Graph Database Access Risk Assessment for Critical Applications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional identity management solutions fail to effectively assess and manage access risks to critical applications, as they primarily focus on user access rather than the broader relationships between applications, client devices, and users, leaving a gap in governance and security for central security experts.
Innovation Solution
A system and method that collect data on relationships between applications and client devices/users, enriching a graph database with metadata to analyze access patterns, generate security policies, and provide visualizations to identify and restrict unauthorized access, using Role-Based Access Control and Zero Trust principles.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional identity management solutions focus on user access management, then user access control is simplified, but comprehensive security assessment of critical applications is insufficient
Solution Approach 1:
The system segments access management into two distinct views: user-centric management for ease of access control, and application-centric security assessment for comprehensive risk evaluation. This segmentation allows each aspect to be optimized independently while working together to provide both operational simplicity and security reliability.
Solution Approach 2:
The patent introduces an intermediary security assessment system that bridges user access management and application security requirements. This intermediary layer collects data from multiple sources, analyzes access patterns, and generates security assessments without disrupting the simplicity of user access management.
2Productivity
If department administrators manage user access, then access decisions are decentralized and efficient, but security governance for critical applications is weakened
Solution Approach 1:
The system divides security governance responsibilities by introducing application-centric security views that are separate from user access management. Department administrators continue to manage user access efficiently, while security experts gain dedicated tools for assessing and governing critical application security without interfering with operational efficiency.
Solution Approach 2:
An intermediary security assessment layer is introduced that works parallel to user access management. This intermediary system provides security experts with comprehensive visibility and control over critical application security, while department administrators maintain their efficient user access management without additional security governance burden.
3Device complexity
If access management is focused on users, then user access control is simplified, but holistic assessment of application access risks is insufficient
Solution Approach 1:
The patent segments the access management ecosystem into user-facing simplified management and security-facing comprehensive assessment. The user-facing side maintains low complexity for ease of use, while the security-facing side introduces comprehensive data collection and analysis capabilities for precise risk assessment.
Solution Approach 2:
The system adds a new dimension to access management by introducing application-centric security views and multi-source data integration. This additional dimension enables holistic risk assessment without increasing the complexity of traditional user access management, as the two operate in different dimensional spaces.
Data Source
AI summary
Systems and methods for assessing an application access risk are provided. An example method commences with collecting data concerning relationships between an application, one or more client devices, and one or more users in a computing environment. The method includes updating a graph database including nodes and edges. The nodes represent the application, the one or more client devices, and the one or more users and the edges represent relationships between the application, the one or more client devices, and the one or more users. The method continues with enriching the graph database by associating the nodes with metadata including information concerning the one or more users accessing the application from the one or more client devices. The method further includes analyzing the graph database to identify a subset of nodes used to access the application and displaying a graphical representation of the subset of nodes.


