Privileged Access Session Inconsistency Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current ticketing systems lack an efficient method to detect inconsistencies between requested and actual activities during privileged sessions, leading to time- and resource-intensive manual reviews that often miss suspicious activity or incorrectly label benign actions as malicious.
Innovation Solution
A system that automatically analyzes actual activities during connection sessions, compares them to requested activities, and performs remediation operations such as alerting, controlling, or restricting access when inconsistencies are detected, using a non-transitory computer readable medium with instructions to identify requests for access, establish connection sessions, and perform remediation based on detected inconsistencies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual review of audit data is performed to detect inconsistencies, then detection capability is improved, but time consumption and resource requirements increase significantly
Solution Approach 1:
The patent replaces manual mechanical review processes with automated computer-based analysis systems. The system automatically collects audit data, compares it against ticket requirements, and generates inconsistency reports without human intervention, thereby maintaining detection capability while eliminating time consumption associated with manual review.
Solution Approach 2:
The system enables self-service by automatically performing the inconsistency detection function that previously required manual analyst intervention. The automated system serves itself by collecting data, analyzing it, and generating reports without requiring external human resources, thus resolving the contradiction between detection quality and time investment.
2Productivity
If manual review techniques are used to analyze sessions, then resource requirements are reduced, but detection accuracy deteriorates due to human error and fatigue
Solution Approach 1:
The patent substitutes human analysts with automated computational systems that perform inconsistency detection. This replacement eliminates human errors and fatigue while maintaining resource efficiency, as the automated system can process multiple sessions simultaneously without additional resource costs.
Solution Approach 2:
The system introduces an automated analysis intermediary between the audit data and the detection outcome. This intermediary systematically processes data through defined algorithms, ensuring consistent and accurate detection without the variability inherent in manual human review, thereby improving detection accuracy while maintaining resource efficiency.
3Reliability
If comprehensive manual analysis is performed on all sessions, then detection thoroughness is improved, but system complexity and operational difficulty increase
Solution Approach 1:
The patent segments the inconsistency detection process into distinct automated modules: data collection, ticket requirement extraction, actual activity analysis, comparison logic, and report generation. This segmentation maintains detection thoroughness by systematically covering all aspects while reducing operational complexity through modular, automated processing of each segment.
Solution Approach 2:
The system replaces complex manual analytical processes with automated computational mechanisms. The automation handles the complexity of comprehensive analysis across multiple sessions and parameters, maintaining detection thoroughness while eliminating the operational difficulty that would arise from manual execution of such complex procedures.
4Productivity
If automated analysis is implemented, then productivity and consistency are improved, but initial system complexity and implementation difficulty increase
Solution Approach 1:
The patent implements a universal automated analysis platform that handles multiple ticketing systems, session types, and inconsistency scenarios through a single system architecture. This multi-functionality achieves high productivity and consistency across diverse use cases while managing implementation complexity through a standardized, reusable framework rather than separate systems for each scenario.
Data Source
AI summary
Disclosed embodiments include securing privileged access communication with target systems. Techniques include identifying a request for access to a target resource by an identity, the request being associated with a requested activity that requires privileged access, identifying a connection session in which the identity communicates with the target resource, automatically analyzing an actual activity of the identity occurring in the connection session, automatically comparing the actual activity to the requested activity to determine whether the actual activity complies with the requested activity, and automatically detecting, based on the determination, an inconsistency between the actual activity of the identity and the requested activity associated with the request for access.


