Analytical device, analytical method, and program

The analytical device and method improve access control accuracy by estimating the influence of access patterns and generating adaptive policies using machine learning, addressing the challenges of incomplete definitions and enhancing network security.

JP7718513B2Active Publication Date: 2025-08-05NEC CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2023576306
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-01-26
Publication Date
2025-08-05
Estimated Expiration
2042-01-26

AI Technical Summary

Technical Problem

Existing access control systems struggle to accurately determine access control actions due to incomplete or ambiguous policy definitions, leading to potential security vulnerabilities and inefficiencies in network security.

Method used

An analytical device and method that utilize a dataset of access attribute patterns and control actions to estimate the influence of these patterns on access control decisions, combined with an access control system that includes a policy generation system to generate precise policies based on user intentions and machine learning models to interpolate missing information.

Benefits of technology

Enhances the accuracy of access control decisions by automatically generating policies that reflect user intentions and adapt to changing network environments, reducing the time and effort required for policy creation while ensuring security and adaptability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007718513000001
    Figure 0007718513000001
  • Figure 0007718513000002
    Figure 0007718513000002
  • Figure 0007718513000003
    Figure 0007718513000003
Patent Text Reader

Abstract

An analysis device (10) according to an embodiment of the present disclosure is provided with: an acquisition unit (11) that acquires a data set that defines a plurality of combinations of a first pattern of one or more elements indicating access attributes and an action for access control corresponding to the first pattern, and also acquires a second pattern of one or more elements indicating access attributes; and an estimation unit (12) that uses the data set and the second pattern to estimate at least one of the order and magnitude of the degree of impact of the second pattern on the action. This can contribute to accurately determining the action for the access control.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an analytical device, an analytical method, and a non-transitory computer-readable medium. [Background technology]

[0002] Access control in a network is important to network security and maintaining necessary access.

[0003] For example, cited reference 1 discloses a system for implementing a computer resource access control policy by extracting an access control policy from an access check mechanism that has policy expression capabilities that are more limited than the access control policy. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Special Publication No. 2009-540397 Summary of the Invention [Problem to be solved by the invention]

[0005] The present disclosure provides an analysis device, an analysis method, and a non-transitory computer-readable medium that can contribute to accurately determining access control actions. [Means for solving the problem]

[0006] An analysis device according to one embodiment includes an acquisition means for acquiring a dataset in which multiple combinations of a first pattern of one or more elements indicating attributes of access and an access control action corresponding to the first pattern are defined, and a second pattern of one or more elements indicating attributes of access, and an estimation means for using the dataset and the second pattern to estimate at least one of the order or magnitude of the influence of the second pattern on an action.

[0007] An analysis method according to one embodiment is performed by a computer to obtain a dataset that defines multiple combinations of a first pattern of one or more elements that indicate attributes of access and an access control action corresponding to the first pattern, and a second pattern of one or more elements that indicate attributes of access, and to estimate, using the dataset and the second pattern, at least one of the order or magnitude of the influence that the second pattern has on an action.

[0008] A non-transitory computer-readable medium according to one embodiment stores a program that causes a computer to acquire a dataset that defines multiple combinations of a first pattern of one or more elements that indicate access attributes and an access control action corresponding to the first pattern, and a second pattern of one or more elements that indicate access attributes, and to use the dataset and the second pattern to estimate at least one of the order or magnitude of the influence of the second pattern on an action. [Effects of the Invention]

[0009] This disclosure makes it possible to provide an analysis device, an analysis method, and a non-transitory computer-readable medium that can contribute to determining access control actions with high accuracy. [Brief explanation of the drawings]

[0010] [Figure 1] FIG. 1 is a block diagram showing an example of an analysis device according to a first embodiment. [Figure 2] 4 is a flowchart showing an example of processing performed by the analyzer according to the first embodiment. [Figure 3] FIG. 10 is a block diagram illustrating an example of a policy generation system according to a second embodiment. [Figure 4] FIG. 10 is a conceptual diagram illustrating processing performed by an intention extraction unit and a policy generation unit according to the second embodiment. [Figure 5] 10 shows an example of an intention extracted by the intention extraction model according to the second embodiment. [Figure 6] FIG. 2 is a block diagram illustrating an example of a hardware configuration of an apparatus according to each embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0011] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. Note that the following description and drawings have been omitted or simplified as appropriate for clarity of explanation. Furthermore, in this disclosure, unless otherwise specified, when multiple items are defined as "at least one of them," the definition may mean any one item or any multiple items (including all items).

[0012] Embodiment 1 1 is a block diagram showing an example of an analysis device. The analysis device 10 includes an acquisition unit 11 and an estimation unit 12. Each unit (means) of the analysis device 10 is controlled by a control unit (controller) not shown. Each unit will be described below.

[0013] The acquisition unit 11 acquires a data set in which multiple combinations of first patterns of one or more elements indicating access attributes and access control actions corresponding to the first patterns are defined, and a second pattern of one or more elements indicating access attributes. There may be one or more second patterns. The acquisition unit 11 is configured with an interface that acquires information from inside or outside the analysis device 10. The acquisition process may be performed automatically by the acquisition unit 11 or by manual input.

[0014] Here, the "element indicating the attribute of the access" in the first and second patterns refers to any element that specifies the nature of the access. Specific examples of the element may include one or more pieces of specific information (values) related to the nature of the access, such as (1) various data of the access source, (2) various data of the access destination, and (3) other data indicating the nature of the access.

