Cloud Security Risk Scoring for Stale Access Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing user access and security vulnerabilities in cloud platform deployments, particularly in hybrid cloud environments, is challenging due to the complexity of landscape components and user access levels, which can lead to security breaches from users with excessive or outdated access rights.
Innovation Solution
A service-based solution that generates a total risk score for an application instance using landscape, access frequency, last access, and tenant incident services, triggering corrective actions when the score exceeds a threshold, including sending alerts and executing automated security tests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cloud platform deployments use multiple landscape components and services to provide functionality, then the versatility and capability of the system is improved, but the complexity of managing user access and security increases
Solution Approach 1:
The patent segments the security management function into separate services: a first service that determines access frequencies and generates access frequency scores, and a second service that determines last access times and generates last access scores. This segmentation allows each service to specialize in specific security assessment tasks, reducing the overall management complexity while maintaining comprehensive security coverage across multiple landscape components.
Solution Approach 2:
The patent implements a universal risk score calculation mechanism that aggregates multiple security metrics (access frequency score, last access score, and other security-related scores) into a single total risk score. This multi-functional approach allows the system to assess security risks across diverse landscape components and user access patterns through a unified framework, simplifying management while maintaining versatility.
2Reliability
If the system monitors multiple security parameters and generates comprehensive risk scores, then the reliability of security detection is improved, but the computational resources and processing time increase
Solution Approach 1:
The patent applies partial action by calculating risk scores based on specific security parameters (access frequency, last access time) rather than monitoring all possible system parameters. The system selectively monitors only the security-relevant metrics that contribute to the risk assessment, achieving reliable security detection without the computational overhead of comprehensive system monitoring.
Solution Approach 2:
The system performs self-service security assessment by automatically generating risk scores and identifying high-risk users without requiring external intervention. The automated calculation of access frequency scores, last access scores, and total risk scores reduces the need for manual security audits and computational resource consumption while maintaining high reliability in security detection.
3Productivity
If the system implements automated security tests and alerting when risk thresholds are exceeded, then the productivity of security response is improved, but the device complexity and infrastructure requirements increase
Solution Approach 1:
The patent implements feedback mechanisms where the system automatically responds to security risks based on pre-defined thresholds. When the total risk score exceeds a threshold, the system triggers automated security tests and sends alert messages to administrative users. This feedback loop enhances security response productivity by eliminating manual monitoring and response delays, while the automated nature of the system reduces infrastructure complexity compared to manual security management.
Data Source
AI summary
Various examples are directed to systems and a method for managing security at a public cloud platform deployment. A landscape service may determine a landscape score for an application instance executing at the public cloud platform deployment. An access frequency service may determine an access frequency score for the application instance. A last access service may determine a last access score for the application instance. The public cloud platform deployment may determine a total risk score for the application instance using the landscape score for the application instance, the access frequency score for the application instance, and the last access score for the application instance. Responsive to determining that the total risk score for the application instance is greater than a threshold value, an alert message may be sent to an administrative user account for the public cloud platform deployment.


