Data transfer discovery and analysis systems and related methods
In various aspects, a data transfer discovery and analysis system may query an entity computing system to identify access credentials for third-party computing systems and scan each access credential to determine associated permissions provided by each access credential on the entity computing system. The data transfer discovery and analysis system may further inspect access logs to identify actual data transfers between the entity computing system and third-party computing systems as well as other access activity associated with each of the credentials. The system can generate and store a mapping of all actual data transfers (e.g., based on the access log data) and potential data transfers (e.g., based on particular access permissions) between/among the entity computing system and the third-party computing systems. By analyzing access logs to determine actual data transfers executed under each particular access credential, the data transfer discovery and analysis system can identify unused and/or underutilized access permissions.
1 . A computer-implemented method comprising:
classifying, by computing hardware, one or more access permission types of one or more access permissions provided by an access credential granted to a third-party computing system in connection with one or more data object types or one or more operations of an entity computing system;
determining, by the computing hardware and by inspecting an access log associated with the entity computing system, access activity for the access credential, wherein the access activity comprises one or more entries of the access log that indicate actual access of one or more data objects by the third-party computing system under the access credential to carry out one or more actual data transfers between the entity computing system and the third-party computing system;
identifying that a potential data transfer is not associated with the one or more actual data transfers indicated by the access activity, wherein the potential data transfer represents configurations for data transfers that are allowed under an access permission type of the one or more access permission types, wherein identifying that the potential data transfer is not associated with the one or more actual data transfers comprises:
determining that the potential data transfer corresponds to the access permission type; and
determining the access activity does not identify an actual data transfer between the entity computing system and the third-party computing system defined by the access permission type; and
causing, by the computing hardware in response to the potential data transfer not being associated with the one or more actual data transfers, the entity computing system to modify the access credential by modifying the access permission type for the access credential.
2 . The computer-implemented method of claim 1 , wherein causing the entity computing system to modify the access credential comprises causing the entity computing system to rescind the access credential.
3 . The computer-implemented method of claim 1 , wherein causing the entity computing system to modify the access credential comprises causing the entity computing system to remove an access permission of the access permission type for the access credential.
4 . The computer-implemented method of claim 1 , wherein determining the access activity comprises determining an amount of data accessed on the entity computing system by a plurality of third-party computing systems comprising the third-party computing system under the access credential, a frequency of data access on the entity computing system by the plurality of third-party computing systems under the access credential, and access permissions utilized by each of the plurality of third-party computing systems under the access credential.
5 . The computer-implemented method of claim 1 , wherein classifying the one or more access permission types of the one or more access permissions provided by the access credential comprises:
classifying a first access permission of the access credential with a first access permission type associated with a data object or an operation; and
classifying a second access permission of the access credential with a second access permission type associated with the data object or the operation.
6 . The computer-implemented method of claim 5 , wherein causing the entity computing system to modify the access credential further comprises:
determining that the access activity with respect to the first access permission type does not exceed an activity threshold; and
causing the entity computing system to modify the first access permission of the access credential in response to the access activity with respect to the first access permission type not exceeding the activity threshold.
7 . The computer-implemented method of claim 1 , further comprising generating a mapping of data transfers between the entity computing system and the third-party computing system by:
generating the mapping to include the one or more actual data transfers between the entity computing system and the third-party computing system according to the access activity; and
generating the mapping to include a plurality of potential data transfers between the entity computing system and the third-party computing system according to the one or more access permissions provided by the access credential.
8 . The computer-implemented method of claim 1 , wherein classifying the one or more access permission types comprises:
generating, utilizing an ensemble of classifiers, a plurality of probabilities of access permission types corresponding to an access permission of the access credential in connection with a particular data object; and
assigning a particular access permission type to the access permission of the access credential for the particular data object based on a corresponding probability exceeding a probability threshold.
9 . A system comprising:
computing hardware configured to:
query an entity computing system to determine access credentials indicating access permissions granted to a third-party computing system in connection with one or more data object types or one or more operations of the entity computing system;
classify, utilizing a classification engine, access permission types of the access permissions provided by the access credentials granted to the third-party computing system;
determine, by inspecting an access log associated with the entity computing system, access activity for the access credentials, wherein the access activity comprises one or more entries of the access log that indicate actual access of one or more data objects by the third-party computing system under the access credentials to carry out one or more actual data transfers between the entity computing system and the third-party computing system;
identify, that a potential data transfer is not associated with the one or more actual data transfers between the entity computing system and the third-party computing system indicated by the access activity, wherein the potential data transfer represents configuration for data transfers that are allowed under an access permission type of the access permission types, wherein identifying that the potential data transfer is not associated with the one or more actual data transfers comprises:
determining that the potential data transfer corresponds to the access permission type; and
determining the access activity does not identify an actual data transfer between the entity computing system and the third-party computing system defined by the access permission type; and
determine that an access credential of the access credentials is underutilized for the entity computing system in response to determining that the potential data transfer allowed under the access permission type is not associated with the one or more actual data transfers according to a mapping; and
the entity computing system, wherein the entity computing system is communicatively coupled to the computing hardware and is configured to modify the access credential determined by the computing hardware to be underutilized by (a) rescinding the access credential or (b) modifying the access permission type for the access credential.
