the multiple additional data sources based on the variability (reliability gain) of each of the multiple additional data sources for the assessment. For example, the data source selection unit 118 may select one or more additional data sources whose data most significantly changes the assessment. Thus, the PDP 110 may determine one or more valid data sources to reduce decision uncertainty.

[0093] Furthermore, the data source selection unit 118 can select at least one additional data source from the plurality of additional data sources based on at least one of the cost, response time, or user experience of each of the plurality of additional data sources. Thus, the PDP 110 can determine one or more effective data sources to reduce not only decision uncertainty but also costs associated with processing one or more of the additional data sources.

[0094] The data source selection unit 118 can select at least one additional data source from the multiple additional data sources based on the variability of each of the multiple additional data sources relative to the evaluation, and at least one of the cost, response time, or user experience of each of the multiple additional data sources. Thus, the PDP 110 can determine one or more effective data sources to balance data cost and capacity (gain).

[0095] Furthermore, after the data source selection unit 118 determines one or more additional data sources, the decision engine 112 can begin to receive additional information according to the determination. As a result, the decision engine 112 further analyzes data from at least one additional data source, as well as the monitoring information and at least one access control policy, to calculate an evaluation. The collection of new additional data leads to an improvement in the reliability of the access decision. Furthermore, because the PDP 110 collects as much monitoring information I as necessary when making an access decision, the method performed by the PDP 110 can reduce processing costs and be scalable in large networks.

[0096] Furthermore, the data source selection unit 118 can determine one or more control plane configurations for the selected one or more additional data sources, so that the PDP 110 can accept specific settings for obtaining the additional information.

[0097] The control plane configuration may include routing information from the PDP 110 to one or more selected additional data sources, so that the PDP 110 can reliably set up a path to obtain the additional information.

[0098] (A modified example of the second embodiment) 7 is a block diagram illustrating another example of the access control system 100 in detail. FIG. 7 differs from FIG. 4 in that the PDP 110 further includes a determining unit 119.

[0099] Before the decision engine 112 outputs the decision score, the decision result, the current monitoring information I, and the security policy P to the decision score analyzer 114, the decision engine 112 outputs the decision score to a determination unit 119. The determination unit 119 determines whether the decision score output by the decision engine 112 is within a predetermined range of possible decision scores. The predetermined range may be the same as the uncertainty range, or may be different. If the ranges are different, the upper limit of the predetermined range may be greater than the upper limit of the uncertainty range, or the lower limit of the predetermined range may be less than the lower limit of the uncertainty range, or both conditions may be met.

[0100] If the determination unit 119 determines that the decision score is within the predetermined range, the determination unit 119 instructs the decision engine 112 to output the decision score regarding the target access, the result of the decision, the current monitoring information I, and the security policy P to the decision score analyzer 114. The decision score analyzer 114 then executes the above process. In this case, the determination unit 119 may further instruct the decision engine 112 to generate specific access rules as described above and output them to the PEP 120.

[0101] However, the determination unit 119 may not instruct the decision engine 112 to generate or output specific access rules to the PEP 120. In this example, the determination unit 119 does not allow the PEP 120 to grant or deny access and puts the process on hold for the PEP 120. As mentioned above, due to the processes by the decision score analyzer 114, the metric derivation unit 116, and the data source selection unit 118, the data source selection unit 118 is expected to select one or more valid additional data sources for additional data collection.

[0102] The decision engine 112 can begin to receive additional information corresponding to one or more available additional data sources. The decision engine 112 then analyzes the received data and calculates an evaluation, e.g., a new decision score. The new decision score may not have a predetermined range because the collection of new additional data leads to an increase in the reliability of the access decision. The determination unit 119 makes a determination regarding the new decision score in the same manner as for the previously calculated decision score. If the determination unit 119 determines that the new decision score is within the predetermined range, the determination unit 119, the decision score analyzer 114, the metric derivation unit 116, and the data source selection unit 118 repeat the above process until the determination unit 119 determines that the decision score is outside the predetermined range.

[0103] If the determination unit 119 determines that the decision score is outside the predetermined range, the determination unit 119 may instruct the decision engine 112 to generate a specific access rule and output it to the PEP 120. As a result, the PEP 120 can grant or deny access according to the specific access rule. Furthermore, at this stage, the determination unit 119 may or may not instruct the decision engine 112 to output the decision score regarding the target access, the decision result, the current monitoring information I, and the security policy P to the decision score analyzer 114. If the determination unit 119 does not instruct the decision engine 112 to do so, the decision score analyzer 114, the metric derivation unit 116, and the data source selection unit 118 do not need to perform the above processes. Therefore, the determination unit 119 can reduce unnecessary processing.

[0104] Next, an example configuration of the data processing device 10 and / or the access control system 100 will be described below with reference to FIG.

