Custom Access Policy Generation via Behavioral Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing remote-computing services often employ generic access policies that fail to meet the specific needs of individual users and applications, as administrators lack precise knowledge of the necessary access permissions, leading to ill-suited policies.
Innovation Solution
Implementing a learning-mode system where the access manager tracks interactions of users and applications, crafting custom policies based on their behavior over time, and iteratively refining these policies with administrator feedback to ensure accurate access permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If generic access policies are used for all users and applications, then device complexity and policy management overhead are reduced, but the suitability and precision of access permissions deteriorate
Solution Approach 1:
The patent segments access policies into two categories: generic policies for common scenarios and custom policies for specific users and applications. This segmentation allows the system to maintain simplicity for most cases while providing precision when needed, resolving the contradiction between policy management complexity and access permission precision.
Solution Approach 2:
The system enables self-service by automatically generating custom access policies based on observed user behavior and interactions with resources. This automation eliminates the need for manual policy creation and reduces administrative overhead while providing precise, tailored access permissions, thus resolving the contradiction between policy complexity and permission precision.
2Measurement precision
If administrators manually assign different access policies to different users and applications, then access permission precision is improved, but device complexity and time consumption increase
Solution Approach 1:
The system performs preliminary action by automatically generating custom access policies based on pre-collected behavioral data and interaction patterns. This eliminates the need for time-consuming manual policy creation while maintaining high precision in access permissions, thus resolving the contradiction between permission precision and policy creation time.
Solution Approach 2:
The system implements feedback mechanisms by continuously monitoring user interactions with resources and using this information to automatically refine and update access policies. This automated feedback loop provides precise access permissions without requiring manual administrator intervention, resolving the contradiction between permission precision and time consumption.
3Measurement precision
If custom policies are created for each user and application based on their specific needs, then access permission precision is improved, but device complexity increases
Solution Approach 1:
The system employs self-service automation to generate and manage custom access policies based on observed user behavior. This automation handles the complexity of creating and maintaining individualized policies without increasing manual management overhead, thus resolving the contradiction between access permission precision and policy management complexity.
Solution Approach 2:
The system dynamically adjusts access policy parameters based on changing user behavior patterns and resource interaction data. This automated parameter adjustment provides precise access permissions adapted to specific needs without requiring complex manual policy management, resolving the contradiction between permission precision and management complexity.
Data Source
AI summary
Techniques for crafting custom policies for entities (e.g., users, applications, etc.) based on past behavior of the entities are described herein. In one example, the techniques are implemented in a network-based environment. In this environment, a remote-computing service may include multiple different resources that provide different services to customers of the remote-computing service. For instance, the remote-computing service may provide a network-based storage service, a network-based compute service, a network-based payment service, or any other network-based resource. Users and/or applications of a particular customer may then access these resources via an interface provided by the remote-computing service. After tracking a user or application's access to these resources for a certain period of time, the remote-computing service may recommend or create a custom policy for the user or application based on the requests made by the user or application.


