Principal Access Graph for Network Security Risk

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increased interconnectivity of computing devices poses challenges in maintaining confidentiality and privacy of information, as users face difficulties in managing access rights and privileges across complex network environments, leading to potential security breaches and unnecessary exposure.

Innovation Solution

A system that communicates with principals to collect data on their rights and privileges, generates a graph representing these relationships, and determines paths for access verification, allowing for the identification of potential security risks and permission transitions to reduce exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If computing devices are increasingly interconnected to expand computing technology, then computing capability and connectivity are improved, but information confidentiality and privacy are compromised

Engineering Contradiction:
Improvecomputing capabilityVSAvoidinformation exposure
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by collecting access rights and privilege data before security breaches can occur. It proactively builds a graph representation of the environment and determines potential access paths between principals, enabling preventive security measures rather than reactive responses to breaches.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously monitoring and collecting data about principals' rights and privileges, then using this information to generate updated graphs and identify security risks. This closed-loop approach allows the system to adapt to changing access conditions and provide ongoing security assessment.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If access rights and privileges are managed across complex network environments, then system functionality and connectivity are improved, but security management complexity increases

Engineering Contradiction:
Improvesystem connectivityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments the complex security management task into distinct components: data collection from principals, graph generation to represent relationships, path determination to identify access routes, and risk identification. This segmentation makes the overall security management process more manageable and systematic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary system that acts as a mediator between principals and security analysis. This intermediary collects data from multiple principals, processes it through graph generation and path determination, and presents consolidated security information, thereby simplifying the complexity of managing access rights across the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If data is collected from multiple principals to analyze access paths, then security assessment accuracy is improved, but data collection time and system overhead increase

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoiddata collection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies partial action by collecting data from a selected subset of principals rather than all principals in the environment. The graph generation and path determination processes focus on relevant principals and access paths, avoiding unnecessary data collection and processing that would increase time overhead without improving security assessment accuracy.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10609033B2Principal access determination in an environment
Publication Date: 2020.03.31 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10609033B2 patent drawing
  • US10609033B2 patent drawing
  • US10609033B2 patent drawing

AI summary

An access determination management system obtains information regarding various different entities in a system (e.g., a networked environment) and what rights or privileges those entities have. An entity, also referred to herein as a principal, can be a user, a computing device, a group of users, a group of computing devices, or a service. The rights or privileges that an entity has includes, for example, whether administrative privileges are available to the entity, whether a particular program can be executed, whether an entity is a member of another entity, and so forth. The access determination management system uses the obtained information to generate and display a graph of the environment. The graph of the environment includes the different objects as well as links between the objects that indicate rights or privileges one object has with respect to another.