Automated Attribute Selection for User Entitlement Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managers face challenges in manually reviewing and understanding the risks associated with user authorizations and entitlements in enterprise systems, especially as the number of applications and user entitlements grows, leading to potential inappropriate approvals.
Innovation Solution
An automated method is implemented to select user attributes using predefined information content rules, such as entropy, unique values, distribution, and cross-correlation tests, to identify anomalies in user application entitlements, providing context for informed decision-making during attestation reviews.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual review of user entitlements is performed, then understanding of potential risks is improved, but time consumption and operational burden increase significantly
Solution Approach 1:
The system introduces automated attribute selection and anomaly detection as intermediary components between the manual review process and the entitlement data. These components process and analyze entitlement information automatically, generating insights and flags that assist managers in their review decisions without requiring them to manually examine all entitlement details.
Solution Approach 2:
The system enables self-service by automatically selecting relevant user attributes and identifying potential anomalies in entitlement data. The automated attribute selection process independently determines which attributes are most relevant for anomaly detection, and the system automatically generates review priorities and risk assessments without requiring manual intervention for each analysis step.
2Adaptability or versatility
If the number of applications and user entitlements increases, then system functionality is improved, but complexity of manual review increases
Solution Approach 1:
The system extracts and isolates the most relevant attributes for anomaly detection from the comprehensive set of user attributes. By automatically selecting and extracting only the critical attributes needed for entitlement analysis, the system reduces the complexity of review while maintaining the ability to handle diverse application scenarios and user roles.
Solution Approach 2:
The system segments the entitlement review process into distinct phases: automated attribute selection, anomaly detection, and manager review of flagged items. This segmentation allows the system to handle large numbers of applications and entitlements by processing them in manageable chunks through automated analysis, reducing the cognitive load and complexity for manual review.
3Productivity
If automated attribute selection is implemented, then review efficiency is improved, but system complexity increases
Solution Approach 1:
The system changes the parameters of attribute selection from manual to automated based on statistical criteria. The automated attribute selection process uses configurable parameters such as information content thresholds and correlation coefficients to automatically determine which attributes are most relevant for anomaly detection, improving review efficiency while keeping the system complexity manageable through parameter-based automation.
Data Source
AI summary
Techniques are provided for selecting attributes to cluster users for a user application entitlement evaluation. An exemplary method comprises obtaining enterprise reference data indicating a plurality of attributes for a plurality of enterprise users; obtaining enterprise entitlement data indicating user application entitlements for the plurality of enterprise users; selecting at least one of the plurality of attributes as a cluster attribute using predefined information content rules applied on the enterprise entitlement data; determining a probability of a user application entitlement for the one or more user application entitlements based on a number of users for a plurality of values of the cluster attribute and a number of users for a plurality of pairs of the cluster attribute and a value of the one or more user application entitlements; and identifying anomalies in the enterprise entitlement data based on the probability of the user application entitlement for at least one user application entitlement and at least one predefined anomaly threshold.


