发明名称 Techniques for Reconciling Permission Usage with Security Policy for Policy Optimization and Monitoring Continuous Compliance
摘要 In one aspect, a method for managing a security policy having multiple policy items includes the steps of: (a) mapping permissions to the policy items which apply to usage of the permissions so as to determine which of the permissions are granted to groups of users by each of the policy items; (b) identifying at least one of the policy items mapped in step (a) that is in violation of least privilege based on a comparison of an actual permission usage with the security policy; (c) identifying at least one of the policy items mapped in step (a) that increases operational risk; (d) verifying that policy constructs in the security policy are consistent with policy constructs inferred from the actual permission usage; and (e) identifying optimizations of the security policy based on output from one or more of steps (a)-(d).
申请公布号 US2014359695(A1) 申请公布日期 2014.12.04
申请号 US201313970174 申请日期 2013.08.19
申请人 International Business Machines Corporation 发明人 Chari Suresh N.;Molloy Ian M.;Park Youngja;Teiken Wilfried
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. An apparatus for managing a security policy having multiple policy items, the apparatus comprising: a memory; and at least one processor device, coupled to the memory, operative to: (a) map permissions to the policy items which apply to usage of the permissions so as to determine which of the permissions are granted to groups of users by each of the policy items;(b) identify at least one of the policy items mapped in step (a) that is in violation of least privilege based on a comparison of an actual permission usage with the security policy;(c) identify at least one of the policy items mapped in step (a) that increases operational risk;(d) verify that policy constructs in the security policy are consistent with policy constructs inferred from the actual permission usage; and(e) identify optimizations of the security policy based on output from one or more of steps (a)-(d).
地址 Armonk NY US