Automated Role Mining via Network Traffic Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for defining Role-Based Access Control (RBAC) policies in organizations are inefficient and costly, often resulting in ineffective policies due to manual processes and confusion around role definitions, and automated solutions tend to produce roles based on existing policies rather than actual user behavior.
Innovation Solution
Utilizing network traffic inspection technology to record user access and analyze it to derive roles and entitlements, with an analytics engine identifying users and applications involved, and interrogating directory services for group and user relationships to refine these roles, generating an XML RBAC policy for identity management systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual processes (interviews, documentation review) are used to discover roles and entitlements, then comprehensive role definitions can be obtained, but the process becomes very expensive and time-consuming
Solution Approach 1:
The patent replaces manual mechanical processes (interviews, documentation review) with automated electronic data collection and analysis systems. Network traffic data is automatically captured and analyzed by processors to extract role definitions, eliminating the need for manual interviews and documentation analysis while maintaining comprehensive role discovery capabilities
Solution Approach 2:
The system enables self-service role discovery by automatically analyzing existing network traffic data and user behavior patterns without requiring manual intervention. The automated analysis of network observations allows the system to self-determine roles and entitlements based on actual usage patterns rather than requiring manual input from employees or administrators
2Productivity
If automated role modeling is implemented to reduce manual effort, then role discovery becomes faster, but the resulting roles track existing policy rather than actual user behavior
Solution Approach 1:
Instead of starting with existing policy definitions and automating their enforcement, the patent inverts the approach by starting with actual network traffic data and user behavior observations, then automatically deriving role definitions from these observed patterns. This ensures roles reflect actual usage rather than predefined policies
Solution Approach 2:
The patent replaces policy-based automated role modeling with behavior-based automated role modeling by analyzing actual network traffic patterns. The system substitutes traditional policy-driven automation with data-driven automation that observes and learns from real user interactions with systems and applications
3Device complexity
If static information is used for role mining in identity management systems, then the process is simpler, but it cannot capture dynamic user behavior patterns
Solution Approach 1:
The patent transforms static role mining into a dynamic process by continuously analyzing network traffic data to capture evolving user behavior patterns. The system dynamically adjusts role definitions based on observed changes in user interactions, making the role mining process adaptive rather than static
Solution Approach 2:
The patent adds the dimension of temporal behavior analysis by examining network traffic over time to identify patterns in user behavior. This transforms the role mining process from a single-point-in-time static analysis to a multi-dimensional analysis that incorporates temporal patterns and behavioral evolution
Data Source
AI summary
A role and entitlements mining system uses network intelligence to facilitate role definition. The system records traffic on a network. The traffic is analyzed to identify the user and application involved. The matched data is then provided to an analytics engine, which analyzes that data to attempt to derive an initial set of one or more roles and the application entitlements for each role. Each role derived by the analytics engine identifies one or more users who are identified as belonging to the role, as well as one or more application entitlements. Preferably, one or more directory services are then interrogated for known group and user relationships to detect whether the roles identified by the analytics engine can be modified or enriched. Evaluation of the known group and user relationships provides a way to identify a more granular set of role definitions. A role-based access control policy is then generated.