10 . The system of claim 9 , wherein the entity computing system is configured to modify the access permission type by removing an access permission of the access permission type for the access credential in connection with the one or more data object types or the one or more operations of the entity computing system.
11 . The system of claim 9 , wherein the computing hardware is configured to cause the system to determine the access activity by determining a volume of data accessed under the access credential, a number of times data was accessed under the access credential, or one or more access permissions utilized under the access credential.
12 . The system of claim 9 , wherein the computing hardware is configured to cause the system to classify the access permission types of the access permissions provided by the access credential by:
classifying each access permission of the access credential as one of a plurality of access permission types in connection with the one or more data object types or the one or more operations; and
generating a data structure comprising a corresponding access permission type of each access permission of the access credential, wherein the data structure is organized according to the access permission types.
13 . The system of claim 9 , wherein:
the computing hardware is configured to cause the system to cause the entity computing system to modify the access credential by determining that the access activity with respect to the access permission type of the access permission types does not exceed an activity threshold; and
the entity computing system is configured to modify the access permission type of the access permission types for the access credential based on the access activity with respect to the access permission type of the access permission types not exceeding the activity threshold.
14 . The system of claim 9 , wherein the computing hardware is configured to cause the system to generate the mapping of data transfers between the entity computing system and the third-party computing system by:
generating the mapping to include a plurality of potential data transfers between the entity computing system and the third-party computing system according to the access permissions provided by the access credentials; and
modify the mapping to include the one or more actual data transfers between the entity computing system and the third-party computing system according to the access activity.
15 . A non-transitory computer readable medium comprising instructions that, when executed by computing hardware, cause the computing hardware to perform operations comprising:
classify one or more access permission types of one or more access permissions provided by an access credential granted to a third-party computing system in connection with one or more data object types or one or more operations of an entity computing system;
determine, by inspecting an access log associated with the entity computing system, access activity for the access credential, wherein the access activity comprises one or more entries of the access log that indicate actual access of one or more data objects by the third-party computing system under the access credential to carry out one or more actual data transfers between the entity computing system and the third-party computing system;
identify that a potential data transfer is not associated with the one or more actual data transfers indicated by the access activity, wherein the potential data transfer represents configurations for data transfers that are allowed under an access permission type of the one or more access permission types, wherein identifying that the potential data transfer is not associated with the one or more actual data transfers comprises:
determining that the potential data transfer corresponds to the access permission type; and
determining the access activity does not identify an actual data transfer between the entity computing system and the third-party computing system defined by the access permission type; and
cause, in response to the potential data transfer not being associated with the one or more actual data transfers, the entity computing system to modify the access credential by modifying the access permission type for the access credential.
16 . The non-transitory computer readable medium of claim 15 , wherein causing the entity computing system to modify the access credential comprises causing the entity computing system to rescind the access credential.
17 . The non-transitory computer readable medium of claim 15 , wherein causing the entity computing system to modify the access credential comprises causing the entity computing system to remove an access permission of the access permission type for the access credential.
18 . The non-transitory computer readable medium of claim 15 , wherein causing the entity computing system to modify the access credential further comprises:
determining that the access activity with respect to the access permission type associated with the potential data transfer does not exceed an activity threshold; and
causing the entity computing system to modify the access credential in response to the access activity with respect to the access permission type associated with the potential data transfer not exceeding the activity threshold.
19 . The non-transitory computer readable medium of claim 15 , wherein the instructions that, when executed by the computing hardware, further cause the computing hardware to perform the operations further comprising generating a mapping of data transfers between the entity computing system and the third-party computing system.
20 . The non-transitory computer readable medium of claim 19 , wherein generating the mapping of data transfers between the entity computing system and the third-party computing system comprises:
generating the mapping to include the one or more actual data transfers between the entity computing system and the third-party computing system according to the access activity; and
generating the mapping to include a plurality of potential data transfers between the entity computing system and the third-party computing system according to the one or more access permissions provided by the access credential.