ML-Based Toxic Access Combination Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting toxic access combinations in organizational systems are prone to human error and oversight, especially as technology infrastructures become more complex, making it difficult to identify and manage customized access controls and potential fraudulent activities.
Innovation Solution
A system utilizing machine learning (ML) and natural language processing (NLP) models to process access control descriptions, determine duty groups, and identify toxic combinations by analyzing database relationships, thereby automating the detection of toxic access permissions across multiple applications and business processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual auditing methods are used to detect toxic access combinations, then human understanding and analysis can be applied, but the system becomes increasingly susceptible to human error and oversight as technology infrastructures scale and become more complex
Solution Approach 1:
The patent replaces manual auditing processes with an automated machine learning-based system. The ML model processes access control descriptions, identifies duty groups, and detects toxic combinations automatically, eliminating human error and oversight that occur in manual auditing, especially as system complexity increases
Solution Approach 2:
The system performs self-service by automatically analyzing its own access control structures without requiring external human auditors. The ML model independently processes access control descriptions, identifies patterns, and detects toxic combinations, enabling the system to audit itself continuously
2Reliability
If automated machine learning systems are implemented to detect toxic access combinations, then detection accuracy and consistency improve, but the initial system complexity and processing requirements increase
Solution Approach 1:
The patent segments the access control analysis process into distinct components: processing access control descriptions to identify duty groups, associating permissions with duty groups, and determining toxic combinations. This segmentation allows the complex ML system to handle complexity systematically through modular processing stages
Solution Approach 2:
The patent introduces duty groups as an intermediary concept between access control descriptions and toxic combination detection. The ML model first processes descriptions to identify duty groups, then uses these groups to determine toxic combinations, simplifying the overall detection process through this intermediate representation
3Quantity of substance
If comprehensive access control descriptions are processed to identify all possible toxic combinations, then detection completeness improves, but processing time and computational resources increase
Solution Approach 1:
The patent applies partial action by processing access control descriptions to identify duty groups and toxic combinations only where necessary, rather than exhaustively analyzing every possible combination. The ML model processes descriptions selectively to extract relevant duty group information, reducing processing time while maintaining comprehensive coverage of actual toxic patterns
Data Source
AI summary
In some aspects, the techniques described herein relate to a method including: storing, in an application management database, an audit group, wherein the audit group identifies one or more computer applications; querying the application management database, wherein the querying returns a plurality of access control descriptions from the application management database; processing keywords from the plurality of access control descriptions with a machine learning (ML) model to determine a plurality of duty groups; associating access control permissions with the plurality of duty groups based on the keywords; and determining toxic combinations of the access control permissions based on database relationships between the plurality of duty groups, the audit group, and a user identifier.


