EDR-Based Access Manager for Dynamic Privilege Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems are vulnerable to credential-based attacks due to persistent account access, leading to increased security breaches and compliance issues, as rotating passwords with shared accounts do not adequately address audit and data-leakage problems.

Innovation Solution

A computerized system utilizing an Endpoint Detection and Response (EDR) system, where an access manager server connected to target computer systems via EDR agents implements dynamic privilege management, allowing for just-in-time access and revocation of privileges, leveraging EDR APIs for real-time monitoring and response to cyber threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If persistent account access is maintained for system operations, then ease of operation is improved, but security vulnerability increases due to credential-based attacks

Engineering Contradiction:
Improveaccount access convenienceVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic privilege management where account access rights are not static but change over time. The system automatically revokes privileges after tasks are completed and provides just-in-time access when needed, making the access state dynamic rather than persistent. This resolves the contradiction by maintaining ease of operation through automated management while reducing security vulnerability through time-limited access.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary actions by pre-configuring privilege management policies and automatically granting access rights before tasks are executed. The access manager server is set up in advance to monitor task completion and automatically revoke privileges, eliminating the need for manual account management while ensuring security. This preliminary configuration enables both operational convenience and security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If rotating passwords with shared accounts are used for protection, then security is improved, but audit and compliance problems worsen

Engineering Contradiction:
Improvesecurity protectionVSAvoidaudit trail integrity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments account access by creating individual user accounts with specific task-based privileges rather than using shared accounts. Each user has their own credentials and audit trail, eliminating the audit problems associated with shared accounts while maintaining security through controlled access. The segmentation of privileges by task and user ensures both security and audit compliance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access manager server implements continuous monitoring and feedback mechanisms that track account usage, task completion, and privilege granting in real-time. This feedback system automatically updates access rights based on monitored conditions and maintains comprehensive audit logs, providing both security protection and complete audit trails simultaneously.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If real-time monitoring and response capabilities are implemented, then breach detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvebreach detection capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The access manager server acts as an intermediary between the EDR system and target computer systems, centralizing the real-time monitoring and privilege management functions. This intermediary approach simplifies the overall system architecture by consolidating complex monitoring and response logic in a single component rather than distributing it across multiple systems, reducing overall complexity while maintaining detection capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12003545B2System account access manager utilizing an endpoint detection and response system
Publication Date: 2024.06.04 NETWRIX CORP
  • US12003545B2 patent drawing
  • US12003545B2 patent drawing
  • US12003545B2 patent drawing

AI summary

In one aspect, a computerized system includes an access manager server connected to one or more target computer systems. The access manager server is connected to the one or more target computer systems via an Endpoint Detection and Response (EDR) system. The EDR system continually monitors one or more target computer systems (e.g. endpoints) and responds to mitigate a cyber threat to the one or more target computer systems. The EDR system includes an EDR control plane that manages and communicates with one or more EDR agents. The EDR control plane causes a specific computer security action in the one or more target computer systems via one or more EDR agents. One or more EDR agents are installed in the one or more target computer systems. The one or more EDR agents are made available via the EDR API.