Context-Based Security Profiles for Dynamic Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security techniques for dynamically changing software-based systems are inadequate in providing comprehensive security, as they focus on discrete controls and fail to protect against unknown or unappreciated security vulnerabilities, leading to 'security islands' that cannot effectively adapt to complex and evolving network environments.

Innovation Solution

The implementation of context-based analysis methods that build dynamic context profiles based on static and dynamic parameters of processes, allowing for the identification of anomalous or suspicious activities by matching current runtime activity against these profiles, and performing control actions to prevent potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If discrete security controls (firewalls, whitelists) are implemented to protect specific software flows, then security coverage for known processes is improved, but the system creates security islands that cannot protect against unknown vulnerabilities and fails to provide comprehensive end-to-end security

Engineering Contradiction:
Improvesecurity coverageVSAvoidcomprehensive security coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent merges discrete security controls into a unified end-to-end process security system. Instead of isolated firewalls and whitelists protecting individual components, the system creates comprehensive context profiles that span entire process flows from start to finish, integrating security controls across all layers and components of the software system to eliminate security islands.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements universal security monitoring that can protect against both known and unknown threats across diverse process types. The context-based analysis framework is designed to be applicable to any software process, whether monolithic or microservices-based, providing adaptable security coverage that automatically adjusts to different process contexts and threat scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of manufacture

If static security policies are used to control software processes, then implementation simplicity is improved, but the system cannot adapt to dynamically changing software environments and evolving threats

Engineering Contradiction:
Improveimplementation simplicityVSAvoidadaptability to dynamic environments
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security policies that automatically adapt to changing software environments. Context profiles are built and updated in real-time based on observed process behavior, allowing the security system to evolve with the software lifecycle. The system continuously learns from process executions and adjusts security controls accordingly, maintaining both simplicity through automation and adaptability to dynamic conditions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates continuous feedback loops where security monitoring data from runtime process execution feeds back into context profile updates. This feedback mechanism enables the system to learn from actual process behavior patterns and automatically refine security policies, balancing implementation simplicity with adaptive response to emerging threats and changing environments.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If piecemeal security controls are applied to individual process components, then ease of implementation is improved, but the system fails to identify and protect the weakest links in end-to-end process flows

Engineering Contradiction:
Improveease of implementationVSAvoidability to identify weakest links
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments process flows into discrete context units that can be individually analyzed and protected. By breaking down end-to-end processes into manageable context profiles with specific start and end points, the system maintains ease of implementation through modular analysis while simultaneously enabling comprehensive identification of weak links across the entire process chain through systematic context matching.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary analysis to build context profiles before security evaluation occurs. By pre-establishing expected process contexts and identifying potential weak links in advance, the system simplifies runtime security operations while ensuring comprehensive protection. The preliminary context building phase enables the system to quickly identify and respond to deviations that indicate security vulnerabilities.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3660717B1Dynamic authorization of requested actions using adaptive context-based matching
Publication Date: 2021.07.07 CYBER ARK SOFTWARE LTD
  • EP3660717B1 patent drawingFigure 1
  • EP3660717B1 patent drawingFigure 2
  • EP3660717B1 patent drawingFigure 3

AI summary

Disclosed embodiments relate to context-based analysis of requested activities. Techniques include building dynamic context profiles for processes based on static parameters of the processes, dynamic parameters of the processes, and detected activity involving the processes; receiving an indication of current runtime activity involving at least one identity; matching the indication of current runtime activity to a dynamic context profile; determining a context-based probability that the current runtime activity is anomalous, suspicious, or non-valid with respect to the dynamic context profile; and performing a control action in association with either the current runtime activity or the process based on whether the current runtime activity is determined to be anomalous, suspicious, or non-valid.