Abnormal Classic Authorization Detection in Cloud Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack effective mechanisms to detect abnormal classic authorization events in cloud storage, which can be exploited by attackers to evade detection and perform unauthorized actions.

Innovation Solution

A system is implemented that uses anomaly scoring and indicator scoring to detect suspicious classic authorization events. Anomaly scoring is based on machine learning models that analyze patterns in classic assignment events, while indicator scoring applies domain-based rules to log data. The system generates a final security score to determine appropriate actions, such as preventing access or alerting administrators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a classic authorization system is used to manage access to cloud storage resources, then access control is simplified and easier to operate, but the system becomes vulnerable to unauthorized access and data breaches

Engineering Contradiction:
Improveaccess control simplicityVSAvoidsecurity against unauthorized access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by establishing baseline behavior patterns for classic administrators through machine learning models. These baselines are built from historical authorization data and are continuously updated to reflect normal operational patterns, enabling proactive detection of deviations before they result in breaches

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where authorization events are monitored, analyzed against machine learning models and domain rules, and fed back into the system to update baselines and refine detection capabilities. This feedback mechanism enables the system to adapt to changing operational patterns while maintaining security

Inventive Principle:
Principle #23Feedback

2Object-generated harmful factors

If attackers create or assign classic administrator roles to perform unauthorized actions, then the attackers can evade detection and access resources, but the system can detect abnormal authorization patterns through anomaly scoring

Engineering Contradiction:
Improveunauthorized access capabilityVSAvoiddetection of abnormal authorization
Core Design Contradiction:
Object-generated harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The system replaces traditional mechanical access control lists with intelligent detection mechanisms that use machine learning models and domain rules to analyze authorization patterns. This substitution enables the system to detect abnormal behaviors based on contextual analysis rather than relying solely on predefined permission checks

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the parameters of detection by introducing anomaly scores and indicator scores that quantify the likelihood of malicious authorization events. These scores are derived from multiple factors including timing, source IP addresses, target resources, and behavioral patterns, transforming qualitative security monitoring into quantitative measurement

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the system monitors and analyzes classic authorization events to detect anomalies, then security detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex security monitoring function into distinct components: machine learning model analysis, domain rule evaluation, anomaly scoring, and indicator scoring. This segmentation allows each component to handle specific aspects of authorization analysis independently, making the overall system more manageable and easier to maintain

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces intermediary scoring mechanisms (anomaly scores and indicator scores) that mediate between raw authorization events and final security decisions. These intermediaries simplify the decision-making process by providing standardized metrics that can be compared against thresholds and trigger appropriate responses without requiring complex real-time analysis

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12282546B2Abnormal classic authorization detection systems
Publication Date: 2025.04.22 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12282546B2 patent drawing
  • US12282546B2 patent drawing
  • US12282546B2 patent drawing

AI summary

A system to detect an abnormal classic authorizations, such as in a classic authorization system of a resource access management system, and take action is described. The system determines an anomaly score in from a model applied to a classic assignment event. An indicator score is determined from the classic assignment event applied to domain-based rules. The security action is taken based on a combination of the anomaly score and the indicator score.