[0015] (1) Specific examples of various data of the access source include any one or more of information on the access source ID, information on the user, information on the access source device, information on the access source IP (Internet Protocol) address, information on the port number, software name (for example, application name), access authentication means, etc. Here, information on the access source ID includes any one or more of the access source ID (user ID), user name, device ID, application ID, user authentication result (authentication history) of the access source ID, etc. Information on the user includes any one or more of the user's affiliation (organization), job title, occupation, user location (location of the device that is the access source), etc. Information on the access source device includes any one or more of the OS ( Operating The information about the access source IP address includes one or more of the following: the IP address of the access source, the risk level of the access source IP address, etc.

[0016] (2) Specific examples of various data of the destination include any one or more of the following: information on the destination ID, information on the destination data, the destination IP address, information on the OS used by the destination device, operation type, etc. Information on the destination ID includes any one or more of the destination resource ID, the name of the owner of the destination resource ID, etc. Information on the destination data includes any one or more of the destination organization (organization that owns the resource), the type of destination data (resource) being requested, the creator, the creation date and time, security level, etc.

[0017] (3) Specific examples of data indicating the nature of other accesses include any one or more of the following: the frequency of requests from the access source ID to the accessed resource ID, the time period (or time) of the access, the session key method, the degree of abnormality, the encryption strength of the traffic, various data related to authentication, etc. The various data related to authentication include any one or more of the following: various authentication methods (including, for example, information on authentication strength), device authentication results, application authentication results, various authentication times, the number of various authentication failures, etc. However, the elements shown above are merely examples, and elements indicating the attributes of access are not limited to these.

[0018] A "pattern of one or more elements indicating the attributes of access" means that one or more of these elements exist. For example, assume that X, Y, and Z are attributes of access, and assume that X1 and X2 are elements with different values of the same attribute X, Y1 and Y2 are elements with different values of the same attribute Y, and Z1 and Z2 are elements with different values of the same attribute Z. In this case, the "pattern of elements indicating the attributes of access" includes any one or more patterns from "X1," "Y1," "Z1," "X1, Y1," "X1, Z1," "Y1, Z1," "X1, Y2," ... "X1, Y1, Z1," ... "X2, Y2, Z2." Note that at least one or more of the elements constituting the first pattern and the second pattern may be different.

[0019] The data set also includes access control actions corresponding to each of the first patterns. Two or more different levels of actions are defined as these actions. For example, two or more types of actions may be defined from among authorization, denial, and conditional authorization (additional authentication request). However, the actions shown above are merely examples, and the types of actions are not limited to these.

[0020] In the data set, multiple combinations of first patterns of one or more elements indicating the access attributes described above and access control actions corresponding to each of the first patterns are defined. For example, if "X1, Y1," "X1, Z1," and "Y1, Z1" exist as patterns of multiple elements indicating access attributes, and "Approve," "Deny," and "Approve" exist as actions corresponding to each pattern, then the data set will define the following combinations of these: "X1, Y1 => Authorize," "X1, Z1 => Deny," and "Y1, Z1 => Authorize."

[0021] The estimation unit 12 estimates at least one of the order and magnitude of the influence of the second pattern on an access control action, using the dataset and the second pattern acquired by the acquisition unit 11. The order of influence means the direction of the action, i.e., whether it is moving toward authorization or toward denial, depending on the pattern of the defined elements. "The action is moving toward authorization" means, for example, at least one of the following: the action changes from "denial" to "authorization," "additional authentication request" to "authorization," or "denial" to "additional authentication request." The magnitude of influence means the degree of magnitude when the action changes. For example, a change from "denial" to "authorization" can be considered to have a greater influence than a change from "additional authentication request" to "authorization" or from "denial" to "additional authentication request." The magnitude of influence can be considered to have a greater influence than a change from "authorization" to "additional authentication request" or from "denial" to "additional authentication request." Information on the order or magnitude of the estimated impact may be stored within the analysis device 10 or output outside the analysis device 10 (e.g., displayed to the user), or may be used for policy generation as described in embodiment 2.

[0022] FIG. 2 is a flowchart showing an example of a typical process of the analysis device 10, and this flowchart will be used to explain the process of the analysis device 10. First, the acquisition unit 11 of the analysis device 10 acquires a data set in which multiple combinations of first patterns of one or more elements indicating access attributes and access control actions corresponding to the first patterns are defined, and a second pattern of one or more elements indicating access attributes (step S11; acquisition step). Next, the estimation unit 12 uses the data set and the second pattern to estimate at least one of the order or magnitude of the influence of the second pattern on the action (step S12; estimation step). By using the order or magnitude of the influence estimated in this way, it is possible to accurately determine an access control action for an arbitrary element pattern.

[0023] Embodiment 2 DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS A second embodiment of the present invention will now be described with reference to the accompanying drawings. In a second embodiment, a specific example of the analysis device 10 described in the first embodiment will be disclosed.

[0024] 3 is a block diagram showing an example of an access control system 20 that executes access control determination on a zero trust network. The access control system 20 includes a policy generation system 21, a determination unit 22, a data store 23, and an enforcer 24. Each unit will be described in detail below.

[0025] The policy generation system 21 corresponds to a specific example of the analysis apparatus 10 according to the first embodiment. The policy generation system 21 generates an access control policy for access control based on an input intention (knowledge necessary for policy generation) and a judgment sample (corresponding to the data set in the first embodiment), and outputs the generated access control policy to the judgment unit 22. Details of the policy generation system 21 will be described later.

