IP Library Patent Application 13326473
Patent Application
App. No. 13/326,473

AUTOMATIC RISK CALIBRATION OF ROLES IN COMPUTER SYSTEMS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/326,473
Abstract

Various embodiments of systems and methods for automatic calibration a risk level of a role are described herein. Automatically and periodically a risk level of a role is evaluated based on various risk factors associated with the role. Risk factors' values are determined by respective risk factor aggregators. Risk factors are assigned weights to determine their influence degree on the risk level of the role. The risk level of the role is computed by a risk calibration engine based on the determined risk factors' values and assigned weights, respectively.

Claims (70)

1 . A computerized method to automatically calibrate a level of risk of a role in a computer system, the method comprising:

tracking by at least one aggregator at least one value of at least one risk factor associated with said role in said computer system;

retrieving from a memory at least one weight associated with said at least one risk factor;

computing by a processor a current level of risk of said role in said computer system based on said at least one value and said at least one weight of said at least one risk factor; and

calibrating said current level of risk against a comparative level of risk of said role in said computer system.

2 . The method of claim 1 further comprising:

updating in said memory said at least one value of said at least one risk factor by said at least one aggregator; and

in response to said updating of said at least one value of said at least one risk factor, computing by said processor said current level of risk of said role in said computer system based on said updated at least one value and said at least one weight of said at least one risk factor.

3 . The method of claim 1 further comprising:

in response to a change of said at least one weight, computing by said processor said current level of risk of said role in said computer system based on said at least one value and said changed at least one weight of said at least one risk factor.

4 . The method of claim 1 further comprising:

determining whether said current level of risk of said role exceeds a threshold, and

formulating mitigation risk strategies upon determining said current level of risk of said role exceeds said threshold.

5 . The method of claim 1 further comprising:

associating said at least one weight with said at least one risk factor to determine an influence degree of said at least one risk factor to said level of risk of said role.

6 . The method of claim 1 further comprising:

selecting said at least one risk factor from a group consisting of:

authorization risk factor determined based on access permissions of said role to resources in the computer system;

application access risk factor determined based on access of said role to critical applications;

inherent risk factor determined based on access of said role to conflicting transactions;

incidents risk factor determined based on violations of said role;

time sensitive risk factor determined based on time a transaction of said role occurs; and

outdated certification risk factor determined based on certification of said role.

7 . The method of claim 1 , wherein tracking by said at least one aggregator said at least one value of said at least one risk factor associated with said user role in said computer system further comprises:

extracting from said memory at least one data value of at least one attribute of said role by said at least one aggregator.

8 . A computer system to calibrate a level of risk of a role, the system including:

at least one processor and memory to execute program code related to:

at least one risk factor aggregator to track at least one value of at least one risk factor associated with said user role; and

a risk calibration engine to:

retrieve from said memory at least one weight associated with said at least one risk factor;

compute a current level of risk of said role based on said at least one value and said at least one weight of said at least one risk factor; and

indicate when said current level of risk is different compared to a stored level of risk of said role in said computer system.

9 . The computer system of claim 8 , wherein said at least one risk factor aggregator to update periodically in said memory said at least one value of said at least one risk factor.

10 . The computer system of claim 8 , wherein said risk calibration engine to:

in response to a change of said at least one weight, compute said current level of risk of said role based on said at least one value and said changed at least one weight of said at least one risk factor.

11 . The computer system of claim 8 , wherein said risk calibration engine to prioritize said role based on said risk level.

12 . The computer system of claim 8 , wherein said risk calibration engine to:

determine whether said current level of risk of said role exceeds a threshold; and

formulate mitigation risk strategies upon determining said current level of risk of said role exceeds said threshold.

13 . The computer system of claim 8 , wherein said at least one risk factor selected from a group consisting of:

authorization risk factor determined based on access permissions to resources of said role;

application access risk factor determined based on access of said role to critical applications;

inherent risk factor determined based on access of said role to conflicting transactions;

incidents risk factor determined based on violations of said role;

time sensitive risk factor determined based on time a transaction of said role occurs; and

outdated certification risk factor determined based on certification of said role.

14 . The computer system of claim 8 , wherein said at least one risk factor aggregator to extract from said memory at least one data value of at least one attribute of said role.

15 . A non-transitory computer readable medium storing instructions thereon, which when executed by a processor cause a computer system to:

track by at least one aggregator at least one value of at least one risk factor associated with a role in said computer system;

retrieve from a memory at least one weight associated with said at least one risk factor;

compute a current level of risk of said role in said computer system based on said at least one value and said at least one weight of said at least one risk factor; and

calibrate said current level of risk against a comparative level of risk of said role in said computer system.

16 . The computer readable medium of claim 15 storing instructions thereon, which when executed by said processor cause said computer system further to:

update in said memory said at least one value of said at least one risk factor by said at least one aggregator; and

in response to said update of said at least one value of said at least one risk factor, compute said current level of risk of said role in said computer system based on said updated at least one value and said at least one weight of said at least one risk factor.

17 . The computer readable medium of claim 15 storing instructions thereon, which when executed by said processor cause said computer system further to:

determine whether said current level of risk of said role exceeds a threshold, and

formulate mitigation risk strategies upon determining said current level of risk of said role exceeds said threshold.

18 . The computer readable medium of claim 15 storing instructions thereon, which when executed by said processor cause said computer system further to:

associate said at least one weight with said at least one risk factor to determine an influence degree of said at least one risk factor to said level of risk of said role.

19 . The computer readable medium of claim 15 storing instructions thereon, which when executed by said processor cause said computer system further to:

select said at least one risk factor from a group consisting of:

authorization risk factor determined based on access permissions of said role to resources in the computer system;

application access risk factor determined based on access of said role to critical applications;

inherent risk factor determined based on access of said role to conflicting transactions;

incidents risk factor determined based on violations of said role;

time sensitive risk factor determined based on time a transaction of said role occurs; and

outdated certification risk factor determined based on certification of said role.

20 . The computer readable medium of claim 15 , wherein tracking by said at least one aggregator said at least one value of said at least one risk factor associated with said user role in said computer system further comprises:

extracting from said memory at least one data value of at least one attribute of said role by said at least one aggregator.

Assignments (2)
CHANGE OF NAME Recorded Aug 26, 2014
From: SAP AG
To: SAP SE
Reel/Frame 033625/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2012
From: ARUMUGAM, SAYEKUMAR; ERUKULLA, RAVIKANTH; RADKOWSKI, JOHN CHRISTOPHER
To: SAP AG
Reel/Frame 027924/0204 →