IP Library Granted Patent US 11,962,597
Granted Patent B2
US 11,962,597 · App. 17/825,545 · Granted Apr 16, 2024

System and method for outlier and anomaly detection in identity management artificial intelligence systems using cluster based analysis of network identity graphs

Inventors: Mohamed M. Badawy (Round Rock, TX); Jostine Fei Ho (Austin, TX)
Assignee: SAILPOINT TECHNOLOGIES, INC.
H04L63/102G06F16/9024H04L63/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,962,597
App. No.
17/825,545
Granted
Apr 16, 2024
Kind
B2
Abstract

Systems and methods for artificial intelligence systems for identity management systems are disclosed. Embodiments may perform outlier detection and risk assessment based on identity management data, including one or more property graphs or peer groups determined from those property graphs, to determine identity management artifacts with ‘abnormal’ patterns when compared to other related identity management artifacts.

Claims (51)

1. An identity management system for risk assessment using graphs, comprising:

a memory;

a processor;

a non-transitory, computer-readable storage medium including instructions executable by the processor for:

accessing identity management data obtained from one or more source systems of an enterprise;

evaluating the accessed identity management data to determine a set of identity management artifacts associated with a set of identities and at least one entitlement, utilized in identity management in association with the enterprise;

generating an identity management graph from the identity management data by:

creating nodes of the identity management graph by creating a node of the identity management graph for each of the determined identity management artifacts associated with the determined set of identities,

creating edges of the identity management graph between nodes of the identity management graph representing the determined identity management artifacts, the creating including pruning one or more edges, and

generating weights for created edges of the identity management graph, based on the created nodes associated with the created edges in accordance with the associated set of identities or at least one entitlement;

storing the identity management graph in a data store;

analyzing the identity management graph or the identity management data to identify an anomaly; and

identifying an identity management artifact associated with the identified anomaly as a high risk identity management artifact.

2. The system of claim 1 , wherein the analysis of the identity management graph comprises dynamic analysis.

3. The system of claim 2 , wherein the dynamic analysis comprises comparing the identity management graph or identity management data with a predicted identity management graph or predicted identity management data.

4. The system of 1 , wherein the instructions are further for presenting an interface depicting a representation of the identity management graph, identity management data or anomaly to a user.

5. The system of claim 4 , wherein the instructions are further for presenting a recommendation associated with the identity management artifact to a user.

6. The system of claim 1 , wherein the instructions are further for generating an alert to a user based on the identified anomaly.

7. The system of claim 6 , wherein the alert is generated based on a threshold for an assessment metric utilized in identifying the anomaly.

8. A method for risk detection using an identity management graph comprising:

accessing identity management data obtained from one or more source systems of an enterprise;

evaluating the accessed identity management data to determine a set of identity management artifacts associated with a set of identities and at least one entitlement, utilized in identity management in association with the enterprise;

generating an identity management graph from the identity management data by:

creating nodes of the identity management graph by creating a node of the identity management graph for each of the determined identity management artifacts associated with the determined set of identities,

creating edges identity management graph between nodes of the identity management graph representing the determined identity management artifacts, the creating including pruning one or more edges, and

generating weights for created edges of the identity management graph, based on the created nodes associated with the created edges in accordance with the associated set of identities or at least one entitlement;

storing the identity management graph in a data store;

analyzing the identity management graph or the identity management data to identify an anomaly; and

identifying an identity management artifact associated with the identified anomaly as a high risk identity management artifact.

9. The method of claim 8 , wherein the analysis of the identity management graph comprises dynamic analysis.

10. The method of claim 9 , wherein the dynamic analysis comprises comparing the identity management graph or identity management data with a predicted identity management graph or predicted identity management data.

11. The method of 8 , further comprising presenting an interface depicting a representation of the identity management graph, identity management data or anomaly to a user.

12. The method of claim 11 , further comprising presenting a recommendation associated with the identity management artifact to a user.

13. The method of claim 8 , further comprising generating an alert to a user based on the identified anomaly.

14. The method of claim 13 , wherein the alert is generated based on a threshold for an assessment metric utilized in identifying the anomaly.

15. A non-transitory computer readable storage medium, comprising instructions for risk detection using an identity management graph executable by a processor for:

accessing identity management data obtained from one or more source systems of an enterprise;

evaluating the accessed identity management data to determine a set of identity management artifacts associated with a set of identities and at least one entitlement, utilized in identity management in association with the enterprise;

generating an identity management graph from the identity management data by:

creating nodes of the identity management graph by creating a node of the identity management graph for each of the determined identity management artifacts associated with the determined set of identities,

creating edges of the identity management graph between nodes of the identity management graph representing the determined identity management artifacts, the creating including pruning one or more edges, and

generating weights for created edges of the identity management graph, based on the created nodes associated with the created edges in accordance with the associated set of identities or at least one entitlement;

storing the identity management graph in a data store;

analyzing the identity management graph or the identity management data to identify an anomaly; and

identifying an identity management artifact associated with the identified anomaly as a high risk identity management artifact.

16. The non-transitory computer readable storage medium of claim 15 , wherein the analysis of the identity management graph comprises dynamic analysis.

17. The non-transitory computer readable storage medium of claim 16 , wherein the dynamic analysis comprises comparing the identity management graph or identity management data with a predicted identity management graph or predicted identity management data.

18. The non-transitory computer readable storage medium of 15 , wherein the instructions are further for presenting an interface depicting a representation of the identity management graph, identity management data or anomaly to a user.

19. The non-transitory computer readable storage medium of claim 18 , wherein the instructions are further for presenting a recommendation associated with the identity management artifact to a user.

20. The non-transitory computer readable storage medium of claim 15 , wherein the instructions are further for generating an alert to a user based on the identified anomaly.

21. The non-transitory computer readable storage medium of claim 20 , wherein the alert is generated based on a threshold for an assessment metric utilized in identifying the anomaly.

Assignments (2)
PATENT SECURITY AGREEMENT Recorded Jun 25, 2025
From: SAILPOINT TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071724/0511 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2022
From: BADAWY, MOHAMED M.; HO, JOSTINE FEI
To: SAILPOINT TECHNOLOGIES, INC.
Reel/Frame 060088/0012 →
Continuity (4)
Continuation 16861335 · Apr 29, 2020
Continuation 16691998 · Nov 22, 2019
Provisional Application 62771889 · Nov 27, 2018
Related Publication 20220360587A1 · Nov 10, 2022
Cited By (3)
US 12,254,422 US 12,294,584 US 12,413,594