Dynamic Multi-Factor Risk Assessment for Virtualized Entity Permissions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern computing systems face significant security risks due to improperly managed permissions, with unused permissions increasing the attack surface and potential damage from malicious attackers, especially in complex virtualized environments like cloud-based systems.

Innovation Solution

A system and method for dynamically generating multi-factor entity risk assessments in virtualized environments, which identify and assess the risk of unused permissions using a composite exposure assessment, allowing for prioritization and recommendation to alter privilege scopes, providing visual representations of the assessment, and enabling entity-specific security management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If permissions are granted to ensure system functionality, then system operation is maintained, but security risk increases due to unused permissions

Engineering Contradiction:
Improvesystem operationVSAvoidsecurity risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic permission management by continuously monitoring permission usage and automatically adjusting permission scopes based on actual needs. The system dynamically generates risk assessments and modifies entity permissions in real-time, transforming static permission assignments into adaptive, context-aware access control that maintains system operation while minimizing security exposure.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of permission scope by generating composite exposure assessments that quantify risk levels. Based on these assessments, the system automatically adjusts permission parameters (scope, duration, privileges) to optimize the balance between system functionality and security risk reduction.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If comprehensive permission monitoring is implemented to identify unused permissions, then security risk assessment improves, but system complexity increases

Engineering Contradiction:
Improvepermission risk assessmentVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a universal permission monitoring framework that serves multiple functions: identifying unused permissions, generating risk assessments, prioritizing security actions, and automatically adjusting permissions. This multi-functional system consolidates complex security management tasks into a unified platform, reducing overall system complexity while improving measurement precision.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs self-service by automatically monitoring permission usage, generating composite exposure assessments, and adjusting permissions without requiring manual intervention. The automated risk assessment engine continuously evaluates permission risks and implements corrective actions, reducing the complexity burden on operators while maintaining high measurement precision.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If dynamic risk assessment is performed for each entity, then security management accuracy improves, but processing time increases

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies partial action by focusing risk assessments on the most critical factors rather than evaluating every possible permission attribute equally. The composite exposure assessment prioritizes key risk indicators and uses weighted scoring to concentrate processing effort on the most significant security concerns, maintaining high accuracy while reducing processing time.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary risk assessments continuously in the background, maintaining up-to-date composite exposure scores for all entities. This preliminary action ensures that when security decisions are needed, the system can quickly retrieve pre-calculated risk assessments rather than performing full evaluations, significantly reducing processing time while maintaining accuracy.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12028366B2Dynamically generating multi-factor entity risk assessments within virtualized environments
Publication Date: 2024.07.02 CYBER ARK SOFTWARE LTD
  • US12028366B2 patent drawing
  • US12028366B2 patent drawing
  • US12028366B2 patent drawing

AI summary

Disclosed embodiments relate to systems and methods for dynamically performing entity-specific security assessments for entities of virtualized network environments. Techniques include identifying an entity associated with a virtualized network environment, identifying a plurality of security factors, determining entity-specific weights to the plurality of security factors, and generating a composite exposure assessment for the entity. Further techniques include selecting at least two security factors of the plurality of security factors, identifying the weights corresponding to the selected security factors, and calculating the composite exposure assessment using the selected security factors and corresponding weights, analyzing the composite exposure assessment, and generating at least one of: a security recommendation based on the analysis to alter a scope of privileges of the entity, a notification providing an indication of the composite exposure assessment, or a visual representation of the composite exposure assessment of the entity.