AI-based multi-cloud security management center system and method
By building a six-layer architecture system and adopting AI Agent and multimodal analysis models, we have solved the problems of global asset management and low security operation efficiency in multi-cloud environments, achieved efficient multi-cloud security governance, reduced manual operation costs, and improved security operation efficiency and accuracy.
Patent Information
- Application Number
- CN202510778501.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-11
- Publication Date
- 2025-09-12
AI Technical Summary
Existing technologies are unable to achieve global asset management in a multi-cloud environment, have low security operation efficiency and high labor costs, lack a full-process closed loop of data integration, intelligent analysis and automatic response, and cannot meet the real-time security needs of medium and large enterprises.
A six-layer architecture system is built, including data collection, integration, intelligent analysis, policy management and automated execution layers, using AI Agent, multimodal analysis models and dynamic knowledge graphs to achieve unified management of cross-cloud resources, improve security operation efficiency and reduce costs.
The time for managing multi-cloud assets has been shortened from 120 minutes to 1 minute, the vulnerability repair cycle has been compressed from days to minutes, the false alarm rate has been reduced by 85%, the high-risk threat detection coverage has been increased to 98%, and manual operations have been reduced by 70%, building a security-efficiency-cost balance system.
Smart Images

Figure FT_1 
Figure FT_2 
Figure FT_3
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cloud computing security technology, specifically an artificial intelligence (AI)-based multi-cloud environment security governance system and method. Through AI-driven automated orchestration technology, it enables global asset management, security compliance checks, and threat detection and response in multi-cloud environments for medium and large enterprises. Background Art
[0002] Industry Development and Technological Challenges As enterprises deepen their digital transformation, multi-cloud architectures (using resources from multiple cloud providers simultaneously) have become the mainstream IT deployment model for medium and large enterprises due to their advantages such as resource elasticity and vendor risk diversification. However, the complexity of multi-cloud environments has led to three core pain points in traditional security governance systems: 1. Inefficient global asset management: In a multi-cloud environment, computing resources (such as AWS EC2 and Alibaba Cloud ECS), storage resources (S3 and OSS), and network configurations (VPC and ACL) are scattered across different vendors' platforms, lacking a unified management tool. Enterprises struggle to obtain a complete asset inventory in real time, and confusion over AKSK (Access Key ID / Secret Access Key) permissions is a prominent issue. Statistics show that 80% of cloud data breaches are directly related to improper AKSK management. Traditional manual inventorying is time-consuming and labor-intensive, and dynamic identification of newly added resources can be delayed by over an hour.
[0003] 2. Inefficient security operations: The traditional model, which relies on manual rule configuration and response, is no longer able to cope with high-frequency and complex attacks. For example, vulnerability remediation requires the security team to conduct cross-platform investigations and manually issue policies, a cycle that can take over 48 hours. Traditional SIEM systems, based on static rule engines, have a false alarm rate as high as 70%, requiring the security team to spend over 60% of their time addressing invalid alerts. Detection coverage for advanced threats (such as APTs) is less than 85%.
[0004] 3. Labor costs continue to rise. Security teams need to maintain multiple cloud platform policies, and this duplication of effort results in annual operating costs that increase exponentially with the scale of multi-cloud operations. For example, for a medium-sized enterprise, the manpower required for security configuration management in a multi-cloud environment increases by 300% compared to a single-cloud scenario, with policy consistency verification accounting for over 40% of the time spent.
[0005] Defects of existing technical solutions 1. Limitations of Traditional Multi-Cloud Security Tools Palo Alto Networks Prisma Cloud: Provides multi-cloud security posture management (CSPM), but data integration relies on customized API development, lacks AI automated response capabilities, and policy delivery delays exceeding 30 minutes in complex scenarios, failing to meet real-time security needs.
[0006] Check Point CloudGuard: Focuses on network layer protection. Its attack path visualization only supports static topology display and lacks dynamic threat deduction capabilities, making it difficult to predict multi-stage attack paths such as "privilege escalation-data theft."
[0007] 2. Shortcomings of open source and semi-automated solutions Open source tools such as CNSI only support basic cloud-native security testing. Compliance adaptation for industries such as finance and healthcare requires additional development (taking an average of 2-3 months), and lacks industry customization capabilities.