[0026] Here, the access control policy is a set of one or more element patterns (fifth patterns) that indicate the attributes of access. 1 or more It defines multiple combinations of access control actions corresponding to element patterns. As a specific example, if the element combination is (accessing user's affiliation: Division A, job type: developer, authentication method: two-step authentication, resource-owning organization: Division A, resource type: design document), the corresponding action is defined as "authorize."

[0027] When an access control inquiry (request) is made, the determination unit 22 determines an access control action based on elements related to the request, using the access control policy acquired from the policy generation system 21. The elements related to the request mean the same elements indicating the access attributes described in the first embodiment.

[0028] Specifically, the determination unit 22 receives, as request-related elements, (i) information on elements included in the request that indicate attributes of the access, and (ii) other information on background attributes. Examples of the information (i) include the ID of the access source, the IP address of the access source, the resource ID of the access destination, the operation type, and a session key, but the information on elements included in the request is not limited to these. Examples of the information (ii) include the user name of the ID of the access source, the user's affiliation, job title or occupation, the manufacturer name of the device, the user location, the user authentication result, the risk level of the IP address of the access source, the owner name of the resource ID of the access destination, the type and creation date and time of the data of the access destination, the encryption strength, the frequency of requests from the ID of the access source to the resource ID of the access destination, the time of access, various authentication methods, the device authentication result, the application authentication result, various authentication times, and the number of authentication failures, but the information on elements included in the information on background attributes is not limited to these.

[0029] The determination unit 22 compares the elements related to the request with combinations of multiple elements defined in the access control policy, identifies combinations of elements defined in the access control policy that satisfy the conditions of the elements related to the request, and determines the actions defined corresponding to each combination as the actions for the request and outputs information about the actions.

[0030] Possible actions in the second embodiment include, but are not limited to, authorization, request for additional authentication, and denial. For example, possible actions include transferring access to a server that performs more detailed checks, or requesting approval from an administrator. These actions constitute a totally ordered set that satisfies the reflexive, transitive, antisymmetric, and perfect laws.

[0031] The above-described determination unit 22 can be realized by any means such as a proxy server for access control, an application gateway, or attribute-based encryption.

[0032] The data store 23 is a storage (storage unit) that stores information on background attributes used by the above-mentioned determination unit 22. The access control system 20 stores automatically collected data in the data store 23. When an access control request is made, the determination unit 22 refers to the data store 23 to obtain information on background attributes corresponding to the request.

[0033] The enforcer 24 is an access control device that, upon receiving an access control request, outputs information on elements related to the request to the determination unit 22. The enforcer 24 then obtains information on the action determined by the determination unit 22 and executes access control for the request based on the action information. If access is authorized, the enforcer 24 forwards the packet related to the access to the resource (access destination), while if access is denied, the enforcer 24 discards the packet related to the access. In this way, the access control system 20 executes access control based on the generated access control policy.

[0034] Next, details of the policy generation system 21 will be described. As shown in FIG. 3, the policy generation system 21 includes a judgment sample acquisition unit 211, an intention acquisition unit 212, an intention extraction unit 213; Policy generation unit 214 and parameter storage unit 215 Each part will be explained below.

[0035] The judgment sample acquisition unit 211 acquires a judgment sample and outputs the judgment sample to the intention extraction unit 213 and the policy generation unit 214. The judgment sample includes multiple sample policies defined by a user (or an existing automation method). The sample policy defines a correspondence between one or more (e.g., multiple) element patterns (first patterns) indicating access attributes and access control actions for the patterns. Here, the multiple sample policies may be defined from different perspectives for each policy. For example, as a perspective based on security functions, elements such as the encryption strength of traffic, the OS version of the access source device, the application authentication result, the user authentication strength, the resource creator, and the resource type may be set. Furthermore, as a perspective based on the organizational department structure (affiliation, position, etc.) for access, elements such as the user's position, affiliation (e.g., project in charge), the resource creator, the resource type, and the user location may be set. In this way, different perspectives may have different elements or the same elements. A specific example of a sample policy is "user's affiliation, job title, authentication method, device location, OS, type of data (request data) to be accessed, application name ⇒ approve / deny."

[0036] Furthermore, some elements of a sample policy may be expressed in a form that does not uniquely identify them (i.e., is "anonymized"). For example, in a sample policy, a user's affiliation may be expressed as "Human Resources Department" or "Development Department" in a non-anonymized state, but may be expressed as "Department A" or "Department B" in an anonymized state. Such anonymization may be performed, for example, to protect confidential information of an organization when presenting the sample policy to people or systems outside the organization. Alternatively, such anonymization may be performed because elements of the underlying data were not uniquely identified when the sample policy was originally generated (e.g., the underlying data was poorly readable). Even if the sample policy has such an incomplete definition, the policy generation system 21 can generate a policy that interpolates the incomplete definition in the sample policy, as described below.

[0037] The judgment sample acquisition unit 211 may output the acquired judgment sample as is to the intention extraction unit 213 and the policy generation unit 214. Alternatively, the judgment sample acquisition unit 211 may further acquire data indicating ideal access control for a specific element pattern and output this data to the intention extraction unit 213 and the policy generation unit 214. The number of patterns included in this data may be, for example, several to several tens of patterns, but is not limited to this. This makes it possible to further improve the accuracy of the policy generated by the policy generation unit 214.

