Privileged Entity Detection via Multi-Layer Permission Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing implementations face challenges in identifying and managing 'shadow' privileged entities, which are difficult to detect due to complex permission structures and dynamic changes in cloud environments, posing security risks.

Innovation Solution

A system and method for automatically discovering and evaluating privileged entities in a network environment by scanning for entities, performing a multi-layer permission evaluation based on network action sensitivity and resource sensitivity, and identifying subsets of entities that can control other privileged entities, with the ability to provide rankings and take remedial actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If current approaches define entities with certain permissions as privileged, then conventional privileged entities can be identified, but shadow privileged entities that control attributes of other entities remain undetected

Engineering Contradiction:
Improvedetection accuracy of privileged entitiesVSAvoidcomplexity of permission structures
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces a new dimension of analysis by examining not only direct permissions but also the relationships between entities. It evaluates how entities can control attributes of other entities through indirect means, adding a relational layer to the traditional permission-based detection approach. This multi-dimensional evaluation enables detection of shadow privileged entities that would be invisible in conventional single-dimension permission checks.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The system uses an intermediary evaluation mechanism that analyzes the control relationships between entities. Instead of directly detecting privileged entities through their own permissions, the system mediates through relationship analysis to identify entities that gain privileged access by controlling attributes of other entities. This intermediary approach bridges the gap between direct permission detection and indirect control detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If cloud environments use many different permissions and dynamic privilege assignments, then flexibility and scalability are improved, but identification of shadow privileged entities becomes extremely difficult

Engineering Contradiction:
Improveflexibility of cloud deploymentVSAvoiddifficulty of identifying shadow privileged entities
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements a dynamic evaluation system that continuously assesses entity relationships and control attributes. Rather than relying on static permission definitions, the system adapts to changing cloud environments by repeatedly evaluating how entities can control each other's attributes. This dynamic approach maintains detection effectiveness despite the flexibility and constant changes inherent in cloud deployments with numerous permissions.

Inventive Principle:
Principle #15Dynamics

3Reliability

If manual tracking and credential rotation are used for privileged entities, then security of known privileged entities can be maintained, but the process is time-consuming and cannot keep pace with dynamic changes

Engineering Contradiction:
Improvesecurity management of privileged entitiesVSAvoidtime for tracking and credential rotation
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements self-service automation where the evaluation process automatically identifies privileged entities and their relationships without manual intervention. The automated system continuously scans the cloud environment, evaluates entity control relationships, and updates the inventory of privileged entities including shadow entities. This self-service approach eliminates manual tracking efforts and enables continuous security management that keeps pace with dynamic cloud changes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where the system continuously monitors and re-evaluates entity relationships. The automated evaluation process provides ongoing feedback about changes in privileged entity status and relationships, enabling real-time security management. This feedback loop ensures that security measures can be promptly adjusted when new shadow privileged entities are detected or when existing ones change their control relationships.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10735433B2Discovering and evaluating privileged entities in a network environment
Publication Date: 2020.08.04 CYBER ARK SOFTWARE LTD
  • US10735433B2 patent drawing
  • US10735433B2 patent drawing
  • US10735433B2 patent drawing

AI summary

Systems and methods are provided for automatically discovering and evaluating privileged entities in a network environment. The systems and methods can include scanning the network environment to identify a plurality of network entities. This scan can include identifying network permissions corresponding to the plurality of network entities. The operations can further include performing a multi-layer evaluation of the permissions corresponding to the plurality of network entities, the multi-layer evaluation being based at least on factors of network action sensitivity and network resource sensitivity. The network action sensitivity factor can address the sensitivity of particular actions that the plurality of network entities are able to take in the network environment. The network resource sensitivity factor can address the sensitivity of particular resources in the network environment that the plurality of network entities are able to access. The system and methods can identify privileged entities using this multi-layer evaluation.