[0008] Manual configuration inspection tools: A single full scan takes 6-8 hours, dynamic resource change detection delays exceed 30 minutes, and the missed detection rate is as high as 20%. They cannot adapt to the dynamic nature of multi-cloud environments.
[0009] Core problems not solved by existing technologies Existing solutions fail to form a closed loop of the entire process of "data integration - intelligent analysis - automatic response". Specific technical gaps include: The challenge of real-time cross-cloud data standardization: Different cloud vendors have heterogeneous data formats, and there is a lack of efficient data conversion and dynamic association technologies. Lack of industry-specific AI model adaptation: General AI models cannot meet the specific compliance requirements of industries like finance (such as Information Security Protection 2.0 and GDPR), and customized training cycles can take up to several weeks. Gaps in quantitative assessment of attack impact: Traditional visualization tools only display static risk points and cannot dynamically measure the scope of attack impact and the probability of spread. Summary of the Invention
[0010] Purpose of the Invention To address the above pain points, the present invention provides an AI-driven multi-cloud security governance hub system to achieve: 1. Unified management of multi-cloud resources: Manage multi-cloud assets in 1 minute, dynamically build a global asset view, and resolve resource silos. 2. Breakthrough in security operations efficiency: Vulnerability remediation cycles have been shortened from days to minutes, false alarm rates have been reduced by 85%, and high-risk threat detection coverage has increased to 98%. 3. Balance between cost and safety: Reduce manual operations by 70%, achieve an operational handling accuracy rate of 99%, and build a "safety-efficiency-cost" triangular balance system.
[0011] Technical Solution 1. System architecture and core modules The present invention constructs a six-layer architecture system (as shown in Figure 1), including: Data collection layer: Use AI Agent to capture multi-cloud resource data in real time; Data integration layer: Cross-cloud conversion engine realizes data standardization and dynamically builds security knowledge graph; Intelligent analysis layer: Multimodal AI models perform risk detection and threat deduction; Policy management layer: A unified rule base supports compliance templates and custom policy generation; Automated execution layer: A closed-loop response engine implements vulnerability remediation, AKSK governance, and other operations; Interactive display layer: The visual interface presents security trends such as asset topology and attack links. 2. Key technology implementation (1) Multi-cloud data seamless integration engine AI Agent cross-cloud collection technology: Design a universal adapter interface (supporting mainstream manufacturers such as AWS, Alibaba Cloud, and Tencent Cloud), and adopt a differentiated collection strategy - core resources (such as servers and databases) are incrementally collected every 10 seconds, and static configurations (such as storage buckets) are fully synchronized every 5 minutes. Initial asset management is completed within 1 minute, with a coverage rate of 99.5%.
[0012] Dynamic knowledge graph construction method: Integrating top-down (business architecture mapping) and bottom-up (resource attribute association) modeling, a three-dimensional graph is constructed that includes asset hierarchy, permission dependencies (ACL / POLICY associations), and traffic paths (VPC peering relationships). Resource changes are updated in seconds through an event-driven mechanism.
[0013] (2) AI-driven security operations architecture Multimodal fusion analysis model: Integrates five-dimensional data such as logs, traffic, and asset topology, and implements it based on graph neural networks (GNN): Dynamic attack chain simulation: Simulates multiple typical attack paths, including "weak password login → lateral movement → data theft," and predicts risks 4 hours in advance with an accuracy rate of 98%; Intelligent alert noise reduction: By combining threat intelligence with historical data to train classification models, the false alarm rate has been reduced from 70% to below 10%, and the response time for high-risk alerts has been shortened to 3 minutes.
[0014] Industry-customized AI fine-tuning framework: This framework uses transfer learning technology to extract security feature representations from common models, and performs targeted fine-tuning for compliance data (such as Information Security Protection 2.0 control items) in industries like finance and healthcare. It completes policy adaptation within 24 hours and supports natural language rule input (for example, "prohibit public network access to core databases" is automatically parsed into a cross-cloud ACL policy).
[0015] (3) Fully automated processing system Unified rule management system: Built-in 200+ international and domestic compliance templates (such as Information Security Protection 2.0 and NIST SP 800-53), using NLP technology to parse custom rules and automatically generate unified cross-cloud policies (such as converting "local storage of EU user data" into AWS EU region restriction policy and Alibaba Cloud compliance configuration).