[0038] The intention acquisition unit 212 acquires the intention that a decision maker is expected to use when deciding on an action based on one or more elements. As described above, the intention means knowledge necessary for policy generation, and more specifically, includes a pattern of one or more elements indicating the attributes of the access (corresponding to the second pattern in the first embodiment).

[0039] The intention acquisition unit 212 can acquire, as intentions, a pattern (third pattern) of one or more elements indicating attributes of access, in which the order and magnitude of the influence that affects the action are defined, and a pattern (fourth pattern) of one or more elements indicating attributes of access, in which at least one of the order or magnitude of the influence defined in the third pattern is not defined. In this example, the fourth pattern is assumed to be one in which neither the order nor the magnitude of the influence is defined. Furthermore, as will be described later, this intention can be defined in an ambiguous format. The intention acquisition unit 212 can acquire any number of these combinations, from 1 onwards.

[0040] Examples of patterns of one or more elements include a set of "user affiliation, type of requested data, or organization owning the resource," a set of "OS, software name, or application name," and individual elements such as "authentication method" and "anomaly level." For example, in access control, the type of data or organization owning the resource to which access is authorized may differ depending on the user's affiliation. Therefore, "user affiliation, type of requested data, or organization owning the resource" may be defined as an element of intent. Similarly, in access control, the security level of access may change depending on the combination of the OS and software or application from the access source, the authentication method, and the anomaly level (i.e., whether access is approved or denied may change). Therefore, "OS, software name, or application name," "authentication method," and "anomaly level" may be defined as elements of intent.

[0041] Furthermore, in the third pattern, the information on the degree of impact that affects an action is information that indicates to what extent the action moves in the direction of "approval" or "denial." As described above, the direction toward "approval" or "denial" is defined as the "order of impact," and information that indicates to what extent the action moves toward "approval" or "denial" is defined as the "magnitude of impact." For example, the "magnitude of impact" is arranged in descending order to form the "order of impact." This information on impact does not necessarily indicate the action that should be executed.

[0042] Here, the intention acquisition unit 212 may acquire data such as quantitatively expressed numerical values as the influence of the intention, or may acquire qualitative (ambiguous) information. A specific example of the latter is information indicating that, with respect to the direction of the action toward "authorization," "User's Department: Development Department, Requested Data: Design Data" is greater than "User's Department: Development Department, Requested Data: Personnel Data." This information can be defined because, in general, it is natural for a user belonging to the development department to request data related to product development (e.g., design data), and it is considered appropriate to authorize access control related to such data. On the other hand, even if a user belongs to the development department, if the user is developing a personnel system, it may be appropriate to authorize access to personnel data for development purposes. Therefore, the influence is qualitative information indicating a general trend, rather than quantitative information indicating whether to actually authorize or deny access. The magnitude of the influence may be expressed in three or more stages (e.g., "high influence," "slightly high influence," and "low influence," in descending order of influence) instead of two stages.

[0043] When the intention acquisition unit 212 acquires such qualitative impact information, it may convert the impact information into a numerical value in which the order and magnitude of the impact are defined, and then output the information to the policy generation unit 214. For example, when assigning a positive score as the direction of "approval," the intention acquisition unit 212 may assign an impact value of "1" to "User's department: Development department, requested data: Design data" and an impact value of "0" to "User's department: Development department, requested data: Personnel data," because it is easier to "approve" the action for the former than for "User's department: Development department, requested data: Personnel data."

[0044] As described above, the intention acquisition unit 212 outputs the information on the intentions related to the third and fourth patterns to the intention extraction unit 213 and the policy generation unit 214.

[0045] When the policy generation unit 214 generates an access control policy, the intention extraction unit 213 extracts an intention that is necessary for the generation of the policy but that was not acquired by the intention acquisition unit 212, and outputs the information to the policy generation unit 214. The extracted intention, for example, uniquely identifies an anonymized definition in the sample policy (interpolates an incomplete definition). The intention extraction unit 213 can estimate and extract an intention that does not contradict the user's preference indicated in the sample policy, even for a pattern not determined by the user who set the sample policy. This is realized by the intention extraction unit 213 extracting information on the influence level in the fourth pattern (i.e., information on the order and magnitude of the influence levels that affect the action, which are numerical values in this example) as the intention. The intention extraction unit 213 corresponds to the estimation unit 12 in the first embodiment.

[0046] In detail, the intention extraction unit 213 acquires a sample policy from the judgment sample acquisition unit 211, and also acquires intention information from the intention acquisition unit 212. An example of the acquired sample policy is "user's affiliation, job title, authentication means, device location, OS, type of data (request data) of the requested access destination, application name ⇒ authorization / denial." Furthermore, examples of patterns of one or more elements in the acquired intention are a set of "user's affiliation, type of requested data or organization owning resource," a set of "OS, software name or application name," a single "authentication means," "anomaly level," etc.

[0047] The intention extraction unit 213 inputs this information into an intention extraction model (hereinafter referred to as the intention extraction model) and causes the intention extraction model to perform machine learning. Then, for a fourth pattern in the intention information, the intention extraction model generates and outputs the degree of influence on the access control action due to each element pattern.

[0048] For example, if the fourth pattern includes "User's department: Development department, requested data: Design data" and "User's department: Development department, requested data: Personnel data," the intention extraction unit 213 may determine, based on the sample policy, that the former pattern is more likely to result in "approval" than the latter pattern. The reason for this is as described above. As a result, the intention extraction unit 213 assigns an impact level of "1" to the former and an impact level of "0" to the latter. This allows the intention extraction unit 213 to estimate the impact that various combinations of elements indicating attributes have on policy determination and extract it as a new intention.

