Machine-Learned Resource Access Rules for Precise Security Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access permission systems in computing systems lack precision, leading to either overly restrictive or overly permissive access, which consumes significant computing resources and fails to effectively prevent malicious activities such as exfiltration of sensitive information.
Innovation Solution
A system that uses machine learning to dynamically determine and update access rules based on user and resource characteristics, monitoring user activity to generate or update access rules in real-time, and prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional access permission systems are used, then access control is implemented, but the precision of access control is low leading to overly restrictive or permissive rules
Solution Approach 1:
The patent implements dynamic access rules that automatically adjust based on real-time user behavior patterns, resource sensitivity levels, and contextual factors. The system continuously learns from user interactions and modifies access permissions without manual intervention, transforming static access control into an adaptive, living system that evolves with organizational needs.
Solution Approach 2:
The system changes multiple parameters simultaneously including user behavior metrics, resource sensitivity classifications, temporal patterns, and contextual conditions to determine access decisions. By monitoring and adjusting these parameters dynamically, the system achieves precise access control while maintaining flexibility in response to changing conditions.
2Reliability
If traditional access permission systems are used, then access control is implemented, but computing resources are consumed significantly
Solution Approach 1:
The system performs preliminary analysis of user behavior patterns, resource sensitivity, and access contexts before making access decisions. By pre-establishing baseline behaviors and sensitivity classifications, the system avoids computationally expensive real-time analysis for every access request, reducing overall resource consumption while maintaining high security effectiveness.
Solution Approach 2:
The access control system serves itself by automatically learning from user behaviors and adjusting permissions without requiring manual security administration. This self-service capability reduces the computational overhead of centralized security management and enables the system to optimize its own resource usage patterns over time.
3Object-affected harmful factors
If traditional access permission systems are used, then access control is implemented, but malicious activities are not effectively prevented
Solution Approach 1:
The system implements continuous feedback loops where access decisions, user behaviors, and security events are constantly monitored and fed back into the machine learning models. This real-time feedback enables the system to detect anomalous patterns indicating malicious activities and automatically adjust access rules to prevent further harm, reducing the time required for manual monitoring and remediation.
Solution Approach 2:
The system takes preliminary anti-actions by proactively identifying potential security threats through behavior analysis and preventing malicious activities before they can cause significant damage. By detecting unusual patterns early and automatically responding with appropriate access restrictions, the system neutralizes threats before they escalate, minimizing both harm and response time.
Data Source
AI summary
In some implementations, a device may monitor user activity in a computing system. The device may detect, based on monitoring the user activity, modification of a resource of the computing system by a user. The device may determine, using a machine learning model and based on detecting the modification of the resource, a set of access rules for the resource based on one or more characteristics associated with the user and one or more characteristics associated with the resource. The device may control access to the resource based on the set of access rules.


