ML-Based Access Revocation for Application Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems face challenges in accurately predicting and managing user access requirements for applications within organizations, leading to either insufficient or excessive access, which can hinder productivity and pose security risks.
Innovation Solution
A machine learning model is employed to analyze user group information and access history to predict and adjust access permissions, ensuring each user has the minimum necessary access by training on a dataset that includes user associations and access information, and making predictions on required access to application functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If manual assessment of access requirements is used, then implementation simplicity is maintained, but access prediction accuracy deteriorates
Solution Approach 1:
The patent replaces the manual mechanical assessment process with an automated machine learning system. The ML model analyzes user profiles, application requirements, and historical access data to automatically predict and determine appropriate access levels, eliminating the need for manual assessment while significantly improving accuracy.
Solution Approach 2:
The system enables self-service access management by allowing the machine learning model to autonomously evaluate and determine access requirements without human intervention. The model continuously learns from data and automatically adjusts access predictions, making the system self-improving and reducing manual workload.
2Ease of operation
If group membership is used for assigning access, then ease of operation is improved, but access precision deteriorates
Solution Approach 1:
The patent moves from uniform group-based access assignment to individualized access determination. The machine learning model evaluates each user's specific characteristics, role, and context to determine precise access requirements, ensuring that each user receives locally optimized access rights rather than blanket group permissions.
Solution Approach 2:
The system transitions from static group membership parameters to dynamic, multi-factor parameters including user profile attributes, application-specific requirements, historical access patterns, and contextual information. The ML model processes these varied parameters to determine optimal access levels for each user-application pair.
3Productivity
If excessive user access is provided, then user productivity is improved, but security risk increases
Solution Approach 1:
The patent implements dynamic access management where the machine learning model continuously evaluates and adjusts access rights based on current user needs, contextual factors, and security requirements. Access permissions are not static but adapt dynamically to changing conditions, ensuring users have sufficient access for productivity while maintaining security through ongoing evaluation.
Solution Approach 2:
The system incorporates feedback mechanisms where the ML model analyzes user behavior patterns, access utilization data, and security events to continuously improve access predictions. The model learns from feedback about actual user needs and security outcomes, refining its predictions to balance productivity and security optimally.
Data Source
AI summary
Methods and systems are described herein for predicting user access revocation for applications. The system may retrieve, based on user identifiers, user access information and user association information. The system may generate a dataset comprising entries for the user identifiers, where the entries include the user access information and the user association information. The system may input the dataset into a machine learning model to obtain predictions as to whether each user identifier requires access to one or more functions of one or more applications. In some embodiments, the machine learning model is trained to predict required user access. In response to determining that a particular prediction does not include one or more particular functions included in the user access information for a respective user identifier, the system may revoke access to the one or more particular functions from the user identifier.


