Automated Privilege Escalation Detection in Cloud IAM

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional identity and access management systems in cloud computing environments are unable to effectively detect and mitigate both vertical and horizontal privilege escalation threats, which can lead to over-privileged access, straining resources and posing additional risks due to their inability to continuously monitor and identify threats across large volumes of access rights.

Innovation Solution

A method and system for identifying over-privileged access in a computing system by receiving configuration information, determining accessible resources and services, and identifying roles that can elevate privileges, providing notification when over-privileged access is detected, thereby enabling continuous monitoring and mitigation of both vertical and horizontal privilege escalation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If conventional IAM techniques are used to manage access rights, then manual methods can determine least privilege access, but they are neither feasible nor scalable to cloud computing environments with growing number of entitlements

Engineering Contradiction:
Improveaccess management efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent replaces manual IAM techniques with an automated simulation-based system that uses virtual identities to traverse and discover access paths in cloud environments. This substitution enables scalable detection of privilege escalation threats without requiring manual review of growing numbers of entitlements.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs self-service by automatically simulating access traversals from user identities to discover horizontal and vertical privilege escalation paths. The simulation engine autonomously explores the cloud environment configuration to identify over-privileged access without external intervention.

Inventive Principle:
Principle #25Self-service

2Reliability

If conventional detection solutions focus on vertical privilege escalation, then they can identify some over-privileged access, but they are unable to detect horizontal escalation and resulting vertical escalation threats

Engineering Contradiction:
Improvethreat detection capabilityVSAvoiddetection complexity
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the privilege escalation detection into two distinct simulation modes: horizontal escalation simulation (traversing same-privilege resources) and vertical escalation simulation (traversing higher-privilege resources). This segmentation enables comprehensive detection of both escalation types and their interconnected threats.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a dimensional perspective by introducing the concept of privilege levels as a vertical dimension to the traditional horizontal resource traversal. This allows the system to detect not only horizontal escalation but also vertical escalation that may result from compromised horizontal access paths.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If continuous monitoring of privilege escalation is implemented, then detection capability is improved, but resource strain increases due to large volumes of access rights to review

Engineering Contradiction:
Improvecontinuous detection capabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent performs preliminary action by conducting simulation-based discovery of privilege escalation paths before actual threats materialize. The system proactively identifies over-privileged access configurations and enables preventive mitigation, reducing the need for continuous intensive monitoring of all access rights.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously monitoring for changes in cloud environment configuration (policies, roles, resources) and re-running simulations only when changes occur. This event-driven approach maintains continuous detection capability while minimizing unnecessary computational resource consumption.

Inventive Principle:
Principle #23Feedback

4Measurement precision

If manual methods are used to determine least privilege access, then accuracy can be maintained, but they are not feasible in cloud computing environments with large numbers of users and resources

Engineering Contradiction:
Improveaccess rights accuracyVSAvoidscalability
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent replaces manual determination of least privilege with automated simulation that objectively analyzes actual access paths in the cloud environment. The simulation accurately identifies over-privileged access by comparing user access rights against actual traversal paths to sensitive resources, maintaining precision while enabling scalability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11777948B2System and method of managing privilege escalation in cloud computing environments
Publication Date: 2023.10.03 THREATMODELER SOFTWARE INC
  • US11777948B2 patent drawing
  • US11777948B2 patent drawing
  • US11777948B2 patent drawing

AI summary

Systems and methods of identifying over-privileged access in a computing system are disclosed. The method includes receiving configuration information for the computing system, selecting an identity that can access the computing system and determining access privileges for the selected identity using at least the received configuration information, the access privileges identifying one or more computing resource or service accessible to the selected identity, determining at least one role assumable by the identified one or more computing resource or service accessible to the selected identity, and determining whether the identified one or more computing resource or service accessible to the selected identity can elevate its privileges. In a case where it is determined that the identified one or more computing resource or service accessible to the selected identity can elevate its privileges, the method provides notification that the identity has over-privileged access to the computing system.