Genetic Algorithm for Cloud User Account Permission Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing trend of cloud-based applications leads to millions of user accounts with unused and abnormal permissions, making it impractical for IT to manage each account individually, resulting in security risks and poor user experience due to unnecessary churn.

Innovation Solution

An automated system using a genetic algorithm to detect unused and abnormal user accounts by determining anomalous permissions compared to similar users, allowing for the safe removal of unused assignments and ranking of abnormal accounts, enabling IT to focus attention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If IT manages each account individually, then account management precision is improved, but management complexity and time consumption increase significantly

Engineering Contradiction:
Improveaccount management precisionVSAvoidmanagement complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs self-service by automatically detecting unused and abnormal permissions through genetic algorithms and AI-based anomaly detection, eliminating the need for manual IT review of each account. The system autonomously identifies accounts needing remediation and prioritizes them based on risk assessment.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the approach from managing individual accounts to managing permission parameters at scale. By analyzing permission patterns, usage metrics, and anomaly indicators across the entire user base, the system identifies abnormal permissions without examining each account individually, thus reducing complexity while maintaining precision.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If unused accounts are removed to reduce security risks, then security is improved, but user experience deteriorates due to unnecessary churn

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system uses feedback mechanisms by continuously monitoring account usage patterns, login frequency, and permission consumption. This feedback data feeds into the genetic algorithm and anomaly detection system to dynamically identify truly unused accounts versus those with legitimate intermittent usage, enabling selective remediation that protects security while preserving user experience.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary analysis by detecting and ranking abnormal permissions before taking remediation action. The genetic algorithm pre-sorts accounts based on risk indicators and usage patterns, allowing IT to take targeted actions only on accounts that truly pose security risks, thereby avoiding unnecessary churn of active users.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If manual account review is performed, then accuracy of permission removal is improved, but time consumption and labor requirements increase

Engineering Contradiction:
Improveaccuracy of permission removalVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system replaces manual mechanical review processes with automated genetic algorithms and AI-based anomaly detection systems. These computational models process large datasets of account usage patterns, permission assignments, and behavioral metrics to automatically identify abnormal permissions with high accuracy, eliminating time-consuming manual audits while maintaining or improving detection accuracy through sophisticated pattern recognition.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If all unused accounts are removed, then security risks are reduced, but legitimate user needs are lost

Engineering Contradiction:
ImprovesecurityVSAvoidlegitimate user needs
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system applies local quality by treating each account and permission differently based on its specific characteristics and usage patterns. Rather than applying a blanket removal policy, the system analyzes individual account behaviors, permission types, and usage contexts to determine which permissions should be removed and which should be retained, preserving legitimate user needs while eliminating security risks.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11785033B2Detecting unused, abnormal permissions of users for cloud-based applications using a genetic algorithm
Publication Date: 2023.10.10 ZSCALER INC
  • US11785033B2 patent drawing
  • US11785033B2 patent drawing
  • US11785033B2 patent drawing

AI summary

Systems and methods include obtaining unused user accounts associated with a cloud application where an unused user account is one where a corresponding user has not accessed the cloud application in a certain period of time; determining a subset of the unused user accounts that are abnormal user accounts, wherein an abnormal user account is one that is anomalous compared to similar users; scoring and ranking the unused and abnormal user accounts; and remediating a set of the ranked unused and abnormal user accounts.