IP Library Granted Patent US 11,178,180
Granted Patent B2
US 11,178,180 · App. 16/177,930 · Granted Nov 16, 2021

Risk analysis and access activity categorization across multiple data structures for use in network security mechanisms

Inventors: Sean Miller (Waterloo, CA); Aaron Beaudoin (Bolton, MA); Avinash Sangappa (Marlborough, MA); Venkata Kanaparthy (Hamburg, DE)
Assignee: EMC IP Holding Company LLC
H04L63/20G06F3/0484G06F16/26G06F16/287H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,178,180
App. No.
16/177,930
Granted
Nov 16, 2021
Kind
B2
Abstract

Methods, apparatus, and processor-readable storage media for risk analysis and access activity categorization across data structures for use in network security mechanisms are provided herein. An example computer-implemented method includes analyzing data, derived from a first set of data structures within a network, pertaining to items of access activity within the network; categorizing, based at least in part on the data analysis, the access activity into multiple review analysis categories; processing, based at least in part on the categorization, the analyzed data into a second set of multiple data structures corresponding to the review analysis categories; generating a visualization of the access activity categorized into the review analysis categories, wherein the visualization comprises displayed access to the second set of multiple data structures; outputting the generated visualization to a user via a GUI; and facilitating, based on user inputs via the GUI, access certification actions within the network.

Claims (41)

1. A computer-implemented method comprising:

analyzing data, derived from a first set of multiple data structures within a network, pertaining to multiple items of access activity within the network;

categorizing, based at least in part on the analyzing of the data, the multiple items of access activity into multiple review analysis categories, wherein the multiple review analysis categories comprise a category pertaining to entitlements held by a percentage of users, (i) associated with the network and (ii) associated with review by a given reviewer, that is below a predetermined percentage threshold;

processing, based at least in part on the categorization, the analyzed data into a second set of multiple data structures within the network, wherein the second set of multiple data structures corresponds to the multiple review analysis categories;

generating a visualization of the multiple items of access activity categorized into the multiple review analysis categories, wherein the visualization comprises displayed access to the second set of multiple data structures;

outputting the generated visualization to at least one reviewer via a graphical user interface; and

facilitating, based on one or more reviewer inputs to the generated visualization via the graphical user interface, one or more access certification actions within the network;

wherein the method is performed by at least one processing device comprising a processor coupled to a memory.

2. The computer-implemented method of claim 1 , wherein the data pertaining to multiple items of access activity comprise identity of one or more users associated with the access activity and historical access-related data attributed to the one or more users associated with the access activity.

3. The computer-implemented method of claim 1 , wherein the data pertaining to multiple items of access activity comprise one or more destinations associated with the access activity.

4. The computer-implemented method of claim 1 , wherein the data pertaining to multiple items of access activity comprise one or more items of temporal data associated with the access activity.

5. The computer-implemented method of claim 1 , wherein the one or more access certification actions comprise at least one of revoking a particular access from one or more users and granting a particular access to one or more users.

6. The computer-implemented method of claim 1 , wherein the review analysis categories comprise a category pertaining to one or more violations.

7. The computer-implemented method of claim 1 , wherein the review analysis categories comprise a category pertaining to instances of previously revoked access.

8. The computer-implemented method of claim 1 , wherein the review analysis categories comprise a category pertaining to one or more objects associated with a given level of importance.

9. The computer-implemented method of claim 1 , wherein the review analysis categories comprise a category pertaining to one or more entitlements associated with a given level of access.

10. The computer-implemented method of claim 1 , wherein the review analysis categories comprise a category pertaining to one or more access determinations approved within a given temporal period.

11. The computer-implemented method of claim 1 , wherein the review analysis categories comprise a category pertaining to one or more pending access revocations.

12. The computer-implemented method of claim 1 , wherein the review analysis categories comprise a category pertaining to access activity including one or more items unchanged from previous instances of the access activity.

