Graph Analysis for Identifying Unauthorized Access Risks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Identifying and addressing unauthorized access to secure data assets within organizational networks is a time-consuming and error-prone process, as users' access permissions often change with job roles or departures, leading to potential data breaches.
Innovation Solution
A system and method utilizing a graph data structure to visualize user connections across security groups, where users and their connections are represented as nodes and edges, allowing system administrators to identify potential security risks by clustering users and calculating betweenness centrality to highlight users with unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual management of user access permissions is used, then flexibility in assigning permissions is maintained, but the process becomes time-consuming and error-prone
Solution Approach 1:
The patent replaces manual mechanical review processes with automated computer-based graph analysis. The system automatically generates visual representations of user connections and calculates betweenness centrality metrics to identify potential unauthorized access, eliminating the need for time-consuming manual inspection of access logs and user records.
Solution Approach 2:
The system enables self-identification of security risks through automated analysis. By calculating betweenness centrality and generating visual graphs, the system allows security teams to automatically detect users with potential unauthorized access without requiring external assistance or complex manual investigations.
2Measurement precision
If comprehensive user connection analysis is performed, then accuracy in identifying security risks is improved, but system complexity increases
Solution Approach 1:
The patent replaces complex manual analysis methods with automated graph theory-based algorithms. By using betweenness centrality calculations and visual graph representations, the system achieves high precision in identifying security risks while reducing operational complexity, as the automated system handles the computational burden.
Solution Approach 2:
The system transforms complex user relationship data into visual graph parameters where nodes represent users and edges represent connections. By changing the representation parameters to graphical form and using betweenness centrality metrics, the system simplifies the analysis of complex security relationships while maintaining high identification accuracy.
3Ease of operation
If visual graph representation of user connections is implemented, then ease of identifying security risks is improved, but data processing complexity increases
Solution Approach 1:
The patent replaces manual creation of visual connection diagrams with automated computer-generated graphs. The system automatically processes user data, calculates relationships, and generates visual representations using graph theory algorithms, eliminating the need for manual diagramming while providing clear visual insights into user connections and potential security risks.
Data Source
AI summary
Methods, systems, apparatus, and non-transitory computer readable media are described for identifying users who are likely to have unauthorized access to secure data files in an organizational network. Various aspects may include presenting the identified users on a display for a system administrator and/or security analyst to resolve. For example, the display may include a graph data structure with users represented as nodes and connections between users represented as edges. Each connection may be a pair of users belonging to the same security group. Nodes of the graph data structure may be clustered to indicate that each of the users in the cluster belong to the same security group. Moreover, the users who are connected to multiple clusters may be identified as a potential risk of having unauthorized access to secure data files. The authorized access may then be remedied or taken away.


