Genetic Algorithm for Cloud User Account Permission Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing trend of cloud-based applications leads to millions of user accounts with unused and abnormal permissions, making it impractical for IT to manage each account individually, resulting in security risks and poor user experience due to unnecessary churn.
Innovation Solution
An automated system using a genetic algorithm to detect unused and abnormal user accounts by determining anomalous permissions compared to similar users, allowing for the safe removal of unused assignments and ranking of abnormal accounts, enabling IT to focus attention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If IT manages each account individually, then account management precision is improved, but management complexity and time consumption increase significantly
Solution Approach 1:
The system performs self-service by automatically detecting unused and abnormal permissions through genetic algorithms and AI-based anomaly detection, eliminating the need for manual IT review of each account. The system autonomously identifies accounts needing remediation and prioritizes them based on risk assessment.
Solution Approach 2:
The system changes the approach from managing individual accounts to managing permission parameters at scale. By analyzing permission patterns, usage metrics, and anomaly indicators across the entire user base, the system identifies abnormal permissions without examining each account individually, thus reducing complexity while maintaining precision.
2Reliability
If unused accounts are removed to reduce security risks, then security is improved, but user experience deteriorates due to unnecessary churn
Solution Approach 1:
The system uses feedback mechanisms by continuously monitoring account usage patterns, login frequency, and permission consumption. This feedback data feeds into the genetic algorithm and anomaly detection system to dynamically identify truly unused accounts versus those with legitimate intermittent usage, enabling selective remediation that protects security while preserving user experience.
Solution Approach 2:
The system performs preliminary analysis by detecting and ranking abnormal permissions before taking remediation action. The genetic algorithm pre-sorts accounts based on risk indicators and usage patterns, allowing IT to take targeted actions only on accounts that truly pose security risks, thereby avoiding unnecessary churn of active users.
3Measurement precision
If manual account review is performed, then accuracy of permission removal is improved, but time consumption and labor requirements increase
Solution Approach 1:
The system replaces manual mechanical review processes with automated genetic algorithms and AI-based anomaly detection systems. These computational models process large datasets of account usage patterns, permission assignments, and behavioral metrics to automatically identify abnormal permissions with high accuracy, eliminating time-consuming manual audits while maintaining or improving detection accuracy through sophisticated pattern recognition.
4Reliability
If all unused accounts are removed, then security risks are reduced, but legitimate user needs are lost
Solution Approach 1:
The system applies local quality by treating each account and permission differently based on its specific characteristics and usage patterns. Rather than applying a blanket removal policy, the system analyzes individual account behaviors, permission types, and usage contexts to determine which permissions should be removed and which should be retained, preserving legitimate user needs while eliminating security risks.
Data Source
AI summary
Systems and methods include obtaining unused user accounts associated with a cloud application where an unused user account is one where a corresponding user has not accessed the cloud application in a certain period of time; determining a subset of the unused user accounts that are abnormal user accounts, wherein an abnormal user account is one that is anomalous compared to similar users; scoring and ranking the unused and abnormal user accounts; and remediating a set of the ranked unused and abnormal user accounts.