13. The computer-implemented method of claim 1 , wherein the review analysis categories comprise a category pertaining to access activity associated with a given level of frequency.

14. A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device:

to analyze data, derived from a first set of multiple data structures within a network, pertaining to multiple items of access activity within the network;

to categorize, based at least in part on the analyzing of the data, the multiple items of access activity into multiple review analysis categories, wherein the multiple review analysis categories comprise a category pertaining to entitlements held by a percentage of users, (i) associated with the network and (ii) associated with review by a given reviewer, that is below a predetermined percentage threshold;

to process, based at least in part on the categorization, the analyzed data into a second set of multiple data structures within the network, wherein the second set of multiple data structures corresponds to the multiple review analysis categories;

to generate a visualization of the multiple items of access activity categorized into the multiple review analysis categories, wherein the visualization comprises displayed access to the second set of multiple data structures;

to output the generated visualization to at least one reviewer via a graphical user interface; and

to facilitate, based on one or more reviewer inputs to the generated visualization via the graphical user interface, one or more access certification actions within the network.

15. The non-transitory processor-readable storage medium of claim 14 , wherein the data pertaining to multiple items of access activity comprise at least one of identity of one or more users associated with the access activity, one or more destinations associated with the access activity, historical access-related data attributed to one or more users associated with the access activity, and one or more items of temporal data associated with the access activity.

16. The non-transitory processor-readable storage medium of claim 14 , wherein the review analysis categories comprise at least one of a category pertaining to one or more violations, a category pertaining to instances of previously revoked access, a category pertaining to one or more objects associated with a given level of importance, a category pertaining to one or more entitlements associated with a given level of access, a category pertaining to one or more access determinations approved within a given temporal period, a category pertaining to one or more pending access revocations, a category pertaining to access activity including one or more items unchanged from previous instances of the access activity, and a category pertaining to common access activity.

17. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the at least one processing device being configured:

to analyze data, derived from a first set of multiple data structures within a network, pertaining to multiple items of access activity within the network;

to categorize, based at least in part on the analyzing of the data, the multiple items of access activity into multiple review analysis categories, wherein the multiple review analysis categories comprise a category pertaining to entitlements held by a percentage of users, (i) associated with the network and (ii) associated with review by a given reviewer, that is below a predetermined percentage threshold;

to process, based at least in part on the categorization, the analyzed data into a second set of multiple data structures within the network, wherein the second set of multiple data structures corresponds to the multiple review analysis categories;

to generate a visualization of the multiple items of access activity categorized into the multiple review analysis categories, wherein the visualization comprises displayed access to the second set of multiple data structures;

to output the generated visualization to at least one reviewer via a graphical user interface; and

to facilitate, based on one or more reviewer inputs to the generated visualization via the graphical user interface, one or more access certification actions within the network.

18. The apparatus of claim 17 , wherein the data pertaining to multiple items of access activity comprise at least one of identity of one or more users associated with the access activity, one or more destinations associated with the access activity, historical access-related data attributed to one or more users associated with the access activity, and one or more items of temporal data associated with the access activity.

19. The apparatus of claim 17 , wherein the review analysis categories comprise at least one of a category pertaining to one or more violations, a category pertaining to instances of previously revoked access, a category pertaining to one or more objects associated with a given level of importance, a category pertaining to one or more entitlements associated with a given level of access, a category pertaining to one or more access determinations approved within a given temporal period, a category pertaining to one or more pending access revocations, a category pertaining to access activity including one or more items unchanged from previous instances of the access activity, and a category pertaining to common access activity.

20. The apparatus of claim 17 , wherein the one or more access certification actions comprise at least one of revoking a particular access from one or more users and granting a particular access to one or more users.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2018
From: MILLER, SEAN; BEAUDOIN, AARON; SANGAPPA, AVINASH; KANAPARTHY, VENKATA
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 047496/0671 →
Continuity (1)
Related Publication 20200145460A1 · May 7, 2020