Unified Access and Identity Management for Intrusion Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access management systems fail to effectively detect and report intrusion threats in E-business environments, lacking the capability to communicate with robust identity management systems and providing inadequate information for identifying attempted intrusions.
Innovation Solution
A system that integrates identity management and access management functionalities to detect access system events, report relevant information, and utilize a rules engine to determine if events indicate attempted intrusions, with configurable reporting options and decentralized administration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access management systems integrate identity management functionality to detect intrusion threats, then security detection capability is improved, but system complexity increases
Solution Approach 1:
The patent combines identity management and access management functionalities into a unified system. The access management system integrates with the identity management system to access identity information and detect intrusion threats, eliminating the need for separate systems and reducing overall complexity despite enhanced detection capabilities.
Solution Approach 2:
The access management system is designed to perform multiple functions: it manages access control while simultaneously detecting intrusion threats by analyzing access patterns against identity information. This multi-functionality allows a single system to address both access management and security detection needs.
2Measurement precision
If the system monitors and reports all access system events, then intrusion detection accuracy is improved, but information processing load increases
Solution Approach 1:
The system applies different monitoring intensities to different types of access events. It focuses detailed analysis on events that are more likely to indicate intrusions (such as authentication failures or unusual access patterns) while using lighter monitoring for routine authorized access, thereby reducing overall processing load while maintaining detection accuracy.
Solution Approach 2:
The system monitors all access events but applies full analysis only to suspicious events. Routine events receive minimal processing, allowing the system to maintain comprehensive monitoring capability while reducing the actual computational burden by focusing resources on partial analysis of only those events that require detailed examination.
3Reliability
If the system stores and manages detailed user and policy information centrally, then security management effectiveness is improved, but administrative scalability deteriorates
Solution Approach 1:
The system segments the centralized identity management information into distributed caches across multiple access management servers. Each server maintains a local cache of identity information, allowing administrative decisions to be made locally while still benefiting from the centralized identity management system. This segmentation enables the system to scale administratively while maintaining security effectiveness.
Solution Approach 2:
The system pre-loads and caches identity information and policy data in advance on local servers. This preliminary action allows the system to respond to access requests and detection needs without real-time queries to the central system, improving both security response effectiveness and administrative scalability by reducing central system dependency.
Data Source
AI summary
A system is disclosed that can be used to monitor for an attempted intrusion of an access system. The system detects an access system event in the access system and determines whether the access system event is of a type that is being monitored. If the access system event is of a type that is being monitored, the system reports information about the access system event. This information can be used by a rules engine or other process to determine if the access system event was part of an attempted intrusion of the access system.


