User Permission Scoring to Detect Overreaching Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large enterprises face challenges in managing access permissions due to the proliferation of security groups, leading to excessive permissions and increased security risks, with traditional methods failing to identify anomalous users effectively.

Innovation Solution

A computer-implemented method and system that determines access permission data for users, computes first score data to assess closeness to expected permissions, and identifies users with overreaching access by setting a threshold, allowing for corrective actions to mitigate risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If security groups are used to manage access permissions, then ease of operation is improved, but device complexity increases due to proliferation of groups

Engineering Contradiction:
Improveaccess permission managementVSAvoidnumber of security groups
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism by continuously monitoring user access patterns and group memberships, then using this information to automatically identify and flag anomalous permissions. The system calculates anomaly scores based on deviations from expected access behavior, providing ongoing feedback that enables dynamic adjustment of permission management without requiring manual review of each group.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs self-service by automatically identifying over-permissioned users through algorithmic analysis of access patterns rather than requiring manual security audits. The anomaly detection system autonomously evaluates permission assignments, calculates risk scores, and generates alerts, enabling the security system to manage itself without constant human intervention.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If permissions are granted in an ad hoc manner, then ease of operation is improved, but reliability deteriorates due to excessive permissions

Engineering Contradiction:
Improvepermission grantingVSAvoidaccess control security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces manual mechanical review processes with an automated computational system that uses algorithmic analysis to evaluate permission assignments. Instead of relying on human security teams to manually audit each permission grant, the system uses automated anomaly detection algorithms to continuously assess permission appropriateness, substituting human judgment with systematic computational evaluation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs preliminary action by proactively identifying potential security risks before they can be exploited. By continuously monitoring and analyzing permission assignments in real-time, the system detects anomalous patterns and flags over-permissioned users before malicious activities can occur, preventing security incidents rather than responding to them after the fact.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If manual determination of appropriate permissions is performed, then measurement precision is improved, but loss of time increases

Engineering Contradiction:
Improvepermission accuracyVSAvoidtime for permission assessment
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements continuous monitoring and analysis of user access patterns, maintaining an ongoing evaluation of permission appropriateness rather than performing discrete manual audits. The system continuously collects access data, updates anomaly scores, and identifies over-permissioned users in real-time, ensuring that permission accuracy is maintained without periodic interruptions for manual review.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system introduces an intermediary automated analysis layer between raw access data and security decisions. Instead of directly comparing each permission against complex security policies, the intermediary anomaly detection system processes access patterns and generates simplified risk assessments, mediating between detailed access data and actionable security insights to reduce assessment time while maintaining precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12375517B1Methods and systems for identifying anomalous users exhibiting overreaching access permissions to data objects
Publication Date: 2025.07.29 CONCENTRIC SOFTWARE INC
  • US12375517B1 patent drawing
  • US12375517B1 patent drawing
  • US12375517B1 patent drawing

AI summary

Methods and systems for identifying anomalous users exhibiting overreaching access permissions to data objects. The method includes determining access permission data for each of a plurality of users. Each of the plurality of data objects corresponds to one of a plurality of categories. The method includes determining first score data for each user of the plurality of users based on the access permission data associated with each of the plurality of users. The method includes computinga threshold value of the first score data defining a boundary value of the first score datafor identification of the anomalous users. The method includes identifying a subset of users, among the plurality of users, as the anomalous users exhibiting overreaching access permission. The first score data for each of the subset of usersis equal to or below the computed threshold value.