Reconciliation - Backdoor Access Finding Strategies with Legacy Applications
摘要
In the intricate realm of Identity and Access Management (IAM), practitioners frequently grapple with a host of prevalent challenges that impede the process of access reconciliation. A prime hurdle is the intricate task of pinpointing inconsistencies and discrepancies within user access rights spread across a plethora of systems and applications. The inherently complex and ever-evolving nature of modern IT landscapes, where access levels are meticulously assigned based on varied roles and responsibilities, exacerbates this challenge. Compounding this issue is the lack of a centralized overview of user access rights, which obstructs the timely detection and resolution of conflicts, such as unwarranted or excessive access privileges. These conflicts not only heighten security risks but also amplify the organization’s vulnerability to unauthorized access. Addressing these issues necessitates the adoption of robust mechanisms aimed at identifying and rectifying access discrepancies, including regular access reviews and automated access certification processes. In this paper, We wrote access reconciliation algorithm to identify backdoor, Manual Error, Timing error exceptions. It is found that the outcomes are satisfactory compared to manual reconciliation and as a result these techniques can be integrated in designing an expert tool and helpful in Audit’s, Technical hardenings.