Analyzing aggregated event data to identify and address permissions issues
A computerized method analyzes permissions and identifies permission insights. A group of event records is obtained from a data source and a subgroup of event records associated with a user is identified in the obtained group of event records. The identified subgroup of event records is mapped to a group of required permissions using a permission hierarchy and a group of granted permissions of the user are identified. It is determined that the group of granted permissions of the user differs from the group of required permissions to which the subgroup of event records is mapped using the permission hierarchy. A permission insight action is performed based on determining that the group of granted permissions of the user differs from the group of required permissions. Thus, the method enables comprehensive analysis of permissions using data from multiple data sources to generate a single set of possible permission issues or insights.
1 . A system comprising:
a processor; and
a memory comprising computer program code, the memory and the computer program code configured to cause the processor to:
obtain a group of event records in parallel from a plurality of data sources through a plurality of parallel data ingestion threads, the group of event records being stored in a plurality of different data formats of the plurality of data sources;
identify a subgroup of event records associated with a user in the obtained group of event records;
normalize the identified subgroup of event records from the plurality of different data formats into normalized event records in a standardized event record format, wherein normalizing includes identifying, for each event record of the subgroup of event records, a permissions associated with occurrence of an event of the event record;
map the identified subgroup of normalized event records to a group of required permissions using a permission hierarchy;
identify a group of granted permissions of the user;
determine that the group of granted permissions of the user differs from the group of required permissions to which the identified subgroup of normalized event records is mapped; and
perform a permission insight action based on determining that the group of granted permissions of the user differs from the group of required permissions.
2 . The system of claim 1 , wherein the normalized event record format includes an indicator that indicates minimum permissions required to cause an event of the associated event record.
3 . The system of claim 1 , wherein performing the permission insight action includes generating a permission report including information associated with the group of granted permissions of the user and the group of required permissions.
4 . The system of claim 1 , wherein performing the permission insight action includes sending instructions for changing permissions of the user to a system with which a data source of the plurality of data sources is associated.
5 . The system of claim 1 , wherein the memory and the computer program code are configured to further cause the processor to:
provide an interface for receiving a user-defined permission hierarchy; and
receive the permission hierarchy via the provided interface.
6 . The system of claim 1 , wherein mapping the identified subgroup of normalized event records to the group of required permissions associated with the permission hierarchy includes generating an event permission map, including:
mapping a user identifier of the user to an event collection data structure;
populating the event collection data structure with event entries associated with the identified subgroup of normalized event records associated with the user;
mapping each event entry of the event collection data structure to a required permission collection data structure; and
populating each required permission collection data structure with the group of required permissions.
7 . The system of claim 1 , wherein identifying the group of granted permissions of the user includes identifying granted permissions of a current permission grouping that is assigned to the user;
wherein determining that the group of granted permissions of the user differs from the group of required permissions to which the identified subgroup of normalized event records is mapped further includes determining a recommended permission grouping that includes the group of required permissions; and
wherein performing the permission insight action includes generating a recommendation indicating the recommended permission grouping in association with the user.
8 . A computerized method comprising:
obtaining a group of event records in parallel from a plurality of data sources through a plurality of parallel data ingestion threads, the group of event records being stored in a plurality of different data formats of the plurality of data sources;
identifying a subgroup of event records associated with a user in the obtained group of event records;
normalizing the identified subgroup of event records from the plurality of different data formats into normalized event records in a standardized event record format, wherein normalizing includes identifying, for each event record of the subgroup of event records, a permissions associated with occurrence of an event of the event record;
mapping the identified subgroup of normalized event records to a group of required permissions using a permission hierarchy;
identifying a group of granted permissions of the user;
determining that the group of granted permissions of the user is more permissive than the group of required permissions to which the identified subgroup of normalized event records is mapped using the permission hierarchy; and
performing a permission insight action based on determining that the group of granted permissions of the user is more permissive than the group of required permissions.
9 . The computerized method of claim 8 , wherein the normalized event record format includes an indicator that indicates minimum permissions required to cause an event of the associated event record.
10 . The computerized method of claim 8 , wherein performing the permission insight action includes generating a permission report including information associated with the group of granted permissions of the user and the group of required permissions.
11 . The computerized method of claim 8 , wherein performing the permission insight action includes sending instructions for changing permissions of the user to a system with which a data source of the plurality of data sources is associated.
12 . The computerized method of claim 8 , further comprising:
providing an interface for receiving a user-defined permission hierarchy; and
receiving the permission hierarchy via the provided interface.
13 . The computerized method of claim 8 , wherein mapping the identified subgroup of normalized event records to the group of required permissions associated with the permission hierarchy includes generating an event permission map, including:
mapping a user identifier of the user to an event collection data structure;
populating the event collection data structure with event entries associated with the identified subgroup of normalized event records associated with the user;
mapping each event entry of the event collection data structure to a required permission collection data structure; and
populating each required permission collection data structure with the group of required permissions.
14 . The computerized method of claim 8 , wherein identifying the group of granted permissions of the user includes identifying granted permissions of a current permission grouping that is assigned to the user;
wherein determining that the group of granted permissions of the user is more permissive than the group of required permissions to which the identified subgroup of normalized event records is mapped further includes determining a recommended permission grouping that includes the group of required permissions; and
wherein performing the permission insight action includes generating a recommendation indicating the recommended permission grouping in association with the user.
15 . A computer storage medium has computer-executable instructions that, upon execution by a processor, cause the processor to at least:
obtain a group of event records in parallel from a plurality of data sources through a plurality of parallel data ingestion threads, the group of event records being stored in a plurality of different data formats of the plurality of data sources;
identify a subgroup of event records associated with a user in the obtained group of event records;
normalize the identified subgroup of event records from the plurality of different data formats into normalized event records in a standardized event record format, wherein normalizing includes identifying, for each event record of the subgroup of event records, a permissions associated with occurrence of an event of the event record;
map the identified subgroup of normalized event records to a group of required permissions using a permission hierarchy;
identify a group of granted permissions of the user;
determine that the group of granted permissions of the user is less permissive than the group of required permissions to which the identified subgroup of normalized event records is mapped using the permission hierarchy; and
perform a permission insight action based on determining that the group of granted permissions of the user is less permissive than the group of required permissions.
16 . The computer storage medium of claim 15 , wherein the normalized event record format includes an indicator that indicates minimum permissions required to cause an event of the associated event record.
17 . The computer storage medium of claim 15 , wherein performing the permission insight action includes generating a permission report including information associated with the group of granted permissions of the user and the group of required permissions.
18 . The computer storage medium of claim 15 , wherein performing the permission insight action includes sending instructions for changing permissions of the user to a system with which a data source of the plurality of data sources is associated.
19 . The computer storage medium of claim 15 , wherein the computer-executable instructions, upon execution by the processor, further cause the processor to at least:
provide an interface for receiving a user-defined permission hierarchy; and
receive the permission hierarchy via the provided interface.
20 . The computer storage medium of claim 15 , wherein mapping the identified subgroup of normalized event records to the group of required permissions associated with the permission hierarchy includes generating an event permission map, including:
mapping a user identifier of the user to an event collection data structure;
populating the event collection data structure with event entries associated with the identified subgroup of normalized event records associated with the user;
mapping each event entry of the event collection data structure to a required permission collection data structure; and
populating each required permission collection data structure with the group of required permissions.