[0049] The access control system 20 may also visualize and present to the user the information on the intention extracted by the intention extraction unit 213. The presented information on the intention includes information on a fourth pattern and an estimated impact for each of the patterns. The information on the intention can be presented by displaying the information on the intention on a screen of the access control system 20 or by printing the information on the intention on a printing device connected to the access control system 20. This allows the user to confirm the extracted intention and use it for manually defining an access control policy or for validating and modifying a generated access control policy. Note that the access control system 20 may present the extracted intention together with at least one of the sample policy acquired by the judgment sample acquisition unit 211 or the information on the intention acquired by the intention acquisition unit 212, to facilitate user confirmation.

[0050] The policy generation unit 214 acquires a judgment sample from the judgment sample acquisition unit 211, acquires intention information from the intention acquisition unit 212, and acquires intention information extracted for the fourth pattern from the intention extraction unit 213. At this time, the extracted intention information defines the degree of influence on the action for the fourth pattern in the intention information. Then, the judgment sample and the extracted intention information are input to an access control policy generation model (hereinafter referred to as a policy generation model), and machine learning is performed on the policy generation model, thereby causing the policy generation model to generate and output an access control policy that can output an access control action in accordance with the input intention. The access control policy is defined by a combination of a fifth pattern of one or more elements indicating access attributes and an action, and the fifth pattern may be a pattern including the first pattern defined in the sample policy and the third and fourth patterns defined in the intention information.

[0051] Based on the acquired intent, the policy generation model can mimic the method by which an administrator of a network subject to access control determined a sample policy, and can determine in detail patterns of combinations of elements and combinations of actions that were not clearly defined in the sample policy (for example, were ignored because they were out of range or did not have a substantial impact on the access control decision). Here, the policy generation model can automatically adjust the order and magnitude of the impact levels corresponding to the intent-based element combinations to set appropriate values.

[0052] In detail, the policy generation model can generate an access control policy so as to preserve information (order and magnitude) of the impact of the fourth pattern estimated by the intention extraction unit 213. That is, it is possible to ensure that the quantitative action in the fourth pattern defined in the access control policy is consistent with the qualitative impact information of the fourth pattern estimated by the intention extraction unit 213. Then, as an example, the generated access control policy may uniquely identify anonymized portions in the sample policy.

[0053] The policy generation unit 214 described above can be realized by any means such as probability logic, fuzzy logic, linear regression, support vector machine, decision tree, neural network, monotonic regression, monotonic decision tree, monotonic neural network, etc.

[0054] Furthermore, the policy generation unit 214 may generate some kind of algorithm (for example, a program) instead of an access control policy. This program receives a pattern of multiple elements indicating the attributes of a predetermined access (for example, a requested access) and outputs an action corresponding to the pattern. The policy generation unit 214 outputs the program to the determination unit 22, and the determination unit 22 uses the program to determine the action for the request.

[0055] The parameter storage unit 215 stores parameters necessary for the policy generation unit 214 to generate an access control policy. The policy generation unit 214 obtains the parameters from the parameter storage unit 215 when generating an access control policy.

[0056] Fig. 4 is a conceptual diagram showing the processing performed by the intention extraction unit 213 and the policy generation unit 214. Fig. 4 shows an intention extraction model M1 used by the intention extraction unit 213, a policy generation model M2 used by the policy generation unit 214, and data input to or output from each model. Below, an overview of the processing for generating an access control policy will be explained again using Fig. 4.

[0057] The intention extraction model M1 receives as input the sample policy acquired by the judgment sample acquisition unit 211 and the intention (for example, a fourth pattern of one or more elements indicating an attribute) acquired by the intention acquisition unit 212. The intention extraction model M1 performs machine learning using the data, extracts an intention, and outputs it.

[0058] The policy generation model M2 receives as input the sample policy acquired by the judgment sample acquisition unit 211, the intention (input intention) acquired by the intention acquisition unit 212, and the intention extracted by the intention extraction model M1. The policy generation model M2 performs machine learning using these data, generates an access control policy, and outputs it.

[0059] Figure 5 shows an example of an intention extracted by the intention extraction model M1. The horizontal axis in Figure 5 represents the organization to which the user belongs, with organization names A1, A2, A3, and A4 set from left to right. On the other hand, the vertical axis in Figure 5 represents the resource type, with type names B1, B2, B3, and B4 set from left to right.

[0060] In Figure 5, combinations of (organization, resource type) are ranked 1, 2, 3, 15, and 16 in descending order of impact. In other words, as a result of learning, the intent extraction model M1 assigns combinations of (organization, resource type) in descending order of impact value as (A2, B2), (A1, B1), (A3, B4), and (A2, B4). The higher the ranking, the more likely the corresponding action is to be "approved," and the lower the ranking, the more likely the corresponding action is to be "denied." A combination with a high ranking may represent an access that is highly secure from a security perspective, or may represent an access that is natural from the perspective of the organizational department structure, etc. The opposite is true for combinations with a low ranking.

[0061] In this example, we assumed a set of two types of elements expressed in two dimensions as the intention, but similar intentions can also be extracted for a set of N types of arbitrary elements expressed in N dimensions (N: natural number).

[0062] The access control system 20 can adopt any of the following three timings for learning the intention extraction model M1 and the policy generation model M2 described above.

