Identity power scoring system for cloud environments
Systems and methods for providing an identity power scoring system for cloud environments. Various embodiments include defining a plurality of admin categories associated with a cloud environment; deriving a category power score of an identity for each of the plurality of admin categories; and calculating a global power score of the identity based on the power score for each of the plurality of admin categories. The scoring system helps identify and prioritize risk associated with specific identities, allowing more optimized methods of protection for information in the cloud-based system.
1 . A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors of a multi-tenant, zero-trust cloud-based security system providing inline monitoring and dynamic security policy enforcement between users and cloud services to perform steps of:
defining a plurality of admin categories for identities within a tenant cloud environment, wherein each admin category is defined by a list of one or more relevant cloud services and an associated entitlement schema comprising all possible action-resource pairs representing operational privileges specific to the tenant cloud environment;
deriving a privilege-based category power score of an identity for each of the plurality of admin categories by expanding all cloud entitlements available to the identity within each admin category, wherein the entitlements comprise action-resource pairs defining specific operational permissions, and calculating a percentage representing the identity's assigned entitlements relative to all possible entitlements available in each respective admin category, wherein each category power score quantifies the extent of the identity's administrative control or privilege coverage within that admin category and is independent of risk, behavioral, or event data associated with the identity; and
calculating and compiling at the cloud-based security system and responsive to real-time security policy enforcement conditions, a global power score of the identity based on weighted combination of the category power scores, wherein the global power score represents an aggregate measure of the identity's potential privilege impact across the tenant cloud environment, distinct from behavioral or risk-based scoring, and wherein the global power score dynamically and automatically adjusts zero-trust security policies governing the identity's cloud resource access in response to changes in calculated power scores.
2 . The non-transitory computer-readable medium of claim 1 , wherein the steps further comprise:
assessing privilege-based risk associated with the cloud environment based on the global power score of the identity.
3 . The non-transitory computer-readable medium of claim 1 , wherein the identity is one of human or non-human based on the global power score.
4 . The non-transitory computer-readable medium of claim 1 , wherein the steps further comprise:
utilizing the global power score as a token or parameter to provide custom rules or adaptive zero-trust access policies for the identity in the cloud environment.
5 . The non-transitory computer-readable medium of claim 1 , wherein the steps further comprise:
assessing the severity of an incident involving the identity based on the global power score.
6 . The non-transitory computer-readable medium of claim 1 , wherein the category power score is based on a percentage of entitlements the identity has, in relation to all the possible entitlements in the cloud environment.
7 . The non-transitory computer-readable medium of claim 1 , wherein the category power score is based on a percentage of resources the identity has access to, in relation to all resources in the cloud environment.
8 . The non-transitory computer-readable medium of claim 1 , wherein each of the plurality of admin categories includes a plurality of cloud services, and the steps further comprise:
deriving a category power score of an identity for each of the plurality of admin categories based on one or more service scores associated with each of the plurality of admin categories.
9 . The non-transitory computer-readable medium of claim 8 , wherein the category power scores are derived based on a weighted system, wherein each cloud service is assigned a weight based on importance.
10 . The non-transitory computer-readable medium of claim 1 , wherein a threshold is defined for any category power score which causes the identity to be considered an admin in that category.
11 . A method, implemented by a multi-tenant, zero-trust cloud-based security system providing inline monitoring and dynamic security policy enforcement between users and cloud services, the method comprising steps of:
defining a plurality of admin categories for identities within a tenant cloud environment, wherein each admin category is defined by a list of one or more relevant cloud services and an associated entitlement schema comprising all possible action-resource pairs representing operational privileges specific to the tenant cloud environment;
deriving a privilege-based category power score of an identity for each of the plurality of admin categories by expanding all cloud entitlements available to the identity within each admin category, wherein the entitlements comprise action-resource pairs defining specific operational permissions, and calculating a percentage representing the identity's assigned entitlements relative to all possible entitlements available in each respective admin category wherein each category power score quantifies the extent of the identity's administrative control or privilege coverage within that admin category and is independent of risk, behavioral, or event data associated with the identity; and
calculating and compiling at the cloud-based security system and responsive to real-time security policy enforcement conditions, a global power score of the identity based on weighted combination of the category power scores, wherein the global power score represents an aggregate measure of the identity's potential privilege impact across the tenant cloud environment, distinct from behavioral or risk-based scoring, and wherein the global power score dynamically and automatically adjusts zero-trust security policies governing the identity's cloud resource access in response to changes in calculated power scores.
12 . The method of claim 11 , wherein the steps further comprise:
assessing privilege-based risk associated with the cloud environment based on the global power score of the identity.
13 . The method of claim 11 , wherein the identity can be is one of human or non-human.
14 . The method of claim 11 , wherein the steps further comprise:
utilizing the global power score as a token or parameter to provide custom rules or adaptive zero-trust access policies for the identity in the cloud environment.
15 . The method of claim 11 , wherein the steps further comprise:
assessing the severity of an incident involving the identity based on the global power score.
16 . The method of claim 11 , wherein the category power score is based on a percentage of entitlements the identity has, in relation to all the possible entitlements in the cloud environment.
17 . The method of claim 11 , wherein the category power score is based on a percentage of resources the identity has access to, in relation to all resources in the cloud environment.
18 . The method of claim 11 , wherein each of the plurality of admin categories includes a plurality of cloud services, and the steps further comprise:
deriving a category power score of an identity for each of the plurality of admin categories based on one or more service scores associated with each of the plurality of admin categories.
19 . The method of claim 18 , wherein the category power scores are derived based on a weighted system, wherein each cloud service is assigned a weight based on importance.
20 . The method of claim 11 , wherein a threshold is defined for any category power score which causes the identity to be considered an admin in that category.