Automated IAM Privilege Remediation via Configuration Baselines

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing systems face challenges in efficiently managing and verifying configuration compliance, particularly in identifying and remediating excessive privileges of Identity and Access Management (IAM) Roles and Policies, leading to security misconfigurations that can result in data loss and system unavailability.

Innovation Solution

A method and system that utilize a configuration engine to discover resources within a target environment, generate environment definitions, build baseline configurations and policies, and automatically scan for misconfigurations, using machine learning to predict root causes and remediate issues, ensuring compliance and security across multi-layered system architectural models.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual methods are used to verify access control policies, then implementation simplicity is maintained, but security reliability deteriorates due to sporadic checking and human error

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables automated self-verification of access control policies through machine learning models that continuously analyze configurations and identify misconfigurations without human intervention, replacing manual security verification processes

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual mechanical verification processes are replaced with automated computational systems using machine learning algorithms to detect security misconfigurations, transitioning from human-operated to algorithm-driven security verification

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive continuous access control checks are implemented across the entire infrastructure, then security reliability improves, but productivity deteriorates due to the resource-intensive nature of comprehensive scanning

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs comprehensive security checks selectively on critical resources and high-risk configurations rather than uniformly across all infrastructure, applying excessive scrutiny where needed and partial monitoring elsewhere to balance security and performance

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system implements continuous monitoring through periodic sampling and event-triggered scans rather than constant comprehensive analysis, allowing the system to maintain security oversight while periodic operation reduces computational overhead and maintains productivity

Inventive Principle:
Principle #19Periodic action

3Measurement precision

If frequent security scans are performed to detect misconfigurations, then measurement precision improves, but loss of time increases due to the scanning overhead

Engineering Contradiction:
Improvemisconfiguration detection accuracyVSAvoidscanning time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary analysis by establishing baselines of correct configurations and pre-compiling security rules before actual scanning occurs, enabling faster comparison and detection during runtime scans without sacrificing detection precision

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system skips resources that have already been verified as compliant or have low risk profiles, rushing through known-good configurations while performing more thorough analysis on suspicious or changed resources, reducing overall scanning time while maintaining detection accuracy

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS11895121B1Efficient identification and remediation of excessive privileges of identity and access management roles and policies
Publication Date: 2024.02.06 CAPITIS SOLUTIONS INC
  • US11895121B1 patent drawing
  • US11895121B1 patent drawing
  • US11895121B1 patent drawing

AI summary

A method includes executing a configuration engine on one or more data processing device(s) of a computing system. In accordance with the execution, the method also includes discovering at least a subset of a number of resources associated with a target environment of the computing system, generating an environment definition associated with the target environment, building baseline configurations, policies, and metadata for at least the subset of the number of resources, and versioning the aforementioned data. Further, the method includes, in accordance with tracking the metadata versioned in the repository, automatically scanning at least the subset of the number of resources and retrieving a first and/or a second specific configuration based on the scanning, and automatically determining a misconfiguration based on comparing the first specific configuration to a corresponding baseline configuration and/or verifying that a sequence of configurations is correctly defined based on the second specific configuration.