Automated Role Mining via Network Traffic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for defining Role-Based Access Control (RBAC) policies in organizations are inefficient and costly, often resulting in ineffective policies due to manual processes and confusion around role definitions, and automated solutions tend to produce roles based on existing policies rather than actual user behavior.

Innovation Solution

Utilizing network traffic inspection technology to record user access and analyze it to derive roles and entitlements, with an analytics engine identifying users and applications involved, and interrogating directory services for group and user relationships to refine these roles, generating an XML RBAC policy for identity management systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual processes (interviews, documentation review) are used to discover roles and entitlements, then comprehensive role definitions can be obtained, but the process becomes very expensive and time-consuming

Engineering Contradiction:
Improverole definition accuracyVSAvoidrole discovery time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical processes (interviews, documentation review) with automated electronic data collection and analysis systems. Network traffic data is automatically captured and analyzed by processors to extract role definitions, eliminating the need for manual interviews and documentation analysis while maintaining comprehensive role discovery capabilities

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service role discovery by automatically analyzing existing network traffic data and user behavior patterns without requiring manual intervention. The automated analysis of network observations allows the system to self-determine roles and entitlements based on actual usage patterns rather than requiring manual input from employees or administrators

Inventive Principle:
Principle #25Self-service

2Productivity

If automated role modeling is implemented to reduce manual effort, then role discovery becomes faster, but the resulting roles track existing policy rather than actual user behavior

Engineering Contradiction:
Improverole discovery efficiencyVSAvoidrole accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

Instead of starting with existing policy definitions and automating their enforcement, the patent inverts the approach by starting with actual network traffic data and user behavior observations, then automatically deriving role definitions from these observed patterns. This ensures roles reflect actual usage rather than predefined policies

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent replaces policy-based automated role modeling with behavior-based automated role modeling by analyzing actual network traffic patterns. The system substitutes traditional policy-driven automation with data-driven automation that observes and learns from real user interactions with systems and applications

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Device complexity

If static information is used for role mining in identity management systems, then the process is simpler, but it cannot capture dynamic user behavior patterns

Engineering Contradiction:
Improverole mining complexityVSAvoidbehavior pattern detection
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent transforms static role mining into a dynamic process by continuously analyzing network traffic data to capture evolving user behavior patterns. The system dynamically adjusts role definitions based on observed changes in user interactions, making the role mining process adaptive rather than static

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent adds the dimension of temporal behavior analysis by examining network traffic over time to identify patterns in user behavior. This transforms the role mining process from a single-point-in-time static analysis to a multi-dimensional analysis that incorporates temporal patterns and behavioral evolution

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9154507B2Automated role and entitlements mining using network observations
Publication Date: 2015.10.06 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9154507B2 patent drawing
  • US9154507B2 patent drawing
  • US9154507B2 patent drawing

AI summary

A role and entitlements mining system uses network intelligence to facilitate role definition. The system records traffic on a network. The traffic is analyzed to identify the user and application involved. The matched data is then provided to an analytics engine, which analyzes that data to attempt to derive an initial set of one or more roles and the application entitlements for each role. Each role derived by the analytics engine identifies one or more users who are identified as belonging to the role, as well as one or more application entitlements. Preferably, one or more directory services are then interrogated for known group and user relationships to detect whether the roles identified by the analytics engine can be modified or enriched. Evaluation of the known group and user relationships provides a way to identify a more granular set of role definitions. A role-based access control policy is then generated.