Systems and methods for generating aggregated application access risk scores
A system determines, based on a request to assess access risk associated with an application, a plurality of layer access risk scores that are associated with the application. The system determines, based on access risk mitigation information and the plurality of layer access risk scores, a plurality of layer residual access risk scores. The system determines respective risk contribution weights associated with the plurality of layer residual access risk scores. The system determines, based on the respective risk contribution weights and on the plurality of layer residual access risk scores, an aggregated application access risk score associated with the application. The system causes, based on the aggregated application access risk score, one or more actions to be performed. For example, the system may initiate an access risk analysis process for the application and/or may generate an access control policy associated with the application.
1 . A system for generating aggregated application access risk scores, the system comprising:
one or more memories; and
one or more processors, communicatively coupled to the one or more memories, configured to:
receive, from a device, a request to assess access risk associated with an application;
identify, based on the request, a network layer, a host layer, an application layer, and a data layer that are associated with the application;
identify, based on the request, access risk mitigation information associated with the application;
determine, based on identifying the network layer, the host layer, the application layer, and the data layer, a network layer access risk score, a host layer access risk score, an application layer access risk score, and a data layer access risk score that are associated with the application;
determine, based on the access risk mitigation information, and based on the network layer access risk score, the host layer access risk score, the application layer access risk score, and the data layer access risk score, a network layer residual access risk score, a host layer residual access risk score, an application layer residual access risk score, and a data layer residual access risk score;
determine respective risk contribution weights associated with the network layer, the host layer, the application layer, and the data layer;
determine, based on multiplying each of the respective risk contribution weights associated with the network layer, the host layer, the application layer, and the data layer with its corresponding residual access risk score of the network layer residual access risk score, the host layer residual access risk score, the application layer residual access risk score, and the data layer residual access risk score, respective weighted residual access risk scores associated with the network layer, the host layer, the application layer, and the data layer;
determine, based on combining the respective weighted residual access risk scores associated with the network layer, the host layer, the application layer, and the data layer an aggregated application access risk score associated with the application; and
generate, based on the aggregated application access risk score, an access control policy associated with the application.
2 . The system of claim 1 , wherein the access risk mitigation information indicates at least one of:
one or more network layer access risk mitigation features;
one or more host layer access risk mitigation features;
one or more application layer access risk mitigation features; and
one or more data layer access risk mitigation features.
3 . The system of claim 1 , wherein the one or more processors, to determine the network layer access risk score, the host layer access risk score, the application layer access risk score, and the data layer access risk score, are configured to:
identify configuration information associated with the application;
determine, using a network layer access risk scoring technique and based on the configuration information, the network layer access risk score;
determine, using a host layer access risk scoring technique and based on the configuration information, the host layer access risk score;
determine, using an application layer access risk scoring technique and based on the configuration information, the application layer access risk score; and
determine, using a data layer access risk scoring technique and based on the configuration information, the data layer access risk score.
4 . The system of claim 1 , wherein the one or more processors, to determine the network layer residual access risk score, the host layer residual access risk score, the application layer residual access risk score, and the data layer residual access risk score, are configured to:
determine, using a network layer access risk re-scoring technique, and based on the network layer access risk score and one or more network layer access risk mitigation features indicated by the access risk mitigation information, the network layer residual access risk score;
determine, using a host layer access risk re-scoring technique, and based on the host layer access risk score and one or more host layer access risk mitigation features indicated by the access risk mitigation information, the host layer residual access risk score;
determine, using an application layer access risk re-scoring technique, and based on the application layer access risk score and one or more application layer access risk mitigation features indicated by the access risk mitigation information, the host layer residual access risk score; and
determine, using a data layer access risk re-scoring technique, and based on the data layer access risk score and one or more data layer access risk mitigation features indicated by the access risk mitigation information, the data layer residual access risk score.
5 . The system of claim 1 , wherein the one or more processors, to determine the respective risk contribution weights associated with the network layer, the host layer, the application layer, and the data layer, are configured to:
identify domain expertise information associated with the network layer, the host layer, the application layer, and the data layer; and
determine, using an analytical hierarchical process statistical technique, and based on the domain expertise information, the respective risk contribution weights associated with the network layer, the host layer, the application layer, and the data layer.
