- 专利标题: Identity misconfiguration detection for role-based access control
-
申请号: US17496020申请日: 2021-10-07
-
公开(公告)号: US11956239B2公开(公告)日: 2024-04-09
- 发明人: Idan Hen , Aharon Michaels , Dotan Patrich , Josef Weizman , Amit Magen
- 申请人: MICROSOFT TECHNOLOGY LICENSING, LLC
- 申请人地址: US WA Redmond
- 专利权人: MICROSOFT TECHNOLOGY LICENSING, LLC
- 当前专利权人: MICROSOFT TECHNOLOGY LICENSING, LLC
- 当前专利权人地址: US WA Redmond
- 代理机构: Shook, Hardy & Bacon L.L.P.
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; G06N20/00 ; H04L9/40
摘要:
Technologies are shown for detection of identity misconfiguration that involve collecting identity/role binding and role/access rules data from multiple clusters supported by a computing resource system. Access rules for identities are extracted from the collected data and an access rule prediction model created to predict access rules for identities. An identity definition request for a tenant is received having a requested identity and a role assigned to the identity. A set of access rules is obtained for the role assigned to the identity and a predicted set of access rules is obtained for the requested identity from the prediction model. The access rules for the requested role are compared to the predicted set of access rules and a misconfiguration alert generated when there is a difference between the set of access rules for the requested role and the predicted set of access rules for the requested identity.
公开/授权文献
信息查询