Self-learning peer group analysis for IAM outlier detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In large enterprises, manual peer group analysis for identity and access management (IAM) is error-prone and fails to accurately predict entitlements due to complex organizational structures, leading to negative outlier accesses and noisy access control configurations.
Innovation Solution
A self-learning peer group analysis (SLPGA) engine that uses machine learning techniques, such as non-negative matrix factorization (NMF), to identify excessive entitlement allocations and perform conditional entropy analysis to automatically define peer groups, thereby identifying outlier entitlements and reducing noise in access control data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual peer group analysis is used for IAM, then administrators can perform access management operations, but the analysis becomes error-prone and fails to accurately predict entitlements due to complex organizational structures
Solution Approach 1:
The patent replaces manual mechanical analysis with automated machine learning algorithms. The system uses unsupervised learning models to automatically analyze user attributes, entitlements, and access patterns, substituting human administrators' manual peer group analysis with computational algorithms that can handle complex organizational structures without human error.
Solution Approach 2:
The system performs self-learning by automatically defining peer groups and identifying outliers without requiring manual configuration. The machine learning model autonomously learns from the data, automatically adjusting parameters and identifying patterns in entitlement allocations, thereby eliminating the need for manual intervention in the analysis process.
2Reliability
If manual peer group analysis is used, then access management can be performed, but noisy access control configurations and negative outlier accesses occur
Solution Approach 1:
The system implements feedback mechanisms where the machine learning model continuously learns from identified outliers and adjusts its analysis. By detecting negative outlier accesses and noisy configurations, the system feeds this information back into the model to refine peer group definitions and improve future entropy calculations, thereby reducing noise and improving reliability over time.
Solution Approach 2:
The patent converts harmful noisy data and negative outlier accesses into beneficial learning opportunities. The machine learning model uses these anomalies as training data to better understand normal versus abnormal patterns, transforming what would be errors into improvements in system accuracy and reliability.
3Extent of automation
If traditional peer group analysis is used, then entitlement management can be performed, but automatic tuning of parameters and accurate identification of outlier entitlements is difficult
Solution Approach 1:
The machine learning model performs self-learning and automatic parameter tuning without requiring manual configuration. The system autonomously learns optimal parameters for entropy calculation and peer group definition by analyzing the data distribution and identifying patterns, thereby achieving high automation while handling parameter complexity internally.
Solution Approach 2:
The system dynamically adjusts parameters based on learned patterns from the data. The machine learning model automatically modifies entropy thresholds, peer group size parameters, and other configuration settings based on the specific characteristics of the organizational data, enabling automatic adaptation to different organizational structures without manual intervention.
Data Source
AI summary
Mechanisms are provided for identifying risky user entitlements in an identity and access management (IAM) computing system. A self-learning peer group analysis (SLPGA) engine receives an IAM data set which specifies user attributes of users of computing resources and entitlements allocated to the users for accessing the computing resources. The SLPGA engine generates a user-entitlement matrix, performs a machine learning matrix decomposition operation on the user-entitlement matrix to identify excessive entitlement allocations, and performs a conditional entropy analysis of the user attributes and entitlements in the IAM data set to identify a set of user attributes for defining peer groups. The SLPGA engine performs a commonality analysis of user attributes and entitlements for each of one or more peer groups defined based on the set of user attributes, and identifies outlier entitlements based on the identification of the excessive entitlement allocations and results of the commonality analysis.