[0063] (1) The access control system 20 causes the intention extraction unit 213 and the policy generation unit 214 to simultaneously learn the intention extraction model M1 and the policy generation model M2, respectively. At this time, the access control system 20 coordinates the learning of the intention extraction model M1 and the policy generation model M2 by learning the intention extraction model M1 so that the accuracy of the finally generated access control policy is improved (i.e., the accuracy of the policy generation model M2 is improved).

[0064] (2) The access control system 20 first causes the policy generation unit 214 to learn the policy generation model M2. After constructing the policy generation model M2 in this way, the access control system 20 causes the intention extraction unit 213 to learn the intention extraction model M1 so that the output result of the policy generation model M2 approaches the access control action that is actually expected to be taken by the administrator.

[0065] In addition, in (1) and (2), the intention extraction unit 213 can adjust the intention extraction model M1 so that the influence level in the fourth pattern is output (estimated) so that the degree of match between the combination of element patterns and actions defined in the sample policy and the combination of element patterns and actions generated by the policy generation model M2 increases.

[0066] (3) The access control system 20 first causes the intention extraction unit 213 to learn the intention extraction model M1. After the intention extraction model M1 is constructed in this way, the access control system 20 causes the policy generation unit 214 to learn the policy generation model M2.

[0067] Comparing (1) to (3), (1) can extract complex intentions and generate policies through the interaction of two learning models, the intention extraction model M1 and the policy generation model M2. Furthermore, because learning is performed simultaneously, the total learning time can be expected to be shortened. In contrast, (2) and (3) avoid excessive adaptation to the learning dataset and policy, enabling simpler yet more valid and robust intention extraction and policy generation. Note that both methods (1) and (2) can be realized by any means, such as rule extraction, decision trees, clustering, linear regression, support vector machines, neural networks, stochastic process regression, and models with constraints on these. Furthermore, method (3) can be realized by the policy generation unit 214 using any means, such as a statistical method, such as correlation analysis between access attributes and actions (e.g., analysis of the correlation between the attribute "authentication method" and the action "authorization") or causal inference between the two.

[0068] The policy generation by the policy generation system 21 described above is performed before the access control determination is started by the determination unit 22. This allows the determination unit 22 to accurately perform access control determination using the generated policy.

[0069] In recent years, advances in zero-trust network technology have increased the importance of access control in such networks. Zero-trust networks can be applied to, for example, local 5G (5th Generation) networks used by companies, local governments, etc.

[0070] A zero trust network calculates a security score for access from all devices and determines whether to allow that access. This prevents threats from accessing important files even if they infiltrate the network, preventing the spread of damage. Furthermore, a zero trust network does not simply block access from outside the network, but instead makes a decision based on the above-mentioned score calculation to allow trusted access. This allows for both network security and availability.

[0071] In such a zero trust network, the network's policy engine determines whether to allow or deny access by integrating various information based on perspectives such as risk, needs, and trust. Accurately determining whether to allow or deny access requires the generation of detailed policies. Furthermore, it is preferable that the policies generated be dynamic, so that even if the network environment (multiple elements related to access control) changes, the environmental changes can be accurately reflected in the policies. This makes the generated policies complex, posing a challenge in how to define or generate such policies.

[0072] For example, when an administrator of a network subject to access control generates a policy, that administrator may have extensive knowledge of a particular perspective (e.g., security functions, department structure, etc.), but little knowledge of other perspectives. Therefore, the accuracy of the generated policy may be degraded, and access control actions may not be accurately determined under diverse circumstances. While it is conceivable that multiple administrators may each generate policies and then integrate those policies to generate a new policy, even in this case, the integrated policy may not cover all diverse situations, resulting in missing definitions that prevent accurate action determination. For example, as mentioned above, this situation occurs when some of the policy definitions are incomplete (parts are anonymized). If a person were to manually review all definitions to resolve this issue, it would likely require a great deal of time and effort.

[0073] In contrast to this, in the second embodiment, even if there is a part that is not defined in the sample policy of the judgment sample, the intention extraction unit 213 can automatically extract an intention that can interpolate that part based on the intention information acquired by the intention acquisition unit 212. In detail, the intention extraction unit 213 inputs, into the intention extraction model, a sample policy (data set) that defines multiple combinations of element patterns and access control actions corresponding to those patterns, and intention information that includes element patterns that indicate access attributes. This makes it possible to estimate the impact of a pattern (fourth pattern) in the intention information for which the impact is not defined.

[0074] The policy generation unit 214 then generates an access control policy using not only known intentions but also newly extracted information about the intentions. Therefore, even if the accuracy of the sample policy cannot be improved because the user who defined the sample policy lacked knowledge or because elements were not uniquely identified, the accuracy of the finally generated access control policy can be improved. This also makes it possible to expand the range of network systems to which the access control policy can be applied.

[0075] Furthermore, since the administrator does not need to check all the definitions necessary for access control, the time and effort required to generate an access control policy can be reduced. Furthermore, there is no need to define all the information required to generate an access control policy as a sample policy, and the access control policy can be automatically generated by having the intention acquisition unit 212 acquire the information as an intention (a set of one or more elements indicating the attributes of the access and a combination of information on the corresponding impact).