[0105] 8 is a diagram showing an example of the hardware configuration of a computer system applicable to the data processing device 10 and / or the access control system 100. The computer system may include an information processing device (computer) 200 having the hardware configuration shown in FIG. 8. The hardware configuration shown in FIG. 8 is merely an example of a hardware configuration that realizes the functions of the data processing device 10 and / or the access control system 100, and is not intended to limit the hardware configuration of the computer system. The computer system may include hardware not shown in FIG. 8.

[0106] 8, the computer 200 includes a central processing unit (CPU) 210, a main memory 220, an auxiliary memory 230, and a network interface card (NIC) 240, which is a communication interface. However, the type of communication interface is not limited to this. These elements are connected to each other by, for example, an internal bus.

[0107] The CPU 210 executes a program (program instructions) stored in the main memory device 220 to execute the program and realize the functions and processes of the data processing device 10 and / or the access control system 100. Furthermore, the CPU 210 may receive commands from the NIC and execute the program according to the commands.

[0108] The CPU 210 is an example of a processor. Instead of a CPU, for example, a microprocessor or an MPU (microprocessing unit) can be used. Furthermore, the computer 200 may include multiple processors. In this case, each of the processors executes one or more programs including instructions to cause the computer to perform the algorithms described above with reference to the drawings.

[0109] The main memory 220 temporarily stores programs executed by the computer 200 so that the CPU 210 can process them. The main memory 220 includes, for example, semiconductor memory (e.g., random access memory (RAM), read-only memory (ROM), electrically erasable programmable ROM (EEPROM)), and / or storage devices including at least one of a hard disk drive (HDD), a solid-state drive (SSD), a compact disc (CD), a digital versatile disc (DVD), etc. From another perspective, the main memory 220 is formed by volatile memory and / or nonvolatile memory. The main memory 220 may also include a storage device located separately from the CPU 210. In this case, the CPU 210 may access the main memory 220 via a NIC.

[0110] The secondary storage device 230 may be, for example, a hard disk drive (HDD) and may store the program for a long period of time. The program may be provided as a computer program stored on a non-transitory computer-readable storage medium. When in use, the program is transferred from the secondary storage device 230 to the primary storage device 220.

[0111] The NIC 240 provides an interface to external terminals over a network and is used to receive and transmit traffic communications.

[0112] Furthermore, the program stored in the main memory device 220 and / or the secondary memory device 230 includes program instructions (program modules) for executing the processing of each unit of the data processing device 10 and / or the access control system 100 in the above-described embodiments. The program may include instructions (or software code) that, when loaded into a computer, cause the computer to perform one or more of the functions described in the embodiments. The program may be stored in a non-transitory computer-readable medium or a tangible storage medium. Non-transitory computer-readable media or tangible storage media include, but are not limited to, RAM, ROM, flash memory, SSD or other memory technology, compact disk-read only memory (CD-ROM), compact disk-read / write (CD-R / W), digital versatile disk (DVD), Blu-ray Disc® or other optical disk storage, magnetic cassette, magnetic tape, magnetic disk storage, or other magnetic storage device. The program may be transmitted on a temporary computer-readable medium or a communication medium. By way of example, and not limitation, transitory computer-readable or communication media include electrical, optical, acoustic or other forms of propagated signals.

[0113] In some embodiments, the implementation of the data processing device 10 and / or the access control system 100 may be implemented not only in one computer system but also in multiple computer systems, for example, one computer system may send / receive data required for an operation processed by the data processing device 10 and / or the access control system 100 to / from another computer system in order to accomplish that operation.

[0114] All or part of the embodiments disclosed above can be described as follows, but are not limited to the following: (Appendix 1) obtaining means for obtaining monitoring information and at least one access control policy; analysis means for analyzing the monitoring information and the at least one access control policy to derive an assessment for determining accessibility; determining whether to select at least one additional data source for additional data collection based on the evaluation; A data processing device comprising: (Appendix 2) the determining means selects at least one additional data source from the plurality of additional data sources based on the variability of each of the plurality of additional data sources relative to the assessment; 2. A data processing device according to claim 1. (Appendix 3) the determining means selects at least one additional data source from the plurality of additional data sources based on at least one of a cost, a response time, or a user experience of each of the plurality of additional data sources; 2. A data processing device according to claim 1. (Appendix 4) the determining means selects at least one additional data source from the plurality of additional data sources based on at least one of a variability of each of the plurality of additional data sources relative to the rating and a cost, a response time, or a user experience of each of the plurality of additional data sources; 2. A data processing device according to claim 1. (Appendix 5) the analysis means analyzes the monitoring information, data from the at least one additional data source, and the at least one access control policy to derive an evaluation; 5. A data processing device according to any one of claims 1 to 4. (Appendix 6) the determining means further determines a control plane configuration for at least one additional data source; 6. A data processing device according to any one of claims 1 to 5. (Appendix 7) the control plane configuration includes routing information from the data processing device to at least one additional data source; 7. A data processing device according to claim 6. (Appendix 8) obtaining monitoring information and at least one access control policy; analyzing the monitoring information and the at least one access control policy to derive an evaluation for determining accessibility; determining whether to select at least one additional data source for additional data collection based on the evaluation; A data processing method carried out by a computer, including: (Appendix 9) selecting at least one additional data source from the plurality of additional data sources based on the variability of each of the plurality of additional data sources relative to the assessment; 9. The data processing method of claim 8, further comprising: (Appendix 10) On the computer, obtaining monitoring information and at least one access control policy; analyzing the monitoring information and the at least one access control policy to derive an evaluation for determining accessibility; determining whether to select at least one additional data source for additional data collection based on the evaluation; A program to execute.

