Dynamic Access Policy Adjustment for System Identities
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Software systems often face security risks due to over-privileged system identities, which can lead to accidental or intentional compromise of secure information, while reducing privileges aggressively can negatively impact productivity and system experience.
Innovation Solution
A method of dynamically adjusting access privileges of system identities by analyzing access logs to generate a restricted access policy, using a continuous monitoring and access management module that collects and analyzes access logs over a defined time period, performs authorization checks, and updates access policies to follow the principle of least privilege, thereby reducing unnecessary access rights.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access privileges of system identities are reduced to follow the principle of least privilege, then security is improved, but system productivity and user experience may be negatively impacted
Solution Approach 1:
The patent implements dynamic access privilege adjustment by continuously monitoring system logs and automatically modifying access policies in real-time. The system transitions from static access control to dynamic adaptation, adjusting privileges based on actual system conditions, threat levels, and user behavior patterns without requiring manual intervention or disrupting productivity.
Solution Approach 2:
The system establishes a feedback loop by continuously collecting system logs, analyzing access patterns, and automatically adjusting access policies based on the analysis results. This closed-loop control enables the system to learn from actual usage and security events, optimizing the balance between security and productivity automatically.
2Object-affected harmful factors
If access privileges are reduced too aggressively, then security risk is minimized, but system functionality and user experience deteriorate
Solution Approach 1:
The system dynamically changes access policy parameters based on analyzed system conditions. Instead of applying fixed restrictive rules, the system adjusts privilege levels, access scopes, and policy constraints as parameters that can be modified in real-time based on actual system state, ensuring optimal balance between security and functionality.
Solution Approach 2:
The system performs preliminary analysis of system logs and access patterns before making policy adjustments. By pre-analyzing usage patterns and identifying legitimate access requirements, the system prepares appropriate access policies in advance that maintain functionality while reducing unnecessary privileges.
3Adaptability or versatility
If manual access policy management is used to balance security and productivity, then flexibility is maintained, but time consumption and operational complexity increase
Solution Approach 1:
The system performs automatic self-service by autonomously analyzing logs, determining appropriate access policies, and implementing adjustments without human intervention. The system serves itself by automatically managing its own access control requirements, eliminating the time-consuming manual policy management process while maintaining flexibility through adaptive decision-making.
Solution Approach 2:
The patent replaces manual mechanical policy management with automated electronic analysis and adjustment systems. Instead of human administrators manually reviewing and adjusting policies, the system uses automated log analysis, pattern recognition, and policy generation algorithms to perform the same function more efficiently and at scale.
Data Source
AI summary
A method of dynamically adjusting access privileges of system identities. A set of access logs associated with a system are analyzed in order to generate a restricted access policy for an over privileged system identity. An initial access policy of the system identity is replaced with the restricted access policy and a continuous monitoring and access management (CMAM) service is initiated. Access logs are collected for a monitoring time window and an access denied error can be extracted from the access logs. The access denied error can be compared to an ignore list and/or the access denied error can be added to the ignore list. Authorization checks can be performed to determine if the action associated with the access denied error is authorized. If the action is authorized, the access policy is adjusted to allow for performance of the action.


