Automated Privilege Escalation Detection in Cloud IAM
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional identity and access management systems in cloud computing environments are unable to effectively detect and mitigate both vertical and horizontal privilege escalation threats, which can lead to over-privileged access, straining resources and posing additional risks due to their inability to continuously monitor and identify threats across large volumes of access rights.
Innovation Solution
A method and system for identifying over-privileged access in a computing system by receiving configuration information, determining accessible resources and services, and identifying roles that can elevate privileges, providing notification when over-privileged access is detected, thereby enabling continuous monitoring and mitigation of both vertical and horizontal privilege escalation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If conventional IAM techniques are used to manage access rights, then manual methods can determine least privilege access, but they are neither feasible nor scalable to cloud computing environments with growing number of entitlements
Solution Approach 1:
The patent replaces manual IAM techniques with an automated simulation-based system that uses virtual identities to traverse and discover access paths in cloud environments. This substitution enables scalable detection of privilege escalation threats without requiring manual review of growing numbers of entitlements.
Solution Approach 2:
The system performs self-service by automatically simulating access traversals from user identities to discover horizontal and vertical privilege escalation paths. The simulation engine autonomously explores the cloud environment configuration to identify over-privileged access without external intervention.
2Reliability
If conventional detection solutions focus on vertical privilege escalation, then they can identify some over-privileged access, but they are unable to detect horizontal escalation and resulting vertical escalation threats
Solution Approach 1:
The patent segments the privilege escalation detection into two distinct simulation modes: horizontal escalation simulation (traversing same-privilege resources) and vertical escalation simulation (traversing higher-privilege resources). This segmentation enables comprehensive detection of both escalation types and their interconnected threats.
Solution Approach 2:
The patent adds a dimensional perspective by introducing the concept of privilege levels as a vertical dimension to the traditional horizontal resource traversal. This allows the system to detect not only horizontal escalation but also vertical escalation that may result from compromised horizontal access paths.
3Reliability
If continuous monitoring of privilege escalation is implemented, then detection capability is improved, but resource strain increases due to large volumes of access rights to review
Solution Approach 1:
The patent performs preliminary action by conducting simulation-based discovery of privilege escalation paths before actual threats materialize. The system proactively identifies over-privileged access configurations and enables preventive mitigation, reducing the need for continuous intensive monitoring of all access rights.
Solution Approach 2:
The system implements feedback by continuously monitoring for changes in cloud environment configuration (policies, roles, resources) and re-running simulations only when changes occur. This event-driven approach maintains continuous detection capability while minimizing unnecessary computational resource consumption.
4Measurement precision
If manual methods are used to determine least privilege access, then accuracy can be maintained, but they are not feasible in cloud computing environments with large numbers of users and resources
Solution Approach 1:
The patent replaces manual determination of least privilege with automated simulation that objectively analyzes actual access paths in the cloud environment. The simulation accurately identifies over-privileged access by comparing user access rights against actual traversal paths to sensitive resources, maintaining precision while enabling scalability.
Data Source
AI summary
Systems and methods of identifying over-privileged access in a computing system are disclosed. The method includes receiving configuration information for the computing system, selecting an identity that can access the computing system and determining access privileges for the selected identity using at least the received configuration information, the access privileges identifying one or more computing resource or service accessible to the selected identity, determining at least one role assumable by the identified one or more computing resource or service accessible to the selected identity, and determining whether the identified one or more computing resource or service accessible to the selected identity can elevate its privileges. In a case where it is determined that the identified one or more computing resource or service accessible to the selected identity can elevate its privileges, the method provides notification that the identity has over-privileged access to the computing system.


