US2017339160A1PendingUtilityA1

Threat-aware provisioning and governance

Assignee: IBMPriority: May 17, 2016Filed: May 17, 2016Published: Nov 23, 2017
Est. expiryMay 17, 2036(~9.8 yrs left)· nominal 20-yr term from priority
H04L 63/105H04L 63/14H04L 63/20G06F 2221/2113G06F 21/577H04L 63/1408H04L 63/102H04L 63/1433H04L 63/10
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A management component of a computing system evaluates end-users, end-user devices, and user accounts for access to provisioned-resources of the computing system. The management component utilizes device compliance attributes to form a device risk vector associated with an end-user device. The management component further utilizes resource compliance attributes to form a resource risk vector associated with a provisioned-resource. The management component forms a policy vector utilizing compliance attributes included in a compliance policy. The management component compares the device and resource risk vectors to the policy vector to determine a threat vector, and uses the threat vector to evaluate the end-users, end-user devices, and user accounts for risk of security breach, damage to, and/or loss of components of the computing system.

Claims

exact text as granted — not AI-modified
1 . A method for managing a provisioned-resource, wherein the provisioned-resource is included in a computing system, wherein an end-user device is configured for use by an end-user to access the provisioned-resource, and wherein the method comprises:
 forming a device risk vector, for the end user device, wherein the device risk vector includes at least one device risk attribute, wherein the at least one device risk attribute is an attribute of the end-user device, and wherein the at least one device risk attribute is included in a device compliance status associated with the end-user device;   forming a resource risk vector, for the provisioned resource, wherein the resource risk vector includes at least one resource risk attribute, wherein the at least one resource risk attribute is an attribute of the provisioned-resource, and wherein the at least one resource risk attribute is included in a resource compliance status associated with the provisioned-resource;   forming a policy vector, wherein the policy vector includes at least one security compliance attribute, and wherein the at least one security compliance attribute represents an access risk boundary associated with the end-user device accessing the provisioned-resource;   forming a threat vector, wherein the threat vector includes at least one system risk attribute, wherein the at least one system risk attribute is based, at least in part, on comparing the device risk vector and the resource risk vector to the policy vector, and wherein the at least one system risk attribute comprises the at least one device risk attribute, the at least one resource risk attribute, and the at least one security compliance attribute; and   performing an access management operation including determining an access-level, wherein the access-level is associated with access to the provisioned-resource by at least one of the end-user, the end-user device, and a user account, wherein the user account is associated with the end-user, and wherein the determining the access-level is based, at least in part, on the at least one system risk attribute included in the threat vector; and   in response to the at least one system risk attribute included in the threat vector exceeding the at least one security compliance attribute, modifying the access level for at least one of the end user, the end user device, and the user account according to particular attributes included within the threat vector.   
     
     
         2 . The method of  claim 1 , wherein the determining the access-level is included in an access management operation. 
     
     
         3 . The method of  claim 2 , wherein the access management operation is included in at least one of:
 provisioning the provisioned-resource to at least one of the at least one of the end-user, the end-user device, and the user account;   certifying the at least one of the end-user, the end-user device, and the user account for the access to the provisioned-resource;   determining whether the access to the provisioned-resource by the at least one of the end-user, the end-user device, and the user account is within acceptable system security risk boundaries;   suspending the at least one of the end-user, the end-user device, and the user account from the access to the provisioned-resource; and   determining an organizational role classification associated with the at least one of the end-user, the end-user device, and the user account.   
     
     
         4 . The method of  claim 1  further comprising communicating a compliance alert in response to the at least one system risk attribute included in the threat vector exceeding the at least one security compliance attribute, wherein the compliance alert comprises at least identifying the end user or the end user device a posing a security risk to the computing system. 
     
     
         5 . The method of  claim 1  wherein the at least one device risk attribute includes at least one of a malware infection status, a device patch level, and a vulnerability. 
     
