IP Library Granted Patent US 12,282,546
Granted Patent B2
US 12,282,546 · App. 17/516,183 · Granted Apr 22, 2025

Abnormal classic authorization detection systems

Inventors: Idan Hen (Tel-Aviv, IL); Ilay Grossman (Tel-Aviv, IL); Avichai Ben David (Tel-Aviv, IL)
Assignee: Microsoft Technology Licensing, LLC
G06F21/554G06F2221/034H04L63/1416H04L63/1425H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,282,546
App. No.
17/516,183
Granted
Apr 22, 2025
Kind
B2
Abstract

A system to detect an abnormal classic authorizations, such as in a classic authorization system of a resource access management system, and take action is described. The system determines an anomaly score in from a model applied to a classic assignment event. An indicator score is determined from the classic assignment event applied to domain-based rules. The security action is taken based on a combination of the anomaly score and the indicator score.

Claims (40)

1. A method to provide cybersecurity to a classic authorization system of a resource access management system, the method comprising:

determining an anomaly score by applying a model to a first log, a second log, and a third log regarding a classic assignment event in which a classic administrator role is assigned to a user,

wherein the first log describes the classic assignment event from a perspective of an assignor who assigns the classic administrator role to the user,

wherein the second log describes the classic assignment event from a perspective of the user to whom the classic administrator role is assigned, and

wherein the third log describes the classic assignment event from a perspective of a subscription in a resource access management system;

determining an indicator score by applying domain-based rules to the classic assignment event in which the classic administrator role is assigned to the user; and

taking a security action based on a combination of the anomaly score, which is determined using the model, and the indicator score, which is determined using the domain-based rules.

2. The method of claim 1 , wherein the determining the anomaly score and the determining the indicator score are based on receiving logs from the resource access management system.

3. The method of claim 2 , wherein the resource access management system comprises a fine-grained authorization system.

4. The method of claim 1 , wherein the security action is based on comparing the anomaly score and the indicator score to a selected threshold.

5. The method of claim 4 , wherein the security action comprises a plurality of actions and the selected threshold comprises a plurality of selected thresholds.

6. The method of claim 5 , wherein an action of the plurality of actions is associated with comparing the anomaly score and the indicator score to two thresholds of the plurality of selected thresholds.

7. The method of claim 1 , wherein a rule of the domain-based rules comprises a determination as to whether an operation was successful.

8. The method of claim 1 , wherein the classic assignment event comprises an assignment of a co-administrator role to the user, the co-administrator role granting the user permission to manage services in a platform portal of the resource access management system.

9. The method of claim 8 , wherein the classic assignment event comprises the assignment of the co-administrator role to the user from another user having a co-administrator role.

10. The method of claim 1 , wherein the anomaly score and the indicator score are combined to form a final security score.

11. The method of claim 1 , wherein the classic administrator role grants full access to the subscription in the resource access management system to the user.

12. A computer readable storage device to store computer executable instructions to control a processor to:

determine an anomaly score by applying a model to a first log, a second log, and a third log regarding a classic assignment event in which a classic administrator role is assigned to a user,

wherein the first log describes the classic assignment event from a perspective of an assignor who assigns the classic administrator role to the user,

wherein the second log describes the classic assignment event from a perspective of the user to whom the classic administrator role is assigned, and

wherein the third log describes the classic assignment event from a perspective of a subscription in a resource access management system;

determine an indicator score by applying domain-based rules to the classic assignment event in which the classic administrator role is assigned to the user; and

take a security action based on a combination of the anomaly score, which is determined using the model, and the indicator score, which is determined using the domain-based rules.

13. The computer readable storage device of claim 12 , comprising a machine learning model to determine the anomaly score.

14. The computer readable storage device of claim 13 , wherein the anomaly score is based on an irregular set of classic assignment events and a relative amount of permissions.

15. The computer readable storage device of claim 12 , wherein the security action comprises providing a security alert.

16. The computer readable storage device of claim 12 , wherein the security action is based on a plurality of available actions that are related to the combination of the anomaly score and the indicator score.

17. The computer readable storage device of claim 12 , wherein the classic administrator role is configured to grant full access to the subscription in the resource access management system to the user.

18. A system, comprising:

a memory device that stores a set of instructions; and

a processor to execute the set of instructions to:

determine an anomaly score by applying a model to a first log, a second log, and a third log regarding a classic assignment event in which a classic administrator role is assigned to a user,

wherein the first log describes the classic assignment event from a perspective of an assignor who assigns the classic administrator role to the user,

wherein the second log describes the classic assignment event from a perspective of the user to whom the classic administrator role is assigned, and

wherein the third log describes the classic assignment event from a perspective of a subscription in a resource access management system;

determine an indicator score by applying domain-based rules to the classic assignment event in which the classic administrator role is assigned to the user; and

take a security action based on a combination of the anomaly score, which is determined using the model, and the indicator score, which is determined using the domain-based rules.

19. The system of claim 18 comprised in a cloud-based environment, wherein the cloud-based environment comprises an identity access management system.

20. The system of claim 18 , wherein the classic administrator role is configured to grant full access to a subscription in the resource access management system to the user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2021
From: HEN, IDAN; GROSSMAN, ILAY; DAVID, AVICHAI BEN
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 057984/0681 →
Continuity (1)
Related Publication 20230132611A1 · May 4, 2023
References Cited (8)
US 11620481B2 · Givental · 2023 [cited by examiner]
US 20170111381A1 · Jones · 2017 [cited by examiner]
US 20200285737A1 · Kraus · 2020 [cited by examiner]
US 20210117868A1 · Sriharsha · 2021 [cited by examiner]
US 20210194913A1 · Hecht · 2021 [cited by examiner]
“Recent Progress of Anomaly Detection”—Xu et al, Wiley/Online Library, Jan. 13, 2019 https://onlinelibrary.wiley.com/doi/epdf/10.1155/2019/2686378 (Year: 2019). [cited by examiner]
“Calculating Anomaly Score for Anomaly Detection Using One-Class SVM”—Stack Overflow, Dec. 28, 2018 https://stackoverflow.com/questions/53956538/calculating-anomaly-score-for-anomaly-detection-using-one-class-svm (Year:… [cited by examiner]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US22/044777”, Mailed Date: Jan. 10, 2023, 11 Pages. [cited by applicant]