Risk-adaptive access control via threat detection data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems require manual intervention by administrators to adjust user privileges in response to detected threats, which is inefficient and prone to delays in mitigating security risks.

Innovation Solution

A risk-adaptive access control system that utilizes threat detection data from network security tools to dynamically adjust access privileges through an XACML-based decision-making process, allowing for automatic changes in access levels based on evolving threat levels, enabling seamless transitions between different security states.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual intervention by administrators is used to adjust user privileges in response to detected threats, then security control can be implemented, but response time is delayed and efficiency is reduced

Engineering Contradiction:
Improvesecurity controlVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-configures access control policies that define privilege adjustment actions for various threat levels. When a threat is detected, the corresponding pre-defined policy is automatically triggered, eliminating the need for administrators to manually determine appropriate privilege adjustments and significantly reducing response time while maintaining security control

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors threat detection data and automatically feeds this information back to the access control policy engine. This closed-loop feedback mechanism enables real-time automatic adjustment of user privileges based on current threat levels, ensuring timely security responses without manual intervention delays

Inventive Principle:
Principle #23Feedback

2Productivity

If automatic adjustment of access privileges is implemented based on threat detection data, then response speed is improved, but system complexity increases

Engineering Contradiction:
Improveresponse speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system employs a universal access control policy framework that can handle multiple threat scenarios and privilege adjustment types through a single standardized policy language (XACML). This multi-functional approach allows the system to automatically respond to various threat levels using the same underlying mechanism, improving response speed while avoiding the complexity of multiple specialized systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system automatically adjusts access control parameters (user privileges) based on changing threat level parameters from detection data. By dynamically modifying these parameters through predefined policies, the system achieves fast automatic responses without requiring complex decision-making logic, as the parameter adjustments are governed by standardized access control rules

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9992213B2Risk-adaptive access control of an application action based on threat detection data
Publication Date: 2018.06.05 DELL EMC
  • US9992213B2 patent drawing
  • US9992213B2 patent drawing
  • US9992213B2 patent drawing

AI summary

Risk-adaptive access control techniques are disclosed. In various embodiments, a value for a threat level attribute is determined based at least in part on threat detection data generated by a security system or process. The determined value for the threat level attribute is used to make, at least in part, an access control decision with respect to a request to access the resource. In various embodiments, the threat level attribute is used as an environment attribute provided as input to an XACML-based access control system.