EDR-Based Access Manager for Dynamic Privilege Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems are vulnerable to credential-based attacks due to persistent account access, leading to increased security breaches and compliance issues, as rotating passwords with shared accounts do not adequately address audit and data-leakage problems.
Innovation Solution
A computerized system utilizing an Endpoint Detection and Response (EDR) system, where an access manager server connected to target computer systems via EDR agents implements dynamic privilege management, allowing for just-in-time access and revocation of privileges, leveraging EDR APIs for real-time monitoring and response to cyber threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If persistent account access is maintained for system operations, then ease of operation is improved, but security vulnerability increases due to credential-based attacks
Solution Approach 1:
The patent implements dynamic privilege management where account access rights are not static but change over time. The system automatically revokes privileges after tasks are completed and provides just-in-time access when needed, making the access state dynamic rather than persistent. This resolves the contradiction by maintaining ease of operation through automated management while reducing security vulnerability through time-limited access.
Solution Approach 2:
The system performs preliminary actions by pre-configuring privilege management policies and automatically granting access rights before tasks are executed. The access manager server is set up in advance to monitor task completion and automatically revoke privileges, eliminating the need for manual account management while ensuring security. This preliminary configuration enables both operational convenience and security.
2Reliability
If rotating passwords with shared accounts are used for protection, then security is improved, but audit and compliance problems worsen
Solution Approach 1:
The patent segments account access by creating individual user accounts with specific task-based privileges rather than using shared accounts. Each user has their own credentials and audit trail, eliminating the audit problems associated with shared accounts while maintaining security through controlled access. The segmentation of privileges by task and user ensures both security and audit compliance.
Solution Approach 2:
The access manager server implements continuous monitoring and feedback mechanisms that track account usage, task completion, and privilege granting in real-time. This feedback system automatically updates access rights based on monitored conditions and maintains comprehensive audit logs, providing both security protection and complete audit trails simultaneously.
3Measurement precision
If real-time monitoring and response capabilities are implemented, then breach detection capability is improved, but system complexity increases
Solution Approach 1:
The access manager server acts as an intermediary between the EDR system and target computer systems, centralizing the real-time monitoring and privilege management functions. This intermediary approach simplifies the overall system architecture by consolidating complex monitoring and response logic in a single component rather than distributing it across multiple systems, reducing overall complexity while maintaining detection capability.
Data Source
AI summary
In one aspect, a computerized system includes an access manager server connected to one or more target computer systems. The access manager server is connected to the one or more target computer systems via an Endpoint Detection and Response (EDR) system. The EDR system continually monitors one or more target computer systems (e.g. endpoints) and responds to mitigate a cyber threat to the one or more target computer systems. The EDR system includes an EDR control plane that manages and communicates with one or more EDR agents. The EDR control plane causes a specific computer security action in the one or more target computer systems via one or more EDR agents. One or more EDR agents are installed in the one or more target computer systems. The one or more EDR agents are made available via the EDR API.


