Dynamic Security Friction for Atypical Access Requests
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security systems fail to effectively manage access rights, leading to increased security risks as users accumulate unnecessary access permissions, which can be exploited by malicious entities, especially when access is not regularly reviewed or revoked.
Innovation Solution
Implementing a system that introduces security friction for atypical resource access requests by varying the level of authentication methods based on the degree of atypicality, using factors like elapsed time between requests, to deter unauthorized access and enhance detection of malicious activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If access rights are granted to individuals for job functions, then productivity and ease of operation are improved, but security risks increase as users accumulate unnecessary access permissions over time
Solution Approach 1:
The system dynamically adjusts access control based on current context rather than using static permissions. It evaluates the user's current job responsibilities, location, time, and device to determine appropriate access rights in real-time, allowing the same user to have different effective permissions at different times without requiring manual re-provisioning
Solution Approach 2:
The system continuously monitors and evaluates access requests against current organizational data, user profiles, and security policies. It provides real-time feedback by granting or denying access based on whether the request aligns with the user's current job functions and organizational security requirements
2Object-affected harmful factors
If IT personnel re-provision access rights periodically, then security risks are reduced, but productivity and ease of operation deteriorate due to access restrictions and re-provisioning overhead
Solution Approach 1:
The system automatically manages access rights without requiring manual IT intervention. It self-adjusts permissions based on organizational changes, project completions, and role transitions by continuously evaluating access requests against current user profiles and job responsibilities, eliminating the need for periodic re-provisioning cycles
3Object-affected harmful factors
If strict access control is implemented for sensitive resources, then security risk is reduced, but ease of operation deteriorates due to additional authentication requirements
Solution Approach 1:
The system implements dynamic authentication that adapts to the specific context of each access request. It evaluates factors such as user location, time of day, device security state, and requested resource sensitivity to determine the appropriate level of authentication required, applying stricter controls only when necessary rather than uniformly to all access attempts
Data Source
AI summary
A method, system and computer-usable medium for providing security friction to a request for access to a resource based on whether the access request is atypical. In certain embodiments, a request to access the resource based on a user identity is received electronically. The system determines whether the request is typical or atypical. If the request is typical, access to the requested resource is granted. However, if the request is atypical, access to the requested resource is only allowed if the correct information is provided in response to one or more access control methods that provide an amount of security friction that would otherwise not have been asserted if the resource request was typical. In certain embodiments, an elapsed time between access requests based on the user identity is used to determine whether the access request is atypical.