6 . The system of claim 1 , wherein the one or more processors are further configured to:
send, to the device, information that includes the aggregated application access risk score,
wherein sending the information to the device allows the device to present the aggregated application access risk score via a display of the device.
7 . The system of claim 1 , wherein the one or more processors are further configured to:
determine that the aggregated application access risk score satisfies a threshold; and
initiate, based on determining that the aggregated application access risk score satisfies the threshold, an access risk analysis process for the application.
8 . The system of claim 1 , wherein the one or more processors are further configured to:
determine that the aggregated application access risk score satisfies a threshold;
generate, based on determining that the aggregated application access risk score satisfies the threshold, the access control policy associated with the application; and
cause the access control policy to be implemented.
9 . A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising:
one or more instructions that, when executed by one or more processors of a system, cause the system to:
receive a request to assess access risk associated with an application;
determine, based on the request, a plurality of layer access risk scores that are associated with the application;
determine, based on access risk mitigation information and the plurality of layer access risk scores, a plurality of layer residual access risk scores;
determine respective risk contribution weights associated with the plurality of layer residual access risk scores;
determine, based on multiplying each of the respective risk contribution weights with a corresponding residual access risk score of the plurality of layer residual access risk scores, respective weighted residual access risk scores;
determine, based on combining the respective weighted residual access risk scores, an aggregated application access risk score associated with the application; and
generate, based on the aggregated application access risk score, an access control policy associated with the application.
10 . The non-transitory computer-readable medium of claim 9 , wherein the one or more instructions, that cause the system to determine the plurality of layer access risk scores, cause the system to:
identify configuration information associated with the application; and
determine, using a plurality of layer access risk scoring techniques and based on the configuration information, the plurality of layer access risk scores.
11 . The non-transitory computer-readable medium of claim 9 , wherein the one or more instructions, that cause the system to determine the plurality of layer residual access risk scores, cause the system to:
determine, using a plurality of layer access risk re-scoring techniques, and based on the plurality of layer access risk scores and the access risk mitigation information, the plurality of layer residual access risk scores.
12 . The non-transitory computer-readable medium of claim 9 , wherein the one or more instructions, that cause the system to determine the respective risk contribution weights associated with the plurality of layer residual access risk scores, cause the system to:
determine, using a statistical technique, and based on domain expertise information, the respective risk contribution weights associated with the plurality of layer residual access risk scores.
13 . The non-transitory computer-readable medium of claim 9 , wherein the one or more instructions, when executed by the one or more processors, further cause the system to:
initiate, based on the aggregated application access risk score, an access risk analysis process for the application.
14 . The non-transitory computer-readable medium of claim 9 , wherein
generating the access control policy allows the access control policy to be implemented by the system or another device.
15 . A method for generating aggregated application access risk scores, comprising:
determining a plurality of layer access risk scores that are associated with an application;
determining, based on access risk mitigation information and the plurality of layer access risk scores, a plurality of layer residual access risk scores;
determining respective risk contribution weights associated with the plurality of layer residual access risk scores;
determining, based on multiplying each of the plurality of layer residual access risk scores with a corresponding risk contribution weight of the respective risk contribution weights, respective weighted residual access risk scores;
determining, based on combining the respective weighted residual access risk scores, an aggregated application access risk score associated with the application; and
initiating, based on the aggregated application access risk score, an access risk analysis process for the application.
16 . The method of claim 15 , wherein determining the plurality of layer residual access risk scores comprises:
determining, using a plurality of layer access risk re-scoring techniques, and based on the plurality of layer access risk scores and the access risk mitigation information, the plurality of layer residual access risk scores.
17 . The method of claim 15 , further comprising:
sending information that includes the aggregated application access risk score,
wherein sending the information allows the aggregated application access risk score to be presented via a display.
18 . The method of claim 15 , further comprising:
generating, based on the aggregated application access risk score, an access control policy associated with the application.
19 . The method of claim 18 , further comprising:
causing the access control policy to be implemented by a device based on transmitting the access control policy to the device.
20 . The method of claim 18 , further comprising:
generating the access control policy associated with the application based on the aggregated application access risk score satisfying a threshold.