[0016] Closed-loop response mechanism: Vulnerability Management: After a vulnerability is detected, it automatically matches the repair knowledge base (including multiple vulnerability patch solutions), generates a work order, and pushes repair suggestions. After authorization, it triggers automated repair (success rate 95%), shortening the repair cycle to 30 minutes. AKSK Governance: Establishes a behavioral baseline based on role profiles (over 50 features such as operation time and resource access frequency), monitors abnormal operations in real time (such as high-privilege calls during non-working hours), triggers circuit breakers, and records full-link logs. AKSK's abuse detection accuracy reaches 99%.
[0017] 3. Typical application scenarios Take the financial industry as an example: (1) Asset management stage: The AI Agent synchronizes AWS and Alibaba Cloud account data, generates a global asset map with risk annotations within 5 minutes, and automatically identifies databases exposed to the public network (marked as red high-risk nodes); (2) Risk detection phase: Through attack chain visualization, the path of "unauthorized access to Redis → obtaining AKSK → cross-cloud data theft" is rehearsed to block risky connections in advance; (3) Response and disposal phase: When it is detected that encryption is not enabled for an EC2 instance, the system automatically generates a work order and links the cross-cloud firewall to block the abnormal IP address. The repair is completed within 30 minutes and a compliance report is generated.
[0018] Technological innovations 1. Real-time cross-cloud data integration technology: Through a standardized conversion engine and dynamic knowledge graph, multi-cloud resources can be managed with one click and updated within seconds, increasing management efficiency by 100 times. 2. Multimodal threat analysis model: Integrating graph neural networks and transfer learning, it enables industry-customized threat deduction for the first time, with an error rate of less than 5% for quantitative assessment of attack impact range; 3. Fully automated closed-loop process: End-to-end human intervention from vulnerability detection to remediation, rule issuance delay less than 10 seconds, and 80% reduction in manual intervention.
[0019] Technical Effects 1. Improved efficiency: The asset management time was reduced from 120 minutes to 1 minute, and the delay in dynamic identification of new resources was less than 10 seconds; The vulnerability repair cycle was shortened from 48 hours to 30 minutes, and emergency response efficiency increased by 95%.
[0020] 2. Cost optimization: The labor cost of security operations has been reduced by 70%, and the time required to configure rules has been reduced from 8 hours to 15 minutes. False alarm processing time was reduced by 85%, and the security team's effective working time was increased by 40%.
[0021] 3. Security enhancements: The operational disposal accuracy rate reached 99%, and the high-risk vulnerability missed detection rate was less than 0.5%; the attack identification coverage rate increased from 85% to 98%, and APT attack detection provided an early warning 4 hours in advance. DETAILED DESCRIPTION
[0022] System deployment and hardware architecture The system of the present invention adopts a distributed microservice architecture and is deployed in an enterprise private cloud or a managed data center. The hardware configuration includes: Data collection nodes: Deploy lightweight AI agents (a single agent resource occupies ≤ 200MB of memory), support Docker container deployment, and deploy agent instances in each cloud vendor environment to achieve real-time data collection; Central processing cluster: Configured with high-performance servers (CPU ≥ 32 cores, memory ≥ 256GB), using Kubernetes for container orchestration, supporting horizontal expansion, and meeting the concurrent processing needs of tens of thousands of cloud resources; Storage system: Use a distributed database (such as Cassandra) to store asset data (throughput ≥ 100,000 TPS), and an Elasticsearch cluster to store logs and threat intelligence (supporting retrieval in seconds).
[0023] Core module specific implementation 1. Implementation of a multi-cloud data seamless integration engine AI Agent data collection process: collects dynamic / static data through differentiated strategies, supports breakpoint resuming, and automatically recollects unsynchronized data after network interruption recovery (maximum recollection delay ≤ 30 seconds).
[0024] Dynamic knowledge graph construction: Use Neo4j graph database for storage, define node types and relationship types, and trigger incremental updates of the graph based on resource change events (delay ≤ 2 seconds).
[0025] 2. AI-driven security operations architecture implementation Multimodal fusion analysis model: implemented based on the PyTorch framework, integrating GNN and Transformer architectures, with training data containing more than 1 million samples, using the AdamW optimizer with a learning rate of 0.001.
