Systems and Methods for Security Monitoring Through Dynamically Controlled Context-Based Access
The disclosure provides a computer-implemented method including operations of detecting one or more access request queries on a nodal graph, wherein the nodal graph includes nodes representing entities from a plurality of data sources and relationships between the entities, responsive to detecting the one or more access request queries, querying the nodal graph for one or more security rules, evaluating the one or more security rules against the nodal graph in view of historical access requests resulting in detection of a defined behavior, and initiating performance of one or more automated access management actions in response to the detection of the defined behavior. Additionally, one or more access request queries may correspond to requests from a protected system for a determination as to whether a first user has permission to access data of the protected system.
1 . A computer-implemented method, comprising:
detecting one or more access request queries on a nodal graph, wherein the nodal graph includes nodes representing entities from a plurality of data sources and relationships between the entities;
responsive to detecting the one or more access request queries, querying the nodal graph for one or more security rules;
evaluating the one or more security rules against the nodal graph in view of historical access requests resulting in detection of a defined behavior; and
initiating performance of one or more automated access management actions in response to the detection of the defined behavior.
2 . The computer-implemented method of claim 1 , wherein the one or more access request queries correspond to requests from a protected system for a determination as to whether a first user has permission to access data of the protected system.
3 . The computer-implemented method of claim 1 , wherein at least a subset of the one or more security rules are configured to detect the defined behavior, wherein the defined behavior corresponds to suspicious or anomalous access requests.
4 . The computer-implemented method of claim 1 , wherein a first automated access management action of the one or more automated access management actions includes revoking a user session of a first user for a software application, denying access to the first user to a resource, or requiring the first user to reauthenticate with the software application, wherein the first user is indicated in the one or more access request queries.
5 . The computer-implemented method of claim 1 , wherein querying the nodal graph for the one or more security rules is based on a first user to which the one or more access request queries correspond, a group to which the first belongs, or an organization that employs the first user.
6 . The computer-implemented method of claim 1 , wherein evaluating the one or more security rules against the nodal graph in view of the historical access requests includes determining whether a number of access requests have been made by a first user within a predetermined time frame.
7 . The computer-implemented method of claim 1 , wherein evaluating the one or more security rules against the nodal graph in view of the historical access requests includes determining whether a number of access requests have been made by a first user for a type of action to one or more assets within a predetermined time frame.
8 . A computing device, comprising:
a processor; and
a non-transitory computer-readable medium having stored thereon instructions that, when executed by the processor, cause the processor to perform operations including:
detecting one or more access request queries on a nodal graph, wherein the nodal graph includes nodes representing entities from a plurality of data sources and relationships between the entities,
responsive to detecting the one or more access request queries, querying the nodal graph for one or more security rules,
evaluating the one or more security rules against the nodal graph in view of historical access requests resulting in detection of a defined behavior, and
initiating performance of one or more automated access management actions in response to the detection of the defined behavior.
9 . The computing device of claim 8 , wherein the one or more access request queries correspond to requests from a protected system for a determination as to whether a first user has permission to access data of the protected system.
10 . The computing device of claim 8 , wherein at least a subset of the one or more security rules are configured to detect the defined behavior, wherein the defined behavior corresponds to suspicious or anomalous access requests.
11 . The computing device of claim 8 , wherein a first automated access management action of the one or more automated access management actions includes revoking a user session of a first user for a software application, denying access to the first user to a resource, or requiring the first user to reauthenticate with the software application, wherein the first user is indicated in the one or more access request queries.
12 . The computing device of claim 8 , wherein querying the nodal graph for the one or more security rules is based on a first user to which the one or more access request queries correspond, a group to which the first belongs, or an organization that employs the first user.
13 . The computing device of claim 8 , wherein evaluating the one or more security rules against the nodal graph in view of the historical access requests includes determining whether a number of access requests have been made by a first user within a predetermined time frame.
14 . The computing device of claim 8 , wherein evaluating the one or more security rules against the nodal graph in view of the historical access requests includes determining whether a number of access requests have been made by a first user for a type of action to one or more assets within a predetermined time frame.
15 . A non-transitory computer-readable medium having stored thereon instructions that, when executed by one or more processors, cause the one or more processor to perform operations including:
detecting one or more access request queries on a nodal graph, wherein the nodal graph includes nodes representing entities from a plurality of data sources and relationships between the entities;
responsive to detecting the one or more access request queries, querying the nodal graph for one or more security rules;
evaluating the one or more security rules against the nodal graph in view of historical access requests resulting in detection of a defined behavior; and
initiating performance of one or more automated access management actions in response to the detection of the defined behavior.
16 . The non-transitory computer-readable medium of claim 15 , wherein the one or more access request queries correspond to requests from a protected system for a determination as to whether a first user has permission to access data of the protected system.
17 . The non-transitory computer-readable medium of claim 15 , wherein at least a subset of the one or more security rules are configured to detect the defined behavior, wherein the defined behavior corresponds to suspicious or anomalous access requests.
18 . The non-transitory computer-readable medium of claim 15 , wherein a first automated access management action of the one or more automated access management actions includes revoking a user session of a first user for a software application, denying access to the first user to a resource, or requiring the first user to reauthenticate with the software application, wherein the first user is indicated in the one or more access request queries.
19 . The non-transitory computer-readable medium of claim 15 , wherein querying the nodal graph for the one or more security rules is based on a first user to which the one or more access request queries correspond, a group to which the first belongs, or an organization that employs the first user.
20 . The non-transitory computer-readable medium of claim 15 , wherein evaluating the one or more security rules against the nodal graph in view of the historical access requests includes determining whether a number of access requests have (i) been made by a first user within a first predetermined time frame, or (ii) been made by the first user for a type of action to one or more assets within a second predetermined time frame.