EP4040723A1

Systems and methods for understanding identity and organizational access to applications within an enterprise environment

Abstract

Methods and systems for understanding identity and organizational access to applications within an enterprise environment are provided. Exemplary methods include collecting data about relationships between applications and metadata associated with the applications in a computing environment of an enterprise, the metadata including information concerning a plurality of users accessing the applications; updating a graph database including nodes representing the applications of the computing environment of the enterprise and edges representing relationships between the applications; enriching the graph database by associating the nodes with metadata associated with the applications and associating user accounts with metadata associated with roles, organizations membership, privileges, and permissions; analyzing the graph database to identify a subset of nodes being accessed by a user of the plurality of users; and displaying, via a graphical user interface, a graphical representation of the subset of nodes and relationships between the nodes in the subset of the nodes.

EP4040723A1, drawing sheet 1
Sheet 1 of 13

Term

Projected expiry 8 February 2042.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

15 claims: 8 independent, 7 dependent

  1. 1
    A system comprising:at least one processor;and a memory communicatively coupled to the at least one processor, the memory storing instructions executable by the at least one processor to perform a method comprising: collecting data about relationships between applications and metadata associated with the applications in a computing environment of an enterprise, the metadata including information concerning a plurality of users accessing the applications;updating a graph database including nodes representing the applications of the computing environment of the enterprise and edges representing relationships between the applications;enriching the graph database by associating the nodes with metadata associated with the applications;enriching the graph database by associating user accounts associated with the plurality of users with metadata associated with roles, organizations membership, privileges, and permissions associated with the plurality of users;analyzing the graph database to identify a subset of nodes being accessed by a user of the plurality of users;displaying, via a graphical user interface, a graphical representation of the subset of nodes and relationships between the nodes in the subset of the nodes;displaying, via the graphical user interface, a graphical representation of a subset of users defined by at least one of a group, a role, and an organizational membership and relationships between the nodes associated with the subset of users;displaying, via the graphical user interface, a graphical representation of the nodes representing the applications and groups of users accessing the applications;displaying, via the graphical user interface, a graphical representation of the permissions provided to the subset of users defined by at least one of the group, the role, and organizational unit in relation to the nodes representing the applications;and comparing the permissions with relationships related to accessing the applications by the subset of users, the relationships related to accessing the applications being recorded to the graph database.
  2. 4
    The system of any of claims 1 to 3, wherein the at least one processor is further configured to permit a subset of communications between the nodes by generating a whitelist identifying at least one user of the plurality of users permitted to access at least one application.
  3. 5
    The system of any of claims 1 to 4, wherein the at least one processor is further configured to:identify one or more of the permissions unutilized by at least one of the plurality of users;generate a score reflecting an accuracy of the permissions provided to the plurality of users;and recommend the one or more of the permissions for removal from the permissions.
  4. 8
    A method comprising:collecting data about relationships between applications and metadata associated with the applications in a computing environment of an enterprise, the metadata including information concerning a plurality of users accessing the applications;updating a graph database including nodes representing the applications of the computing environment of the enterprise and edges representing relationships between the applications;enriching the graph database by associating the nodes with metadata associated with the applications;enriching the graph database by associating user accounts associated with the plurality of users with metadata associated with roles, organizations membership, privileges, and permissions associated with the plurality of users;analyzing the graph database to identify a subset of nodes being accessed by a user of the plurality of users;displaying, via a graphical user interface, a graphical representation of the subset of nodes and relationships between the nodes in the subset of the nodes;displaying, via the graphical user interface, a graphical representation of a subset of users defined by at least one of a group, a role, and an organizational membership and relationships between the nodes associated with the subset of users;displaying, via the graphical user interface, a graphical representation of the nodes representing the applications and groups of users accessing the applications;displaying, via the graphical user interface, a graphical representation of the permissions provided to the subset of users defined by at least one of the group, the role, and organizational unit in relation to the nodes representing the applications;and comparing the permissions with relationships related to accessing the applications by the subset of users, the relationships related to accessing the applications being recorded to the graph database.
  5. 11
    The method of any of claims 8 to 10, further comprising permitting a subset of communications between the nodes by generating a whitelist identifying at least one user of the plurality of users permitted to access at least one application of the applications.
  6. 12
    The method of any of claims 8 to 11, further comprising:identifying one or more of the permissions unutilized by at least one of the plurality of users;generating a score reflecting an accuracy of the permissions provided to the plurality of users;and recommending the one or more of the permissions for removal from the permissions.
  7. 14
    The system of any of claims 1 to 8 or the method of any of claims 9 to 13, wherein the metadata includes network logs of access events of the users into the applications, and/or wherein the metadata includes telemetry data concerning an amount of data written to or read from workloads running the applications, types of operations conducted, access operations, time of day, and a client device used by the users.
  8. 15
    A non-transitory processor-readable medium having embodied thereon a program being executable by at least one processor to perform a method comprising:collecting data about relationships between applications and metadata associated with the applications in a computing environment of an enterprise, the metadata including information concerning a plurality of users accessing the applications;updating a graph database including nodes representing the applications of the computing environment of the enterprise and edges representing relationships between the applications;enriching the graph database by associating the nodes with metadata associated with the applications;enriching the graph database by associating user accounts associated with the plurality of users with metadata associated with roles, organizations membership, privileges, and permissions associated with the plurality of users;analyzing the graph database to identify a subset of nodes being accessed by a user of the plurality of users;displaying, via a graphical user interface, a graphical representation of the subset of nodes and relationships between the nodes in the subset of the nodes;displaying, via the graphical user interface, a graphical representation of a subset of users defined by at least one of a group, a role, and an organizational membership and relationships between the nodes associated with the subset of users;displaying, via the graphical user interface, a graphical representation of the nodes representing the applications and groups of users accessing the applications;displaying, via the graphical user interface, a graphical representation of the permissions provided to the subset of users defined by at least one of the group, the role, and organizational unit in relation to the nodes representing the applications;and comparing the permissions with relationships related to accessing the applications by the subset of users, the relationships related to accessing the applications being recorded to the graph database.