[0026] Industry-customized AI fine-tuning: By freezing the underlying feature layer of the general model and opening the industry adaptation layer, and inputting financial industry compliance data, the accuracy rate of compliance strategy generation reaches 98.7%.
[0027] 3. Implementation of fully automated processing system Unified rule management: Supports natural language rule parsing, such as "Prohibit Shanghai regional servers from accessing the MySQL port from the public network" to automatically generate cross-cloud security group rules.
[0028] Closed-loop vulnerability management: NVD is connected to cloud vendor patch libraries, and automatic repair supports tools such as AWS SSM and Alibaba Cloud ROS, with a repair success rate of 95.2%. Implementation variants and instructions
[0029] 1. Rule management variations: The compliance template library may delete or add templates based on enterprise needs, but the number must not be less than 30. Natural language processing technology may use different parsing algorithms, and the rule parsing accuracy must be no less than 90%. 2. Deployment environment variants: Supports different cloud service provider combinations, including Google Cloud and Huawei Cloud; adapts to hybrid cloud (private cloud + public cloud) deployment, and performs data collection and policy management based on the special network configuration and permission requirements of private clouds. 3. Functional extension variant: It can integrate new security features such as data desensitization and zero-trust access control; and customize industrial Internet security management and control, patient data privacy protection and other functions for the manufacturing and medical industries. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 System technical architecture layered diagram description: The layered architecture clearly shows the data flow and realizes full-process automation from the collection layer to the display layer.
[0031] a. Data collection layer: Deploy lightweight AI Agent (Docker containerization) and use dedicated interfaces for different cloud vendors: AWS Agent obtains EC2 instance metadata and S3 bucket configuration through the AWS SDK; Alibaba Cloud Agent collects ECS instance security group and OSS storage bucket region information through OpenAPI; The data cleaning module automatically filters invalid fields (such as unenabled resource logs) and transmits them to the central cluster via TLS 1.3 encryption.
[0032] b. Data integration layer: The cross-cloud conversion engine unifies heterogeneous data into JSON Schema format (defining resource entities and attribute fields); The dynamic knowledge graph builds the three-dimensional association of assets, permissions, and networks in real time, supporting the processing of 1,000+ resource change events per second.
[0033] c. Intelligent analysis layer: The multimodal fusion engine integrates GNN (for processing knowledge graphs) and Transformer (for parsing log text) to output an attack probability score (accurate to 0.1%). The attack simulation module rehearses typical attack paths and marks high-risk nodes in real time (public network exposed resources are highlighted in red).
[0034] d. Strategic management: The compliance template library includes over 2,000 controls based on standards such as Information Security Protection 2.0 and GDRP, and supports natural language rule input (e.g., "Prohibit financial data from being stored on unencrypted volumes" is automatically interpreted as a cross-cloud storage policy). The cross-cloud policy generator adapts to the API syntax of different vendors (for example, converting AWS Security Group rules into Alibaba Cloud ACL policies).
[0035] e.Automation execution layer: The vulnerability closed-loop system connects to the NVD vulnerability database and automatically matches repair solutions (including patch verification and rollback mechanisms); The AKSK governance module dynamically adjusts permissions based on role profiles, and synchronously generates audit logs (precisely recording the operation IP, time, and resource path) when abnormal operations trigger circuit breakers.
[0036] f. Interactive display layer: The asset topology map supports three levels of drilling (business system → application → specific resource), and displays a real-time heat map of resource utilization; The compliance dashboard dynamically calculates compliance rates for standards like PCI-DSS, with red alerts for non-compliant items (such as API interfaces that don't have TLS 1.3 enabled).
[0037] Figure 2: Sequence diagram of the entire multi-cloud security governance process Note: The timing diagram shows the closed-loop process from data collection to strategy feedback, highlighting the efficiency of automated processing.
[0038] Data collection phase: Dynamic resources (servers, databases) use a 10-second polling mechanism, and static resources (storage buckets, security groups) are fully fetched every 5 minutes. AI Agent supports breakpoint resuming and automatically re-collects unsynchronized data after network interruption is restored (maximum re-collection delay ≤ 30 seconds).
