Network Identity Graph Clustering for Outlier Risk Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large organizations face challenges in effectively managing and quantifying access risks in complex, distributed networked computing environments due to decentralized risk management approaches, lack of enterprise-level visibility, and the difficulty in clustering categorical identity and entitlement data, leading to inefficient compliance efforts and increased security risks from insiders.
Innovation Solution
A network graph approach is used to construct a property graph of identities and entitlements, prune weak edges, and cluster them into peer groups using graph-based community detection algorithms, with a feedback loop to optimize clustering based on a peer group assessment metric, allowing for dynamic and domain-specific risk assessment and visualization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If decentralized risk management approaches are used in large organizations, then operational autonomy is maintained, but enterprise-level visibility and risk quantification capability deteriorate
Solution Approach 1:
The patent merges decentralized identity and access management data from multiple sources into a unified enterprise-wide property graph. This graph consolidates identities, entitlements, and relationships across the organization, providing centralized visibility while preserving the decentralized structure of individual systems. The graph-based approach enables enterprise-level risk quantification without requiring centralization of operational control.
2Ease of manufacture
If traditional clustering methods are applied to categorical identity and entitlement data, then data organization is attempted, but computational complexity and clustering accuracy worsen due to the categorical nature of the data
Solution Approach 1:
The patent transforms categorical identity and entitlement data into a graph-based representation where entities become nodes and relationships become edges with weighted attributes. This parameter transformation converts difficult-to-cluster categorical data into a structured format suitable for community detection algorithms, reducing computational complexity while improving clustering accuracy for peer group identification.
3Reliability
If comprehensive access risk assessment is performed across all identities, then security coverage is improved, but computational burden and processing time increase
Solution Approach 1:
The patent segments the enterprise identity space into peer groups using community detection on the property graph. This segmentation divides the comprehensive risk assessment task into smaller, manageable clusters of similar identities. Risk assessment can then be performed efficiently within each peer group rather than across all identities individually, reducing processing time while maintaining comprehensive security coverage through the peer group structure.
Data Source
AI summary
Systems and methods for artificial intelligence systems for identity management systems are disclosed. Embodiments may perform outlier detection and risk assessment based on identity management data, including one or more property graphs or peer groups determined from those property graphs, to determine identity management artifacts with ‘abnormal’ patterns when compared to other related identity management artifacts.


