Unified Access Path Graphs for Cloud Data Governance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face difficulties in understanding and managing data access paths in cloud environments, making it challenging to identify which users have access to sensitive data and potential vulnerabilities, both within and outside the organization.
Innovation Solution
A system that utilizes data scanners to obtain permissions and access control data, construct a unified access path graph, and visualize user access to data stores at varying levels of granularity, identifying interdependencies for remedial actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data scanners are used to obtain and analyze permissions data and access control data to identify access paths, then data security posture management capability is improved, but system complexity increases
Solution Approach 1:
The patent introduces an intermediary system that acts as a mediator between the complex access control data sources and the security analysis requirements. This intermediary system consolidates permissions data and access control data from multiple sources, processes them through standardized methods, and presents unified access path information. By inserting this intermediary layer, the system manages complexity while maintaining reliable security posture management capability.
2Loss of information
If a unified access path graph is constructed to visualize user access to data stores at varying levels of granularity, then visibility and understanding of access paths is improved, but computational resources and time increase
Solution Approach 1:
The patent segments the access path visualization into multiple levels of granularity, allowing users to view information at different detail levels (e.g., high-level summary views versus detailed access path views). This segmentation enables the system to provide comprehensive visibility without always processing and displaying the maximum amount of detail, thereby reducing computational time and resource usage while maintaining information visibility when needed.
3Measurement precision
If comprehensive access path analysis is performed to identify all users with access to sensitive data, then security risk identification is improved, but processing time and computational resources increase
Solution Approach 1:
The patent implements partial action by performing comprehensive access path analysis selectively rather than continuously. The system identifies and analyzes access paths based on specific triggers, events, or risk thresholds, performing full analysis only when necessary. This approach maintains high security risk identification accuracy for critical scenarios while improving processing efficiency by avoiding unnecessary comprehensive analyses in routine situations.
Data Source
AI summary
A system for detection and organization of access paths in a computing environment includes a processor and memory accessible by the processor. The memory includes instructions executable to access permissions data and access control data for one or more computing resources in the computing environment, assemble a set of access paths to the one or more computing resources based on the permissions data and the access control data, trace the set of access paths to enumerate constituent elements along the access paths to the one or more computing resources, and automatically construct a unified access path graph representing the set of access paths. The unified access path graph includes node display elements connected by edge display elements to represent interdependencies between the constituent elements at one or more levels of granularity along the access paths to the one or more computing resources.


