Anomalous Authorization Alerting via Proximity Graph
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large organizations face inefficiencies and inaccuracies in managing user authorization requests for access to applications and modules, relying heavily on manual reviews by managers, which is time-consuming and prone to errors.
Innovation Solution
Implementing a system that uses organizational relationships and machine learning to calculate a critical score for user authorization requests, comparing them to peer group datasets to autonomously approve or deny access based on normalized IDF and Jensen-Shannon Divergence analysis, and validating user profiles by determining normalized divergence values.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual review by managers is used to authorize user requests, then authorization accuracy can be maintained through human judgment, but the process becomes time-consuming and inefficient
Solution Approach 1:
The system performs preliminary analysis by generating peer group datasets and calculating baseline probability distributions of authorization patterns before evaluating individual requests. This pre-computed contextual information enables rapid automated decision-making while maintaining accuracy, resolving the contradiction between speed and reliability.
Solution Approach 2:
The patent introduces an intermediary automated authorization system that acts as a mediator between user requests and final approval. This intermediary uses machine learning models to analyze requests against peer group patterns, handling routine cases automatically while flagging only anomalous cases for human review, thus reducing processing time without sacrificing accuracy.
2Productivity
If automated systems are used to process authorization requests, then processing speed and efficiency are improved, but accuracy and detection of anomalous requests may deteriorate
Solution Approach 1:
The system implements feedback mechanisms where automated authorization decisions are continuously evaluated against actual outcomes and peer group patterns. The machine learning models are retrained with new data, and the probability distributions are updated, creating a closed-loop system that improves detection accuracy over time while maintaining high processing throughput.
Solution Approach 2:
The patent dynamically adjusts decision thresholds and probability cutoffs based on contextual factors and historical performance. By changing the sensitivity parameters of the detection system, the automated model can optimize the balance between processing speed and detection accuracy for different operational contexts.
3Reliability
If individual user authorization requests are reviewed manually to ensure security, then security accuracy is maintained, but the complexity and resource requirements of the system increase
Solution Approach 1:
The authorization system is segmented into distinct functional modules: peer group dataset generation, probability distribution calculation, request evaluation, and anomaly detection. Each module performs a specific function and can be independently optimized or updated, reducing overall system complexity while maintaining security verification accuracy.
4Measurement precision
If manual authorization review processes are used, then detailed analysis of each request can be performed, but the quantity of requests that can be processed decreases
Solution Approach 1:
The system applies full analytical depth only to requests that deviate from normal peer group patterns, while routine requests receive streamlined processing. By performing detailed analysis partially (only when necessary), the system maintains measurement precision for anomalous cases while significantly increasing overall productivity.
Data Source
AI summary
An information-security automated process for authorizing a user request for access to a module and for identifying anomalous user authorization requests, may be implemented on a computer machine and may include the steps of receiving a user request for access to a module, generating a peer group proximity dataset, generating a user dataset, calculating a critical score, determining if the critical score is less than an enterprise threshold, and generating an approval or denial of the user request based upon the critical score. In some examples the process may include the step of executing machine learning instructions to generate a second approval or a second denial of a second user request for access to a second module. In another examples an information-security automated process for validating a user authorization access profile is disclosed herein.