     
         6 . The method of  claim 1  wherein the at least one resource risk attribute includes at least one of a malware infection status, a device patch level, and a vulnerability. 
     
     
         7 . The method of  claim 1  wherein the end-user is one of a human user, a first computing device, a first computer program, a first electronic device, and a first component of a first mechanical device;
 wherein the end-user device is one of a second computing device, a second computer program, a second electronic device, a second component of a second mechanical device, a mobile device, a handheld device, and a component of a home appliance; and 
 wherein the provisioned-resource is at least one of access to the computing system, a virtual machine, a programming container, a resource included in the computing system, and a service included in the computing system. 
 
     
     
         8 . A computer program product for managing a provisioned-resource, wherein the provisioned-resource is included in a computing system, wherein an end-user device is configured for use by an end-user to access the provisioned-resource, wherein the computer program product comprises a computer readable storage medium having program instructions embodied therewith, and wherein the program instructions are executable by a first computing device to perform a method, the method comprising;
 forming a device risk vector, for the end user device, wherein the device risk vector includes at least one device risk attribute, wherein the at least one device risk attribute is an attribute of the end-user device, and wherein the at least one device risk attribute is included in a device compliance status associated with the end-user device;   forming a resource risk vector, for the provisioned resource, wherein the resource risk vector includes at least one resource risk attribute, wherein the at least one resource risk attribute is an attribute of the provisioned-resource, and wherein the at least one resource risk attribute is included in a resource compliance status associated with the provisioned-resource;   forming a policy vector, wherein the policy vector includes at least one security compliance attribute, and wherein the at least one security compliance attribute represents an access risk boundary associated with the end-user device accessing the provisioned-resource;   forming a threat vector, wherein the threat vector includes at least one system risk attribute, wherein the at least one system risk attribute is based, at least in part, on comparing the device risk vector and the resource risk vector to the policy vector, and wherein the at least one system risk attribute comprises the at least one device risk attribute, the at least one resource risk attribute, and the at least one security compliance attribute; and   performing an access management operation including determining an access-level, wherein the access-level is associated with access to the provisioned-resource by at least one of the end-user, the end-user device, and a user account, wherein the user account is associated with the end-user, and wherein the determining the access-level is based, at least in part, on the at least one system risk attribute included in the threat vector; and   in response to the at least one system risk attribute included in the threat vector exceeding the at least one security compliance attribute, modifying the access level for at least one of the end user, the end user device, and the user account according to particular attributes included within the threat vector.   
     
     
         9 . The computer program product of  claim 8 , wherein the method determining the access-level is included in an access management operation. 
     
     
         10 . The computer program product of  claim 9 , the method wherein the access management operation is included in at least one of:
 provisioning the provisioned-resource to the at least one of the end-user, the end-user device, and the user account;   certifying the at least one of the end-user, the end-user device, and the user account for the access to the provisioned-resource;   determining whether the access to the provisioned-resource by the at least one of the end-user, the end-user device, and the user account is within acceptable system security risk boundaries;   suspending the at least one of the end-user, the end-user device, and the user account from the access to the provisioned-resource; and   determining an organizational role classification associated with the at least one of the end-user, the end-user device, and the user account.   
     
     
         11 . The computer program product of  claim 8 , wherein the method further comprises communicating a compliance alert, the compliance alert in response to the at least one system risk attribute included in the threat vector exceeding the at least one security compliance attribute, wherein the compliance alert comprises at least identifying the end user or the end user device a posing a security risk to the computing system. 
     
     
         12 . The computer program product of  claim 8 , the method wherein the at least one device risk attribute includes at least one of a malware infection status, a device patch level, and a vulnerability. 
     
     
         13 . The computer program product of  claim 8 , the method wherein the at least one resource risk attribute includes at least one of a malware infection status, a device patch level, and a vulnerability. 
     
