Principal Access Graph for Network Security Risk
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increased interconnectivity of computing devices poses challenges in maintaining confidentiality and privacy of information, as users face difficulties in managing access rights and privileges across complex network environments, leading to potential security breaches and unnecessary exposure.
Innovation Solution
A system that communicates with principals to collect data on their rights and privileges, generates a graph representing these relationships, and determines paths for access verification, allowing for the identification of potential security risks and permission transitions to reduce exposure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If computing devices are increasingly interconnected to expand computing technology, then computing capability and connectivity are improved, but information confidentiality and privacy are compromised
Solution Approach 1:
The system performs preliminary actions by collecting access rights and privilege data before security breaches can occur. It proactively builds a graph representation of the environment and determines potential access paths between principals, enabling preventive security measures rather than reactive responses to breaches.
Solution Approach 2:
The system implements feedback by continuously monitoring and collecting data about principals' rights and privileges, then using this information to generate updated graphs and identify security risks. This closed-loop approach allows the system to adapt to changing access conditions and provide ongoing security assessment.
2Adaptability or versatility
If access rights and privileges are managed across complex network environments, then system functionality and connectivity are improved, but security management complexity increases
Solution Approach 1:
The system segments the complex security management task into distinct components: data collection from principals, graph generation to represent relationships, path determination to identify access routes, and risk identification. This segmentation makes the overall security management process more manageable and systematic.
Solution Approach 2:
The patent introduces an intermediary system that acts as a mediator between principals and security analysis. This intermediary collects data from multiple principals, processes it through graph generation and path determination, and presents consolidated security information, thereby simplifying the complexity of managing access rights across the network.
3Measurement precision
If data is collected from multiple principals to analyze access paths, then security assessment accuracy is improved, but data collection time and system overhead increase
Solution Approach 1:
The system applies partial action by collecting data from a selected subset of principals rather than all principals in the environment. The graph generation and path determination processes focus on relevant principals and access paths, avoiding unnecessary data collection and processing that would increase time overhead without improving security assessment accuracy.
Data Source
AI summary
An access determination management system obtains information regarding various different entities in a system (e.g., a networked environment) and what rights or privileges those entities have. An entity, also referred to herein as a principal, can be a user, a computing device, a group of users, a group of computing devices, or a service. The rights or privileges that an entity has includes, for example, whether administrative privileges are available to the entity, whether a particular program can be executed, whether an entity is a member of another entity, and so forth. The access determination management system uses the obtained information to generate and display a graph of the environment. The graph of the environment includes the different objects as well as links between the objects that indicate rights or privileges one object has with respect to another.