[0115] Some or all of the elements (e.g., structures and functions) described in Appendix 3 to Appendix 7 that depend on Appendix 1 may also depend on Appendix 8 with the same dependency as Appendix 3 to Appendix 7 on Appendix 1. Similarly, some or all of the elements described in Appendix 2 to Appendix 7 that depend on Appendix 1 may also depend on Appendix 10 with the same dependency as Appendix 2 to Appendix 7 on Appendix 1. Some or all of the elements described in any one of the appendices may be applied to various types of hardware, software, and recording means for recording software, systems, and methods.

[0116] Although each embodiment of the present disclosure has been described above, it should be noted that the embodiments or examples can be modified or adjusted based on the basic technical concept within the scope of the entire disclosure (including the claims). Furthermore, within the scope of the entire disclosure, various elements of the disclosure (including individual elements of individual claims, individual elements of individual embodiments or examples, and individual elements of individual figures) can be variously combined or selected (or at least partially removed). In other words, it is obvious that the present disclosure includes all kinds of variations and modifications that would be made by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical concept of the disclosure. In particular, any numerical range disclosed in this specification should be construed as specifically disclosing any intermediate value or subrange falling within the range of the disclosure, even if not explicitly stated. Each embodiment can be appropriately combined with at least one of the embodiments. [Explanation of symbols]

[0117] 10 Data processing device 12 Acquisition Units 14 Analysis Unit 16 Judgment Unit 100 Access Control Systems 102 Policy Information Point 104 Policy Administration Point 106 source databases 110 Policy Decision Points 112 Decision Engine 114 Decision Score Analyzer 116 Metric Derivation Unit 118 Data Source Selection Unit 119 Judgment Unit 120 Policy Enforcement Points

Claims

1. obtaining means for obtaining monitoring information and at least one access control policy; analysis means for analyzing the monitoring information and the at least one access control policy to derive an assessment for determining accessibility; determining whether to select at least one additional data source for additional data collection based on said evaluation; A data processing device comprising:

2. the determining means selecting the at least one additional data source from a plurality of additional data sources based on a variability of each of the plurality of additional data sources relative to the assessment; 2. The data processing device according to claim 1.

3. the determining means selects the at least one additional data source from a plurality of additional data sources based on at least one of a cost, a response time, or a user experience of each of the plurality of additional data sources; 2. The data processing device according to claim 1.

4. the determining means selects the at least one additional data source from a plurality of additional data sources based on at least one of a variability of each of the plurality of additional data sources relative to the assessment, and a cost, a response time, or a user experience of each of the plurality of additional data sources; 2. The data processing device according to claim 1.

5. the analyzing means analyzes the monitoring information, data from the at least one additional data source, and the at least one access control policy to derive the evaluation; 5. A data processing device according to claim 1.

6. the determining means further determines a control plane configuration for the at least one additional data source.

5. A data processing device according to claim 1.

7. the control plane configuration includes routing information from the data processing device to the at least one additional data source; 7. The data processing device according to claim 6.

8. obtaining monitoring information and at least one access control policy; analyzing the monitoring information and the at least one access control policy to derive an evaluation for determining accessibility; determining whether to select at least one additional data source for additional data collection based on said evaluation; A data processing method carried out by a computer, including:

9. selecting the at least one additional data source from a plurality of additional data sources based on the variability of each of the plurality of additional data sources relative to the assessment; The data processing method of claim 8 further comprising:

10. On the computer, obtaining monitoring information and at least one access control policy; analyzing the monitoring information and the at least one access control policy to derive an evaluation for determining accessibility; determining whether to select at least one additional data source for additional data collection based on said evaluation; A program to execute.

Citation Information

Patent Citations

  • Application passive security

    JP2016523398A