[0076] Furthermore, the intention extraction unit 213 can estimate the order and magnitude of the degree of influence that will affect an action for a pattern (fourth pattern) of one or more elements that indicate attributes of access, for which neither the order nor the magnitude of the degree of influence that will affect an action is defined, among the intentions acquired by the intention acquisition unit 212. As a result, the intention extraction unit 213 executes processing only for those for which estimation of the degree of influence is necessary, thereby minimizing the processing load of the entire access control system 20.

[0077] Furthermore, the actions are defined as a totally ordered set, and the intention extraction unit 213 may estimate the order and magnitude of the impact so that they are order-isomorphic to the actions. As a result, when the impact changes toward approval or denial, the actions defined in the access control policy change in a direction corresponding to the change. Therefore, the access control system 20 can determine actions that reflect the administrator's intentions.

[0078] Furthermore, the policy generation unit 214 can generate an access control policy (a combination of an action and a fifth pattern of one or more elements indicating attributes of access) so as to preserve information on the order and magnitude of the impact levels estimated by the intention extraction unit 213. This allows the access control system 20 to make the action determined by the access control policy the one assumed to be intended by the administrator.

[0079] Furthermore, the intention extraction unit 213 can output (estimate) the influence degree in the fourth pattern so that the degree of match between the combination of the element pattern (first pattern) and action defined in the sample policy and the combination of the element pattern and action generated by the policy generation model M2 increases. This allows the action determined by the access control policy to reflect the administrator's intention indicated in the sample policy.

[0080] Furthermore, at the stage when the intention extraction unit 213 extracts an intention, the extracted intention may be visualized and presented to the user. By the user verifying the validity of the presented intention, the user can check the sample policy acquired by the judgment sample acquisition unit 211 and the intention information acquired by the intention acquisition unit 212, which can lead to verifying their validity. If the sample policy or the information on the intention is invalid, the user can correct the data and have the judgment sample acquisition unit 211 or the intention acquisition unit 212 acquire it, thereby improving the accuracy of the access control policy. Furthermore, the time and effort required to verify the validity of the sample policy can be reduced.

[0081] The present invention is not limited to the above-described embodiment, and can be modified as appropriate within the scope of the invention.

[0082] The fourth pattern in the second embodiment may include a pattern of one or more elements indicating attributes of accesses, in which either the order or the magnitude of the influence that affects the action is defined. By inputting such a pattern to the intention extraction model M1, the intention extraction unit 213 can estimate the other of the order or magnitude of the influence that is not defined in the pattern and output it as the extracted intention.

[0083] In addition, in the second embodiment, an example in which an access control policy is generated using both the order and magnitude of the impact degrees has been described. However, an access control policy may be generated using only one of them. In such a case, the intention acquired by the intention acquisition unit 212 is defined as a pattern (third pattern) of one or more elements indicating the attributes of the access, in which either the order or magnitude of the impact degrees affecting the action is defined, and a pattern (fourth pattern) of one or more elements indicating the attributes of the access, in which neither the order nor magnitude of the impact degrees affecting the action is defined. Even in such a case, the intention extraction unit 213 may generate and output, for each pattern, either the order or magnitude of the impact degrees on the access control action according to each element pattern, in the same manner as described in the second embodiment.

[0084] Even in the above case, the policy generation unit 214 can generate an access control policy by performing machine learning on the policy generation model using the information on the intention extracted by the intention extraction unit 213, as in the second embodiment. Therefore, an access control policy with high accuracy can be generated.

[0085] Furthermore, in the second embodiment, as a method for determining the order and magnitude of the numerical impact, a totally ordered set is defined in which the numerical impact value becomes larger in the positive direction when the action is moving in the direction of "approval" rather than "denial." However, the totally ordered set is not limited to this example, and any arbitrary one can be used.

[0086] Furthermore, the determination unit 22 can be modified as follows. As described above, the determination unit 22 uses the access control policy to determine an access control action when a request is made. Here, the determination unit 22 does not need to refer to the data store 23 and acquire background attributes corresponding to the request each time it receives a request. Before receiving a request, the determination unit 22 modifies the variables related to the background attributes of the access control policy acquired from the policy generation unit 214 so that the current background attributes are reflected. This allows the determination unit 22 to generate a temporary access control policy. As a result, unless the current background attributes are changed, the determination unit 22 does not need to refer to the data store 23 when receiving a request and determining an action; it can simply refer to the elements in the request. In this way, by performing a two-stage operation, the determination unit 22 can determine an action more quickly when a request is accepted. Furthermore, since the amount of processing performed per request can be reduced, the hardware of the control device in which the determination unit 22 is installed can be made more cost-effective. Note that the temporary access control policy may be generated by the policy generation system 21 rather than by the determination unit 22.

[0087] Here, the determination unit 22 may use only elements related to the attributes of the packet header included in the request (for example, at least one of the IP address of the access source or the access destination, and the port number) as data to be input into the temporary access control policy. This allows the enforcer 24 (access control device) to be a general firewall, packet filter, SDN (Software Defined Network) switch, or V-LAN (Virtual Local Area Network) as a control device equipped with the determination unit 22. This makes it possible to configure the device related to the determination unit 22 as an inexpensive device.

[0088] In the above-described embodiments, this disclosure has been described as a hardware configuration, but this disclosure is not limited to this. This disclosure can also be realized by having a processor in a computer execute a computer program to perform the processes (steps) of the policy generation device or policy generation system described in the above-described embodiments.

[0089] 6 is a block diagram showing an example of the hardware configuration of an information processing device (signal processing device) that executes the processes of the above-described embodiments. Referring to FIG. 6, this information processing device 90 includes a signal processing circuit 91, a processor 92, and a memory 93.

