Automatic Access Permission Replacement via Actual Usage Learning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data access permission management systems rely on user security groups, which can lead to inefficient and insecure access control, as they do not accurately reflect actual user access patterns, potentially allowing unauthorized access due to broad permissions like the MICROSOFT® EVERYONE GROUP.
Innovation Solution
An enterprise system that learns and adapts by replacing user-security group-based access permissions with permissions based on actual access history and patterns, using a subsystem to automatically update permissions without disrupting access, and includes notification and authorization processes to ensure stakeholders are informed and approve changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If user security groups are used for access permission management, then ease of operation is improved, but security reliability deteriorates due to broad permissions allowing unauthorized access
Solution Approach 1:
The system automatically learns actual access patterns from user behavior data and self-adjusts permission assignments without requiring manual intervention. The learned access permission subsystem continuously monitors and adapts permissions based on observed usage patterns, enabling the system to serve itself in optimizing security policies.
Solution Approach 2:
The system implements a feedback loop where actual access history is continuously monitored and fed back into the permission assignment process. The learned access permission subsystem uses this feedback to refine and update access control decisions, creating a dynamic adaptive system that improves security over time based on real usage data.
2Productivity
If automatic permission replacement is implemented, then productivity is improved through automation, but device complexity increases due to multiple subsystems
Solution Approach 1:
The system is divided into distinct functional subsystems: learned access permission subsystem, learned actual access subsystem, and computer security policy administration subsystem. Each subsystem handles a specific aspect of permission management, allowing for modular development and easier maintenance while achieving high-level automation.
Solution Approach 2:
The computer security policy administration subsystem serves multiple functions: it receives data from both learned subsystems, processes permission replacements, manages stakeholder notifications, and coordinates authorization requests. This multi-functional design reduces the need for separate components and simplifies the overall architecture.
3Reliability
If pre-replacement notification and authorization is implemented, then reliability is improved through stakeholder authorization, but loss of time increases due to notification and authorization processes
Solution Approach 1:
The system performs preliminary notifications to stakeholders before executing permission replacements. This advance notice allows stakeholders to prepare for changes and provides an opportunity for them to authorize or object to the replacement in advance, reducing potential delays during the actual permission change execution.
Solution Approach 2:
The notification and authorization process operates periodically rather than continuously. The system notifies stakeholders at scheduled intervals before permission replacements are executed, allowing for batch processing of authorization requests and minimizing the impact on overall system operation time.
Data Source
AI summary
A system for automatically replacing a user security group-based computer security policy by a computer security policy based at least partially on actual access, including a learned access permissions subsystem operative to learn current access permissions of users to network objects in an enterprise computer environment and to provide an indication of which users are members of which user security groups having access permissions to which network objects, a learned actual access subsystem operative to learn actual access history of users in the enterprise to the network objects and to provide indications of which users have had actual access to which network objects, and a computer security policy administration subsystem, receiving indications from the learned access permission subsystem and the learned actual access subsystem and being operative to automatically replace pre-selected user-security group-based access permissions with at least partially actual access-based access permissions without disrupting access to network objects.


