IP Library › Granted Patent US 12,242,600
Granted Patent B2
US 12,242,600 · App. 17/320,010 · Granted Mar 4, 2025

Abnormally permissive role definition detection systems

Inventors: Idan Yehoshua Hen (Tel-Aviv, IL); Ilay Grossman (Tel-Aviv, IL); Avichai Ben David (Tel-Aviv, IL)
Assignee: Microsoft Technology Licensing, LLC
G06F21/554G06N5/04G06N20/00G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,242,600
App. No.
17/320,010
Granted
Mar 4, 2025
Kind
B2
Abstract

A system to detect an abnormally permissive role definition, which can include an abnormally permissive custom role definition, and take action is described. The system receives a role definition for a security principal over a scope of resources in which the role definition includes a built-in role and a custom role. Permissions of the role definition and a creation event of the role definition are analyzed. A security score based on the role definition and creation event for the scope of resources is determined. An action is taken based on the security score and the creation event analysis.

Claims (48)

1. A method to provide cybersecurity, the method comprising:

receiving a role definition, which is based on a schema, for a security principal regarding a scope of resources, the role definition including a first role definition, which defines a first permission based on a first element that is preassigned to the schema, and a second role definition, which defines a second permission based on a second element that is not preassigned to the schema;

determining a security score by providing permissions of the role definition, which include at least the first permission and the second permission, and a creation event, which indicates a circumstance of creation of the role definition, as inputs to a machine learning model, which causes the machine learning model to determine that the creation event is an irregular role definition creation event, to determine that the permissions of the role definition correspond to a relatively high amount of permission, and to generate the security score by taking into consideration that the creation event is the irregular role definition creation event and further by taking into consideration that the permissions of the role definition correspond to the relatively high amount of permission;

comparing the security score to a plurality of security score ranges that are defined by a plurality of thresholds and that correspond to a plurality of actions,

the plurality of thresholds comprising a first threshold and a second threshold that is less than the first threshold,

the plurality of actions comprising a first action in which access to a resource in the scope of resources is provided, a second action in which conditional access to the resource is provided, and a third action in which access to the resource is denied,

the plurality of security score ranges comprising a first security score range that is greater than the first threshold and that corresponds to the first action, a second security score range that is less than the first threshold and greater than the second threshold and that corresponds to the second action, and a third security score range that is less than the second threshold and that corresponds to the third action; and

denying access to the resource by selecting the third action from the plurality of actions as a result of the security score being included in the third security score range.

2. The method of claim 1 , wherein the analyzing is based on logs that are received from a role-based access controller.

3. The method of claim 1 , wherein determining the security score comprises:

causing the machine learning model to analyze the creation event using rule-based logic.

4. The method of claim 3 , wherein the security score is based at least on a difference between the first permission and the second permission.

5. The method of claim 1 , wherein the plurality of thresholds comprises two thresholds, the two thresholds comprising the first threshold and the second threshold.

6. The method of claim 1 , wherein determining the security score comprises:

causing the machine learning model to analyze allowed operations in the schema.

7. The method of claim 6 , wherein the schema includes operations of actions, notActions, dataActions, and notDataActions.

8. The method of claim 1 , wherein the machine learning model is trained on features that are based on permissions of role definitions and creation events for multiple scopes of resources.

9. The method of claim 1 , wherein analyzing the creation event comprises:

determining how often a creator of the role definition, who is indicated by the creation event, creates role definitions.

10. A computer readable storage device to store computer executable instructions to control a processor to:

receive a role definition, which is based on a schema, for a security principal regarding a scope of resources, the role definition including a first role definition, which defines a first permission based on a first element that is preassigned to the schema, and a second role definition, which defines a second permission based on a second element that is not preassigned to the schema;

determine a security score by providing permissions of the role definition, which include at least the first permission and the second permission, and a creation event, which indicates a circumstance of creation of the role definition, as inputs to a machine learning model, which causes the machine learning model to generate the security score by taking into consideration a determination by the machine learning model that the creation event is an irregular role definition creation event and further by taking into consideration a determination by the machine learning model that the permissions of the role definition correspond to a relatively high amount of permission;

compare the security score to a plurality of security score ranges that are defined by a plurality of thresholds and that correspond to a plurality of actions,

the plurality of thresholds comprising a first threshold and a second threshold that is less than the first threshold,

the plurality of actions comprising a first action in which access to a resource in the scope of resources is provided, a second action in which conditional access to the resource is provided, and a third action in which access to the resource is denied,

the plurality of security score ranges comprising a first security score range that is greater than the first threshold and that corresponds to the first action, a second security score range that is less than the first threshold and greater than the second threshold and that corresponds to the second action, and a third security score range that is less than the second threshold and that corresponds to the third action; and

provide access to the resource by selecting the first action from the plurality of actions as a result of the security score being included in the first security score range.

11. The computer readable storage device of claim 10 , wherein the computer executable instructions are to control the processor to cause the machine learning model to analyze operations in the schema.

12. The computer readable storage device of claim 10 , wherein the computer executable instructions are to control the processor to:

based on the security score reaching a threshold, prevent the access to the resource or provide the conditional access to the resource.

13. The computer readable storage device of claim 10 , wherein the machine learning model is trained on features that are based on permissions of role definitions and creation events for multiple scopes of resources.

14. The computer readable storage device of claim 10 , wherein the computer executable instructions are to control the processor to cause the machine learning model to analyze the creation event using rule-based logic.