     
         14 . The computer program product of  claim 8 , the method wherein the end-user is one of a human user, a first computing device, a first computer program, a first electronic device, and a first component of a first mechanical device;
 wherein the end-user device is one of a second computing device, a second computer program, a second electronic device, a second component of a second mechanical device, a mobile device, a handheld device, and a component of a home appliance; and   wherein the provisioned-resource is at least one of access to the computing system, a virtual machine, a programming container, a resource included in the computing system, and a service included in the computing system.   
     
     
         15 . A system for managing a provisioned-resource, the system comprising:
 a computing system, wherein the computing system includes a first computing device having a processor, and a memory in communication with the processor;   a provisioned-resource, wherein the provisioned-resource is included in the computing system; and   an end-user device, wherein the end-user device is configured for use by an end-user to access the provisioned-resource;   wherein the system is configured to form a device risk vector for the end user device, the device risk vector including at least one device risk attribute, the at least one device risk attribute being an attribute of the end-user device, the at least one device risk attribute included in a device compliance status associated with the end-user device;   wherein the system is configured to form a resource risk vector for the provisioned resource, the resource risk vector including at least one resource risk attribute, the at least one resource risk attribute being an attribute of the provisioned-resource, the at least one resource risk attribute included in a resource compliance status associated with the provisioned-resource;   wherein the system is configured to form a policy vector, the policy vector including at least one security compliance attribute, the at least one security compliance attribute representing an access risk boundary associated with the end-user device accessing the provisioned-resource;   wherein the system is configured to form a threat vector, the threat vector including at least one system risk attribute, wherein the at least one system risk attribute is based, at least in part, on comparing the device risk vector and the resource risk vector to the policy vector, and wherein the at least one system risk attribute comprises the at least one device risk attribute, the at least one resource risk attribute, and the at least one security compliance attribute;   wherein the system is configured to perform an access management operation to determine an access-level, the access-level associated with access to the provisioned-resource by at least one of the end-user, the end-user device, and a user account, the user account associated with the end-user, the determining the access-level based, at least in part, on the at least one system risk attribute included in the threat vector; and   in response to the at least one system risk attribute included in the threat vector exceeding the at least one security compliance attribute, modifying the access level for at least one of the end user, the end user device, and the user account according to particular attributes included within the threat vector.   
     
     
         16 . The system of  claim 15 , wherein the system is further configured to determine the access-level as part of an access management operation, and wherein the access management operation is included in at least one of:
 provisioning the provisioned-resource to the at least one of the end-user, the end-user device, and the user account;   certifying the at least one of the end-user, the end-user device, and the user account for the access to the provisioned-resource;   determining whether the access to the provisioned-resource by the at least one of the end-user, the end-user device, and the user account is within acceptable system security risk boundaries;   suspending the at least one of the end-user, the end-user device, and the user account from the access to the provisioned-resource; and   determining an organizational role classification associated with the at least one of the end-user, the end-user device, and the user account.   
     
     
         17 . The system of  claim 15 , wherein the system is further configured to communicate a compliance alert, the compliance alert in response to the at least one system risk attribute included in the threat vector. 
     
     
         18 . The system of  claim 15 , wherein the at least one device risk attribute includes at least one of a malware infection status, a device patch level, and a vulnerability. 
     
     
         19 . The system of  claim 15 , wherein the at least one resource risk attribute includes at least one of a malware infection status, a device patch level, and a vulnerability. 
     
     
         20 . The system of  claim 15 , wherein the end-user is one of a human user, a first computing device, a first computer program, a first electronic device, and a first component of a first mechanical device;
 wherein the end-user device is one of a second computing device, a second computer program, a second electronic device, a second component of a second mechanical device, a mobile device, a handheld device, and a component of a home appliance; and   wherein the provisioned-resource is at least one of access to the computing system, a virtual machine, a programming container, a resource included in the computing system, and a service included in the computing system.

Join the waitlist — get patent alerts

Track US2017339160A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.