Privileged Entity Detection via Multi-Layer Permission Evaluation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud computing implementations face challenges in identifying and managing 'shadow' privileged entities, which are difficult to detect due to complex permission structures and dynamic changes in cloud environments, posing security risks.
Innovation Solution
A system and method for automatically discovering and evaluating privileged entities in a network environment by scanning for entities, performing a multi-layer permission evaluation based on network action sensitivity and resource sensitivity, and identifying subsets of entities that can control other privileged entities, with the ability to provide rankings and take remedial actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If current approaches define entities with certain permissions as privileged, then conventional privileged entities can be identified, but shadow privileged entities that control attributes of other entities remain undetected
Solution Approach 1:
The patent introduces a new dimension of analysis by examining not only direct permissions but also the relationships between entities. It evaluates how entities can control attributes of other entities through indirect means, adding a relational layer to the traditional permission-based detection approach. This multi-dimensional evaluation enables detection of shadow privileged entities that would be invisible in conventional single-dimension permission checks.
Solution Approach 2:
The system uses an intermediary evaluation mechanism that analyzes the control relationships between entities. Instead of directly detecting privileged entities through their own permissions, the system mediates through relationship analysis to identify entities that gain privileged access by controlling attributes of other entities. This intermediary approach bridges the gap between direct permission detection and indirect control detection.
2Adaptability or versatility
If cloud environments use many different permissions and dynamic privilege assignments, then flexibility and scalability are improved, but identification of shadow privileged entities becomes extremely difficult
Solution Approach 1:
The patent implements a dynamic evaluation system that continuously assesses entity relationships and control attributes. Rather than relying on static permission definitions, the system adapts to changing cloud environments by repeatedly evaluating how entities can control each other's attributes. This dynamic approach maintains detection effectiveness despite the flexibility and constant changes inherent in cloud deployments with numerous permissions.
3Reliability
If manual tracking and credential rotation are used for privileged entities, then security of known privileged entities can be maintained, but the process is time-consuming and cannot keep pace with dynamic changes
Solution Approach 1:
The system implements self-service automation where the evaluation process automatically identifies privileged entities and their relationships without manual intervention. The automated system continuously scans the cloud environment, evaluates entity control relationships, and updates the inventory of privileged entities including shadow entities. This self-service approach eliminates manual tracking efforts and enables continuous security management that keeps pace with dynamic cloud changes.
Solution Approach 2:
The patent incorporates feedback mechanisms where the system continuously monitors and re-evaluates entity relationships. The automated evaluation process provides ongoing feedback about changes in privileged entity status and relationships, enabling real-time security management. This feedback loop ensures that security measures can be promptly adjusted when new shadow privileged entities are detected or when existing ones change their control relationships.
Data Source
AI summary
Systems and methods are provided for automatically discovering and evaluating privileged entities in a network environment. The systems and methods can include scanning the network environment to identify a plurality of network entities. This scan can include identifying network permissions corresponding to the plurality of network entities. The operations can further include performing a multi-layer evaluation of the permissions corresponding to the plurality of network entities, the multi-layer evaluation being based at least on factors of network action sensitivity and network resource sensitivity. The network action sensitivity factor can address the sensitivity of particular actions that the plurality of network entities are able to take in the network environment. The network resource sensitivity factor can address the sensitivity of particular resources in the network environment that the plurality of network entities are able to access. The system and methods can identify privileged entities using this multi-layer evaluation.


