Automated Access Control Policy Verification Using Machine Learning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control management in IT infrastructure is inefficient due to reliance on manual, sporadic, and error-prone methods, leading to inconsistent policy enforcement and vulnerabilities in complex, dynamic environments, particularly in cloud infrastructure where rapid changes and large scales make comprehensive verification impractical.
Innovation Solution
The implementation of a processor-implemented method using machine learning and AI techniques to normalize, visualize, and enforce access control policies across a distributed IT infrastructure, creating an access control graph to identify non-compliant policies and automate continuous verification and enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If manual access control verification methods are used, then implementation simplicity is maintained, but verification comprehensiveness and security reliability deteriorate
Solution Approach 1:
The patent replaces manual mechanical verification processes with an automated computer-implemented system that uses machine learning models to continuously analyze access control policies, entity relationships, and infrastructure configurations, thereby maintaining simplicity while dramatically improving verification reliability and comprehensiveness
Solution Approach 2:
The system enables self-service automation where the access control management system automatically performs continuous verification, policy analysis, and anomaly detection without requiring manual intervention, allowing the system to monitor and enforce its own security policies across the entire infrastructure
2Use of energy by moving object
If sporadic manual reviews are conducted, then resource consumption is reduced, but security coverage and policy enforcement consistency worsen
Solution Approach 1:
The patent implements continuous automated verification that operates continuously across the entire IT infrastructure, constantly monitoring access control policies, entity relationships, and configuration changes to ensure consistent enforcement without gaps, thereby maintaining security reliability while using computational resources efficiently through automated processes
3Reliability
If comprehensive automated verification is implemented, then security reliability and policy enforcement consistency improve, but system complexity and computational resource requirements worsen
Solution Approach 1:
The patent segments the complex verification task into distinct functional components including machine learning model training, entity relationship analysis, policy configuration validation, and anomaly detection modules, allowing each component to specialize in specific aspects of access control verification while working together to provide comprehensive security coverage
Solution Approach 2:
The system introduces an intermediary access control graph that represents entity relationships and access patterns in a structured format, serving as a mediator between raw infrastructure data and verification logic, thereby simplifying the complexity of analyzing complex access control policies and entity relationships
4Ease of operation
If manual access control analysis is performed, then ease of operation is maintained, but verification speed and responsiveness to infrastructure changes worsen
Solution Approach 1:
The patent replaces manual analysis operations with automated machine learning-based verification processes that continuously monitor and analyze access control policies, entity relationships, and infrastructure configurations at high speed, maintaining ease of operation through automated processes while dramatically improving verification speed and responsiveness to changes
Data Source
AI summary
Normalized access control policies associated with entities in an information technology (IT) infrastructure comprising a plurality of subsystems may be obtained based on a stored access control policy representation governing access to resources in the IT infrastructure. Based on the normalized access control policies, entity clusters associated with the entities may be determined. Further, derived access control policies corresponding to the at least one entity cluster may be determined. A set of non-compliant access control policies may be determined where the set of non-compliant access control policies may comprise: a subset of the normalized access control policies that are non-compliant with stated access control policies applicable to the entity clusters, and/or a subset of the derived access control policies that are non-compliant with the stated access control policies. Machine learning and/or Artificial Intelligence techniques may be used to determine, maintain, and audit policies for the IT infrastructure.


