Adaptive Role-Based Access Control via Behavior Analytics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cybersecurity breaches often occur due to users unintentionally engaging in unsafe internet practices, which organizations struggle to mitigate despite training, as cyber-attack methods evolve faster than awareness can be disseminated, leading to vulnerabilities in computer systems and networks.

Innovation Solution

A method that receives user behavior data from devices, generates risk levels based on email accounts, browser histories, and password usage, simulates potential risk events, and adjusts role-based access controls to prevent risky behaviors, reducing the likelihood of data and infrastructure vulnerabilities by restricting access and privileges.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cybersecurity training is provided to users, then awareness of safe internet practices is improved, but the system remains vulnerable because cyber-attack methods evolve faster than training can be updated

Engineering Contradiction:
Improvecybersecurity reliabilityVSAvoidspeed of cyber-attack evolution
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system performs preliminary actions by continuously monitoring user behavior patterns and predicting potential security risks before they materialize into actual breaches. The behavior analytics engine proactively identifies suspicious activities and triggers preventive measures such as access control adjustments or user notifications, allowing the system to anticipate and counter evolving cyber-attacks rather than merely reacting to them after training updates are needed.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If user behavior is monitored and access control is adjusted to prevent risky behaviors, then system security is improved, but user productivity may be impacted due to restricted access

Engineering Contradiction:
Improvesystem securityVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies dynamics by making access controls adaptive and flexible rather than static. The behavior analytics engine continuously evaluates user actions in real-time and dynamically adjusts permissions based on contextual factors such as time of day, location, device reliability, and specific action patterns. This allows the system to maintain security by restricting access only when and where risks are detected, while preserving full productivity for legitimate users through dynamic, context-aware permission management.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements local quality by applying differentiated access control policies to different users, different data, and different actions based on their individual risk profiles and behaviors. Rather than a blanket restriction, the system evaluates each access request contextually and applies appropriate permissions locally, allowing users to maintain productivity in low-risk scenarios while receiving enhanced protection in high-risk situations.

Inventive Principle:
Principle #3Local quality

3Reliability

If continuous behavior monitoring and risk prediction is implemented, then prevention of cyber-attacks is improved, but system complexity increases

Engineering Contradiction:
Improveattack prevention capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system achieves universality by implementing a multi-functional behavior analytics engine that performs multiple security functions through a unified approach. The same engine that collects behavior data also analyzes patterns, predicts risks, evaluates threats, and triggers preventive actions. This consolidated architecture reduces overall system complexity compared to having separate specialized systems for each function, while maintaining comprehensive attack prevention capabilities through integrated multi-functional processing.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12086254B2Adjusting role-based access control of a user based on behavior data of the user
Publication Date: 2024.09.10 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12086254B2 patent drawing
  • US12086254B2 patent drawing
  • US12086254B2 patent drawing

AI summary

A computer-implemented method according to one approach includes receiving behavior data associated with a user's behavior on at least one device. The behavior data is based on one or more of an email account, a browser history, password usage and online behavior history. Risk levels associated with the behavior data are generated and role-based risk events are predicted based on the behavior data. The method further includes simulating the role-based risk events based on the risk levels, and adjusting role-based access control of the user based on results of the simulating. A computer program product for adjusting role-based access control according to another approach includes a computer readable storage medium having program instructions embodied therewith. The program instructions are readable and/or executable by a computer to cause the computer to perform the foregoing method.