15. A system, comprising:

a memory device to store a set of instructions; and

a processor to execute the set of instructions to:

receive a role definition, which is based on a schema, for a security principal regarding a scope of resources, the role definition including a first role definition, which defines a first permission based on a first element that is preassigned to the schema, and a second role definition, which defines a second permission based on a second element that is not preassigned to the schema;

determine a security score by providing permissions of the role definition, which include at least the first permission and the second permission, and a creation event, which indicates a circumstance of creation of the role definition, as inputs to a machine learning model, which causes the machine learning model to generate the security score by taking into consideration a determination by the machine learning model that the creation event is an irregular role definition creation event and further by taking into consideration a determination by the machine learning model that the permissions of the role definition correspond to a relatively high amount of permission;

compare the security score to a plurality of security score ranges that are defined by a plurality of thresholds and that correspond to a plurality of actions,

the plurality of thresholds comprising a first threshold and a second threshold that is less than the first threshold,

the plurality of actions comprising a first action in which access to a resource in the scope of resources is provided, a second action in which conditional access to the resource is provided, and a third action in which access to the resource is denied,

the plurality of security score ranges comprising a first security score range that is greater than the first threshold and that corresponds to the first action, a second security score range that is less than the first threshold and greater than the second threshold and that corresponds to the second action, and a third security score range that is less than the second threshold and that corresponds to the third action; and

provide conditional access to the resource by selecting the second action from the plurality of actions as a result of the security score being included in the second security score range.

16. The system of claim 15 included in a cloud-based environment.

17. The system of claim 16 , wherein the cloud-based environment includes an identity access management system.

18. The system of claim 15 , wherein the creation event indicates a person who created the role definition.

19. The system of claim 15 , wherein the creation event indicates when the role definition was created.

20. The system of claim 15 , wherein the processor is to execute the set of instructions to:

determine the security score by providing the permissions of the role definition and the creation event for the scope of resources as the inputs to the machine learning model, which causes the machine learning model to generate the security score based at least on the machine learning model determining that the creation event is the irregular role definition creation event and that the second permission defined by the second role definition corresponds to the relatively high amount of permission.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2021
From: HEN, IDAN YEHOSHUA; GROSSMAN, ILAY; DAVID, AVICHAI BEN
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 056235/0852 →
Continuity (1)
Related Publication 20220366039A1 · Nov 17, 2022
References Cited (40)
US 9424416B1 · Choudhary · 2016 [cited by examiner]
US 9471797B1 · Biller et al. · 2016 [cited by applicant]
US 10049227B1 · Sampson · 2018 [cited by examiner]
US 10346626B1 · Pratt · 2019 [cited by examiner]
US 10432637B2 · Kuehr-McLaren · 2019 [cited by examiner]
US 10862928B1 · Badawy · 2020 [cited by examiner]
US 11102204B1 · Jacques de Kadt · 2021 [cited by examiner]
US 11238383B2 · Mansour · 2022 [cited by examiner]
US 11240204B2 · Patil · 2022 [cited by examiner]
US 11575680B1 · Challey · 2023 [cited by examiner]
US 11722491B1 · Al-Rashid · 2023 [cited by examiner]
US 11770398B1 · Erlingsson · 2023 [cited by examiner]
US 11848827B1 · Haefner · 2023 [cited by examiner]
US 11886872B1 · Bienkowski · 2024 [cited by examiner]
US 20020026591A1 · Hartley · 2002 [cited by examiner]
US 20020184521A1 · Lucovsky · 2002 [cited by examiner]
US 20100325160A1 · Grebenik · 2010 [cited by examiner]
US 20110219425A1 · Xiong · 2011 [cited by examiner]
US 20140143149A1 · Aissi · 2014 [cited by examiner]
US 20140215604A1 · Giblin · 2014 [cited by examiner]
US 20140359692A1 · Chari et al. · 2014 [cited by applicant]
US 20170070527A1 · Bailey · 2017 [cited by examiner]
US 20170126650A1 · Hay · 2017 [cited by examiner]
US 20180097849A1 · Arquero · 2018 [cited by examiner]
US 20190260754A1 · Hecht · 2019 [cited by applicant]
US 20200028850A1 · Ouellette · 2020 [cited by examiner]
US 20200076818A1 · Krishnan · 2020 [cited by examiner]
US 20200135049A1 · Atencio · 2020 [cited by examiner]
US 20200364355A1 · Chen · 2020 [cited by examiner]
US 20200403996A1 · Parimi · 2020 [cited by examiner]
US 20200404010A1 · Costante · 2020 [cited by examiner]
US 20200412726A1 · Nevatia · 2020 [cited by examiner]
US 20210051153A1 · Bogdanich Espina · 2021 [cited by examiner]
US 20210099490A1 · Crabtree · 2021 [cited by examiner]
US 20210243190A1 · Bargury · 2021 [cited by examiner]
US 20220217156A1 · Wahbo · 2022 [cited by examiner]
US 20220269806A1 · Ben-Natan · 2022 [cited by examiner]
US 20230199025A1 · Xu · 2023 [cited by examiner]
Goet; Azure Sentinel: designing access and authorizations that meet the enterprise needs; 2019; retrieve from the Internet https://medium.com/wortell/azure-sentinel-designing-access-and-authorizations-that-meet-the-ente… [cited by examiner]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US22/025664”, Mailed Date: Jul. 25, 2022, 11 Pages. [cited by applicant]