Access Policy Anomaly Detection Using User-Resource Embeddings
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional access control systems face challenges in maintaining consistent, minimal, and complete access control policies due to user and resource changes, leading to inconsistent, excessive, and incomplete access control, which increases the risk of unauthorized access and data breaches.
Innovation Solution
Utilizing non-negative matrix factorization and embedding techniques to identify user-resource anomalies, assign correct access rights, and manage access control policies efficiently, ensuring consistency and completeness by clustering user and resource embeddings.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional access control policy management methods are used in large organizations with constantly changing users and resources, then manual policy maintenance becomes increasingly complex and error-prone, but automated solutions using matrix factorization and embedding techniques require significant computational resources and data processing infrastructure
Solution Approach 1:
The patent replaces manual mechanical policy maintenance with automated computational analysis using matrix factorization and embedding techniques. The system automatically processes user-resource access data, identifies anomalies, and generates policy recommendations, eliminating the need for manual tracking and updating of access control policies in large organizations.
Solution Approach 2:
The patent transforms access control policy management by changing the parameters from manual discrete policy definitions to continuous mathematical representations through matrix factorization. User and resource attributes are converted into embedding vectors, allowing for automated similarity analysis and anomaly detection based on mathematical distance metrics rather than manual policy rules.
2Reliability
If comprehensive access control policies are maintained for all users and resources, then security coverage is maximized, but the complexity of managing and detecting anomalies in access patterns increases significantly
Solution Approach 1:
The patent creates simplified copies of the complex access control system by generating embedding representations of users and resources. These embeddings capture the essential access patterns and relationships in a condensed mathematical form, enabling efficient anomaly detection through distance calculations without requiring direct analysis of the full complexity of all access policies.
Solution Approach 2:
The patent introduces matrix factorization and embedding techniques as intermediary layers between the raw access control data and the anomaly detection process. These mathematical transformations serve as mediators that convert complex user-resource access patterns into comparable vector representations, making anomaly detection computationally feasible while maintaining comprehensive security coverage.
3Adaptability or versatility
If access control policies are frequently updated to adapt to changing organizational needs, then adaptability is improved, but consistency and minimality of policies deteriorate due to accumulation of changes
Solution Approach 1:
The patent implements a feedback mechanism where the system continuously analyzes current access patterns, compares them against learned embeddings, and automatically generates policy recommendations. This closed-loop approach ensures that policy updates are based on actual usage data and similarity analysis, maintaining consistency by only making changes that align with the underlying access patterns rather than accumulating arbitrary modifications.
Solution Approach 2:
The patent performs preliminary analysis of access patterns and generates policy recommendations before actual policy updates are implemented. By pre-processing the data through matrix factorization and embedding, the system identifies optimal policy configurations in advance, allowing for coordinated updates that maintain consistency rather than reactive changes that may conflict with existing policies.
Data Source
AI summary
Certain aspects of the disclosure provide techniques for access control policy management. A method generally includes factorizing a user access co-occurrence data element to generate two data sub-elements, wherein: the user access co-occurrence data element represents co-occurrences between users of a system and resources of the system, a product of the two data sub-elements approximates the user access co-occurrence data element, and each of the two data sub-elements has reduced dimensionality compared to the user access co-occurrence data element; generating an approximated user access co-occurrence data element based on the product of the two data sub-elements; comparing the user access co-occurrence data element and the approximated user access co-occurrence data element to determine one or more anomalies, wherein each of the one or more anomalies relates to access for a user to a resource of the system; and taking one or more actions to rectify the one or more anomalies.


