Security Policy Optimization via Permission Usage Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security policies are manually maintained and often outdated, leading to increased security risks and compliance issues due to the lack of automated tools that monitor permission usage and ensure alignment with high-level security objectives.

Innovation Solution

A method for correlating access logs with security policies to identify policy items that violate the principle of least privilege, increase operational risk, and optimize security policies based on actual permission usage, ensuring continuous compliance and reducing administrative burdens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security policies are manually maintained by security administrators, then policy creation and updates can be performed with human judgment and oversight, but the workload for security administrators becomes huge and policies become outdated quickly

Engineering Contradiction:
Improvepolicy accuracyVSAvoidpolicy maintenance efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs self-service by automatically analyzing permission usage logs and generating policy optimization recommendations without requiring continuous manual intervention. The automated analysis engine continuously monitors permission usage and identifies policies that violate least privilege principles, enabling the system to maintain and optimize itself

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring actual permission usage and comparing it against defined security policies. This feedback loop enables the system to identify discrepancies between intended security posture and actual usage patterns, automatically generating recommendations to align policies with actual needs

Inventive Principle:
Principle #23Feedback

2Reliability

If the number of security policies increases to cover thousands of employees and resources, then security coverage improves, but the policies become very complicated and hard to maintain

Engineering Contradiction:
Improvesecurity coverageVSAvoidpolicy complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts the complexity of policy analysis by separating policy evaluation from policy management. The automated analysis engine isolates the complex task of analyzing permission usage patterns and policy compliance, presenting simplified recommendations to administrators rather than requiring them to manually analyze complex policy interactions

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the parameter of policy representation by transforming complex policy definitions into actionable metrics such as permission usage frequency, violation counts, and risk scores. This parameter transformation makes large numbers of policies manageable by focusing on key indicators rather than detailed policy configurations

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If security administrators manually update policies frequently, then policies can stay up-to-date with employee changes, but the administrative workload increases significantly

Engineering Contradiction:
Improvepolicy currencyVSAvoidadministrative time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system implements continuous monitoring of permission usage logs and automatic detection of policy violations. This continuous action eliminates the need for periodic manual policy reviews by maintaining constant surveillance of permission usage patterns and automatically identifying when policies need optimization

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs preliminary analysis of permission usage patterns to identify potential policy violations before they become actual security risks. By proactively analyzing usage logs and predicting policy optimization needs, the system prevents policy obsolescence rather than reacting to it

Inventive Principle:
Principle #10Preliminary action

4Extent of automation

If automated tools are introduced to monitor permission usage, then policy compliance can be continuously verified, but no such automated tools currently exist to perform this function

Engineering Contradiction:
Improvecompliance monitoring automationVSAvoidsystem implementation difficulty
Core Design Contradiction:
Extent of automationVSEase of manufacture

Solution Approach 1:

The system achieves universality by designing a multi-functional platform that combines permission usage log analysis, policy compliance verification, least privilege detection, and optimization recommendation generation. This single system performs multiple security functions that would otherwise require separate tools, simplifying implementation while providing comprehensive automated monitoring

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9288232B2Techniques for reconciling permission usage with security policy for policy optimization and monitoring continuous compliance
Publication Date: 2016.03.15 SAILPOINT TECHNOLOGIES HOLDINGS INC
  • US9288232B2 patent drawing
  • US9288232B2 patent drawing
  • US9288232B2 patent drawing

AI summary

In one aspect, a method for managing a security policy having multiple policy items includes the steps of: (a) mapping permissions to the policy items which apply to usage of the permissions so as to determine which of the permissions are granted to groups of users by each of the policy items; (b) identifying at least one of the policy items mapped in step (a) that is in violation of least privilege based on a comparison of an actual permission usage with the security policy; (c) identifying at least one of the policy items mapped in step (a) that increases operational risk; (d) verifying that policy constructs in the security policy are consistent with policy constructs inferred from the actual permission usage; and (e) identifying optimizations of the security policy based on output from one or more of steps (a)-(d).