Machine learning for identity access management
A computer readable medium, a system, and a method for providing data security through identity access management using a transaction classifier to classify transactions according to a set of transaction data associated with the transaction and mitigate abnormal transactions. The transaction classifier is trained using a set of training data and updated after each transaction. The identity access management may also include a mitigation policy that is used to determine a mitigation technique for each transaction.
1 . A method of threat mitigation for an identity access management system, the method comprising:
receiving transaction data relating to a transaction associated with a user account;
authorizing the user account based at least in part on user information associated with a user;
determining a transaction type of the transaction based on the transaction data;
determining, using a machine learning model, a threat level associated with the transaction based on the transaction data and the transaction type,
wherein the machine learning model is trained with training data comprising at least one of user data, access control policy, subject attributes, and environmental attributes;
responsive to determining the threat level, selecting a mitigation procedure from a stored mitigation policy based on the transaction type of the transaction and the threat level associated with the transaction;
applying the mitigation procedure to the transaction based on the transaction type; and
storing the transaction data, a first indication of the mitigation procedure, and a second indication of the threat level associated with the transaction in a transaction data store.
2 . The method of claim 1 , further comprising:
updating the stored mitigation policy based on the transaction data and the transaction type of the transaction.
3 . The method of claim 1 , further comprising:
accessing at least one of a multifactor authentication database, an identity governance database, and a privileged access management database via a data base communication connection.
4 . The method of claim 1 , further comprising:
determining one or more normal user values associated with normal user activity, wherein the one or more normal user values are used to classify a normal transaction.
5 . The method of claim 4 , further comprising:
identifying an abnormality associated with the transaction based on the transaction data using the machine learning model, wherein the abnormality is identified based on a disparity of the transaction with the one or more normal user values of the normal transaction.
6 . The method of claim 1 , wherein the mitigation procedure comprises locking the user account to prevent access.
7 . The method of claim 6 , further comprising:
identifying a lockout time period based on the threat level associated with the transaction, the lockout time period indicating a time period for which the user account is locked.
8 . The method of claim 1 , wherein the mitigation procedure further comprises:
checking a classification of the transaction;
updating the classification of the transaction with a new classification; and
retraining the machine learning model with the new classification.
9 . A method of threat mitigation for an identity access management system, the method comprising:
receiving transaction data relating to a transaction associated with a user account;
determining a transaction type of the transaction based on the transaction data;
determining, using a machine learning model, a threat level associated with the transaction based on the transaction data and the transaction type,
wherein the machine learning model is trained with training data comprising historical user data;
responsive to determining the threat level, selecting a mitigation procedure from a stored mitigation policy based on the transaction type of the transaction and the threat level associated with the transaction;
applying the mitigation procedure to the transaction based on the transaction type; and
storing the transaction data, a first indication of the mitigation procedure, and a second indication of the threat level associated with the transaction in a transaction data store.
10 . The method of claim 9 , further comprising:
authorizing the user account based at least in part on user information associated with a user.
11 . The method of claim 10 , wherein authorizing the user account comprises a multi-factor authentication procedure using two or more authentication factors to authenticate the user account.
12 . The method of claim 11 , wherein the two or more authentication factors are selected from a combination of a plurality of factors relating to any of a knowledge of the user, a possession of the user, and an inherence of the user.
13 . The method of claim 11 , wherein the two or more authentication factors comprise a password of the user and biometric data received from a biometric sensor.
14 . The method of claim 9 , further comprising:
identifying an abnormality associated with the transaction based on the transaction data using the machine learning model, wherein the abnormality is identified based on a disparity of the transaction with one or more normal user values of a normal transaction.
15 . The method of claim 14 , wherein the one or more normal user values comprises a normal input pattern.
16 . The method of claim 14 , wherein the mitigation procedure comprises disabling the transaction based on the abnormality and the threat level associated with the transaction.
17 . A method of threat mitigation for an identity access management system, the method comprising:
receiving transaction data relating to a transaction associated with a user account;
determining a transaction type of the transaction based on the transaction data;
determining, using a machine learning model, a threat level associated with the transaction based on the transaction data and the transaction type,
wherein the machine learning model is trained with training data comprising at least one of user data, access control policy, subject attributes, and environmental attributes;
responsive to determining the threat level, selecting a mitigation procedure from a stored mitigation policy based on the transaction type of the transaction and the threat level associated with the transaction;
updating the stored mitigation policy based on the transaction data and the transaction type of the transaction; and
storing the transaction data, a first indication of the mitigation procedure, and a second indication of the threat level associated with the transaction in a transaction data store.
18 . The method of claim 17 , wherein the transaction comprises a login attempt to the user account.
19 . The method of claim 17 , wherein the transaction comprises a request to access a resource by the user account.
20 . The method of claim 17 , wherein the transaction comprises a data entry from the user account.