[0090] The signal processing circuit 91 is a circuit for processing signals in accordance with the control of the processor 92. The signal processing circuit 91 may include a communication circuit for receiving signals from a transmitting device.

[0091] The processor 92 is connected (coupled) to the memory 93, and performs the processing of the device described in the above embodiment by reading and executing software (computer programs) from the memory 93. As an example of the processor 92, one of a CPU (Central Processing Unit), an MPU (Micro Processing Unit), an FPGA (Field-Programmable Gate Array), a DSP (Demand-Side Platform), and an ASIC (Application Specific Integrated Circuit) may be used, or a plurality of these may be used in parallel.

[0092] The memory 93 is configured with a volatile memory, a nonvolatile memory, or a combination thereof. The memory 93 is not limited to one, and multiple memories may be provided. The volatile memory may be, for example, a RAM (Random Access Memory) such as a DRAM (Dynamic Random Access Memory) or an SRAM (Static Random Access Memory). The nonvolatile memory may be, for example, a ROM (Random Only Memory) such as a PROM (Programmable Random Only Memory) or an EPROM (Erasable Programmable Read Only Memory), a flash memory, or an SSD (Solid State Drive).

[0093] The memory 93 is used to store one or more instructions. Here, the one or more instructions are stored as a group of software modules in the memory 93. The processor 92 can perform the processes described in the above embodiments by reading and executing the group of software modules from the memory 93.

[0094] The memory 93 may include memory built into the processor 92 in addition to memory provided outside the processor 92. The memory 93 may also include storage located away from the processors constituting the processor 92. In this case, the processor 92 can access the memory 93 via an I / O (Input / Output) interface.

[0095] As described above, one or more processors included in each device in the above-described embodiments execute one or more programs including instructions for causing a computer to execute the algorithms described using the drawings. This processing enables the signal processing method described in each embodiment to be realized.

[0096] The program includes instructions (or software code) that, when loaded into a computer, cause the computer to perform one or more functions described in the embodiments. The program may be stored in a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, computer-readable media or tangible storage media include random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD) or other memory technologies, CD-ROM, digital versatile disk (DVD), Blu-ray® disk or other optical disk storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage device. The program may also be transmitted on a transitory computer-readable medium or communication medium. By way of example and not limitation, transitory computer-readable media or communication media include electrical, optical, acoustic, or other forms of propagated signals.

[0097] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above. Various modifications that can be understood by a person skilled in the art can be made to the configuration and details of the present disclosure within the scope of the disclosure. [Explanation of symbols]

[0098] 10 Analyzer 11 Acquisition part 12 Estimation part 20 Access Control Systems 21 Policy generation system 22 Judgment unit 23 Data Store 24 Enforcer 211 judgment sample acquisition unit 212 intention acquisition unit 213 Intention Extraction Unit 214 Policy Generation Unit 215 Parameter storage section

Claims

1. an acquisition means for acquiring a data set in which a plurality of combinations of a first pattern of one or more elements indicating an access attribute and an access control action corresponding to the first pattern are defined, and a second pattern of one or more elements indicating an access attribute; and an estimation means for estimating at least one of the order or magnitude of the degree of influence that the second pattern has on the action, using the data set and the second pattern. Analyzer.

2. the acquiring means acquires, as the second pattern, a third pattern of one or more elements indicating attributes of access, in which at least one of the order or magnitude of the influence degree that influences the action is defined, and a fourth pattern of one or more elements indicating attributes of access, in which at least one of the order or magnitude of the influence degree defined in the third pattern is not defined; the estimation means estimates at least one of an order or a magnitude of an influence degree by which the fourth pattern influences the action; The analytical device of claim 1 .

3. the actions are defined as a totally ordered set; the estimation means estimates at least one of the order or magnitude of the influence degrees so as to be order isomorphic to the order of the actions; The analytical device of claim 1 .

4. and a generating unit configured to generate a combination of the action and a fifth pattern of one or more elements indicating an attribute of the access for use in access control, so that information on at least one of the order or magnitude of the degree of impact estimated by the estimating unit is preserved. The analytical device according to any one of claims 1 to 3.

5. the estimation means estimates at least one of an order or a magnitude of an influence of the second pattern on the action so as to increase a degree of coincidence between a combination of the first pattern and the action defined in the data set and a combination of the fifth pattern and the action generated by the generation means. The analytical device according to claim 4 .

6. and visualizing at least one of the order and magnitude of the estimated influence degrees and presenting it to a user. The analytical device according to any one of claims 1 to 5.

7. acquiring a data set in which a plurality of combinations of a first pattern of one or more elements indicating an access attribute and an access control action corresponding to the first pattern are defined, and a second pattern of one or more elements indicating an access attribute; using the data set and the second pattern to estimate at least one of the order and magnitude of the influence of the second pattern on the action; A computer-implemented analytical method.

8. acquiring a data set in which a plurality of combinations of a first pattern of one or more elements indicating an access attribute and an access control action corresponding to the first pattern are defined, and a second pattern of one or more elements indicating an access attribute; using the data set and the second pattern to estimate at least one of the order and magnitude of the influence of the second pattern on the action; A program that makes a computer do something.

Citation Information

Patent Citations

  • Access policy creation system, method and program

    JP2007109016A

  • Extraction and conversion of security policies from native representations of access check mechanisms

    JP2009540397A

  • Access control policy warnings and suggestions

    US10986131B1