Self-learning peer group analysis for IAM outlier detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large enterprises, manual peer group analysis for identity and access management (IAM) is error-prone and fails to accurately predict entitlements due to complex organizational structures, leading to negative outlier accesses and noisy access control configurations.

Innovation Solution

A self-learning peer group analysis (SLPGA) engine that uses machine learning techniques, such as non-negative matrix factorization (NMF), to identify excessive entitlement allocations and perform conditional entropy analysis to automatically define peer groups, thereby identifying outlier entitlements and reducing noise in access control data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual peer group analysis is used for IAM, then administrators can perform access management operations, but the analysis becomes error-prone and fails to accurately predict entitlements due to complex organizational structures

Engineering Contradiction:
Improveaccuracy of entitlement predictionVSAvoidcomplexity of organizational structure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces manual mechanical analysis with automated machine learning algorithms. The system uses unsupervised learning models to automatically analyze user attributes, entitlements, and access patterns, substituting human administrators' manual peer group analysis with computational algorithms that can handle complex organizational structures without human error.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs self-learning by automatically defining peer groups and identifying outliers without requiring manual configuration. The machine learning model autonomously learns from the data, automatically adjusting parameters and identifying patterns in entitlement allocations, thereby eliminating the need for manual intervention in the analysis process.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual peer group analysis is used, then access management can be performed, but noisy access control configurations and negative outlier accesses occur

Engineering Contradiction:
Improvereliability of access control configurationVSAvoidnoise in access control data
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The system implements feedback mechanisms where the machine learning model continuously learns from identified outliers and adjusts its analysis. By detecting negative outlier accesses and noisy configurations, the system feeds this information back into the model to refine peer group definitions and improve future entropy calculations, thereby reducing noise and improving reliability over time.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent converts harmful noisy data and negative outlier accesses into beneficial learning opportunities. The machine learning model uses these anomalies as training data to better understand normal versus abnormal patterns, transforming what would be errors into improvements in system accuracy and reliability.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Extent of automation

If traditional peer group analysis is used, then entitlement management can be performed, but automatic tuning of parameters and accurate identification of outlier entitlements is difficult

Engineering Contradiction:
Improveautomatic parameter tuningVSAvoidcomplexity of parameter optimization
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The machine learning model performs self-learning and automatic parameter tuning without requiring manual configuration. The system autonomously learns optimal parameters for entropy calculation and peer group definition by analyzing the data distribution and identifying patterns, thereby achieving high automation while handling parameter complexity internally.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically adjusts parameters based on learned patterns from the data. The machine learning model automatically modifies entropy thresholds, peer group size parameters, and other configuration settings based on the specific characteristics of the organizational data, enabling automatic adaptation to different organizational structures without manual intervention.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11416771B2Self-learning peer group analysis for optimizing identity and access management environments
Publication Date: 2022.08.16 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11416771B2 patent drawing
  • US11416771B2 patent drawing
  • US11416771B2 patent drawing

AI summary

Mechanisms are provided for identifying risky user entitlements in an identity and access management (IAM) computing system. A self-learning peer group analysis (SLPGA) engine receives an IAM data set which specifies user attributes of users of computing resources and entitlements allocated to the users for accessing the computing resources. The SLPGA engine generates a user-entitlement matrix, performs a machine learning matrix decomposition operation on the user-entitlement matrix to identify excessive entitlement allocations, and performs a conditional entropy analysis of the user attributes and entitlements in the IAM data set to identify a set of user attributes for defining peer groups. The SLPGA engine performs a commonality analysis of user attributes and entitlements for each of one or more peer groups defined based on the set of user attributes, and identifies outlier entitlements based on the identification of the excessive entitlement allocations and results of the commonality analysis.