Electronic device and method for enhancing the security of enterprise computer systems against security breaches
View Patent ↗A method for enhancing the security of data in enterprise computer systems against security breaches is provided that includes collecting, by at least one electronic device, information about a user. The information includes at least permissions to access applications in electronic devices, permissions to access data in at least one share folder in electronic devices, permissions to access electronic devices, and permissions to access data in databases in the enterprise computer system. Moreover, the method includes comparing the collected permissions against record permissions of the user and in response to determining at least one collected permission fails to match a record permission, determining a state change has occurred. Furthermore, the method includes determining whether the non-matching permission was authorized to be assigned to the user, and in response to determining that the non-matching permission was assigned to the user, validating the state change.
1 . A method for enhancing the security of enterprise computer systems against security breaches comprising the steps of:
collecting, by at least one electronic device in an enterprise computer system, information about a user, the information including at least permissions to access applications in electronic devices in the enterprise computer system, permissions to access data in at least one share folder in electronic devices included in the enterprise computer system, permissions to access electronic devices in the enterprise computer system, and permissions to access data in databases in the enterprise computer system, the collected permissions being associated with the user;
comparing the collected permissions against record permissions of the user;
in response to determining at least one collected permission fails to match a record permission, determining a state change has occurred;
searching items of evidence, wherein each item of evidence authorizes assignment of a permission;
when an item of evidence is found that authorizes assignment of the non-matching permission to the user, determining the non-matching permission was authorized to be assigned to the user, otherwise determining the non-matching permission was not authorized to be assigned to the userd; and
in response to determining that the non-matching permission was assigned to the user, validating the state change.
2 . The method according to claim 1 , further comprising changing the collected permissions of the user to match the record permissions of the user in response to determining the non-matching permission was not authorized to be assigned to the user.
3 . The method according to claim 1 , said further comprising determining whether the non-matching permission assigned administrative or remote access privileges.
4 . The method according to claim 3 , further comprising determining whether the user has permission to access additional electronic devices in the enterprise computer system.
5 . The method according to claim 4 , further comprising determining whether a firewall in the enterprise computer system permits electronic devices in the enterprise computer system to communicate with other electronic devices outside the enterprise computer system when the user has permission to access additional electronic devices in the enterprise computer system.
6 . The method according to claim 5 , further comprising:
investigating the enterprise security system for a security breach when the firewall permits electronic devices in the enterprise computer system to communicate with other electronic devices outside the enterprise computer system.
7 . An electronic device for enhancing the security of enterprise computer systems against security breaches comprising a processor and a memory configured to store data and items of evidence, each item of evidence authorizing assignment of a permission to a record user, said electronic device being associated with a network and said memory being in communication with said processor and having instructions stored thereon which, when read and executed by said processor, cause said electronic device to:
receive information about a user, the information including at least permissions to access applications in electronic devices in the enterprise computer system, permissions to access data in at least one share folder in electronic devices included in the enterprise computer system, permissions to access electronic devices in the enterprise computer system, and permissions to access data in databases in the enterprise computer system, the collected permissions being associated with the user;
compare the received permissions against record permissions of the user;
in response to determining at least one collected permission fails to match a record permission, determine a state change has occurred;
search the items of evidence for an item of evidence that authorizes assignment of the non-matching permission to the record user;
when an item of evidence is found that authorizes assignment of the non-matching permission to the user, determine the non-matching permission was authorized to be assigned to the user, otherwise determine the non-matching permission was not authorized to be assigned to the use; and
in response to determining that the non-matching permission was assigned to the user, validate the state change.
8 . The electronic device according to claim 7 , wherein the instructions when read and executed by said processor, cause said electronic device to change the collected permissions of the user to match the record permissions of the user in response to determining the non-matching permission was not authorized to be assigned to the user.
9 . The electronic device according to claim 7 , wherein the instructions when read and executed by said processor, cause said electronic device to determine whether the non-matching permission assigned administrative or remote access privileges.
10 . The electronic device according to claim 9 , wherein the instructions when read and executed by said processor, cause said electronic device to determine whether the user has permission to access folders and databases in additional electronic devices in the enterprise computer system.
11 . The electronic device according to claim 10 , wherein the instructions when read and executed by said processor, cause said electronic device to determine whether a firewall in the enterprise computer system permits electronic devices in the enterprise computer system to communicate with other electronic devices outside the enterprise computer system when the user has permission to access additional electronic devices in the enterprise computer system.
12 . The electronic device according to claim 11 , wherein when the firewall permits electronic devices in the enterprise computer system to communicate with other electronic devices outside the enterprise computer system the instructions when read and executed by said processor, cause said electronic device to transmit a message to an entity responsible for managing permissions in the enterprise computer system to investigate the system for a security breach.
13 . A non-transitory computer-readable recording medium in an electronic device for enhancing the security of enterprise computer systems against security breaches, the non-transitory computer-readable recording medium storing one or more programs which when executed by a hardware processor cause the non-transitory recording medium to perform steps comprising:
collecting information about a user, the information including at least permissions to access applications in electronic devices in the enterprise computer system, permissions to access data in at least one share folder in electronic devices included in the enterprise computer system, permissions to access electronic devices in the enterprise computer system, and permissions to access data in databases in the enterprise computer system, the collected permissions being associated with the user;
comparing the collected permissions against record permissions of the user;
in response to determining at least one collected permission fails to match a record permission, determining a state change has occurred;
searching items of evidence, wherein each item of evidence authorizes assignment of a permission;
when an item of evidence is found that authorizes assignment of the non-matching permission to the user, determining the non-matching permission was authorized to be assigned to the user, otherwise determining the non-matching permission was unauthorized to be assigned to the user; and
in response to determining that the non-matching permission was assigned to the user, validating the state change.
14 . The non-transitory computer-readable recording medium according to claim 13 , further comprising changing the collected permissions of the user to match the record permissions of the user in response to determining the non-matching permission was not authorized to be assigned to the user.
15 . The non-transitory computer-readable recording medium according to claim 13 , further comprising:
determining whether a firewall in the enterprise computer system permits electronic devices in the enterprise computer system to communicate with other electronic devices outside the enterprise computer system when the user has permission to access additional electronic devices in the enterprise computer system; and
investigating the enterprise security system for a security breach when the firewall permits electronic devices in the enterprise computer system to communicate with other electronic devices outside the enterprise computer system.