[0039] Risk analysis phase: The intelligent analysis module performs asset correlation analysis (taking ≤ 2 seconds) and attack probability calculation (based on the Monte Carlo simulation algorithm, taking ≤ 5 seconds) in parallel; High-risk (score ≥90 points) triggers the emergency response process and automatically skips the manual review process.
[0040] Strategy execution phase: Cross-cloud policy delivery supports batch operations (up to 500 rules can be processed at a time), with an average latency of ≤10 seconds; When automatic repair fails (e.g., patch version incompatibility), the system automatically generates a manual handling work order and identifies alternative solutions (e.g., manual configuration of firewall rules).
[0041] Figure 3 Schematic diagram of the attack link dynamic deduction visualization interface Note: The interactive interface supports attack stage screening, risk level classification, and real-time demonstration of attack paths and defense measures, improving security decision-making efficiency.
[0042] Interface element description: Left navigation bar: Attack stage filtering: supports multi-stage filtering such as "reconnaissance", "lateral movement", and "data exfiltration"; Risk level screening: high-risk (red), medium-risk (yellow), and low-risk (green) node classification display.
[0043] Main view area: Node Type: Server node: displays the instance ID, cloud vendor, and public IP address (unencrypted nodes are marked in red); Database node: displays the storage type (RDS / OSS) and access policy (green indicates intranet access only). AKSK node: Displays permission scope (administrator / read-only) and last update time (no update for more than 90 days is marked in red).
[0044] Edge attribute labels: Network connection edge: indicates bandwidth (Mbps) and encryption status (TLS 1.3 / unencrypted). Permission dependency edge: displays the ACL policy version and authorization time (dashed lines indicate expired permissions); Attack path edge: The color depth of the arrow represents the probability of attack success (dark red ≥ 70%, light red 50%-70%).
[0045] Right operation bar: Risk Details: Click a node to display the CVE vulnerability list and compliance status (e.g., failure to pass the storage encryption requirement of SME Security 2.0 Level 3); Disposal suggestions: Automatically generate blocking strategies (such as banning abnormal IP addresses and reclaiming excessive permissions), and support one-click execution (delay ≤ 5 seconds).
[0046] Bottom timeline: Dynamically demonstrate the attack evolution process: from "weak password login at 09:00 on January 1, 2024" to "obtaining the administrator's AKSK at 09:15" and then to "cross-cloud data download at 09:30"; Real-time display of the effective time of each stage of defense measures (such as "09:05 Firewall blocks RDP port").
[0047] Figure 4 Vulnerability closed-loop management flow chart Note: The closed-loop process covers vulnerability detection, analysis, repair, and verification, ensuring full lifecycle management of security incidents.
[0048] New vulnerability detection portal (scheduled scanning + real-time anomaly detection), covering more than 99% of known vulnerability types; The risk level uses the CVSS v4.0 standard, automatically calculating the exploit complexity and impact score. The post-repair retesting mechanism ensures a closed-loop vulnerability loop and automatically upgrades the priority of the work order if the retest fails (for example, retest failure of a high-risk vulnerability triggers emergency manual intervention). Explanation of terms
[0049] 1. AKSK: The access credentials used by cloud service providers for authentication, including Access Key ID (public key) and Secret Access Key (private key), are the core elements of cloud resource access control.
[0050] 2. Knowledge graph: A knowledge base that represents entities (such as servers and databases) and their relationships (such as permission dependencies and network connections) through a graph structure, used to model the security association relationships in a multi-cloud environment.
[0051] 3. AI Agent: A lightweight program deployed in various cloud environments, responsible for data collection, preprocessing, and simple rule execution, supporting seamless integration of APIs across cloud vendors. Keywords
[0052] Multi-cloud security, AI-driven, automated orchestration, knowledge graph, compliance checking, and dynamic detection.
Claims
1. An AI-based multi-cloud security governance hub system, characterized by: include: The data collection layer deploys a lightweight AI agent. This AI agent adapts to the APIs / SDKs of different cloud vendors and uses differentiated collection strategies to acquire core resource data such as computing resources, storage resources, and network configuration in a multi-cloud environment in real time. It also performs data cleaning and encrypted transmission. The data integration layer includes a cross-cloud data conversion engine that standardizes heterogeneous data into a unified format and uses a combination of top-down and bottom-up modeling methods to dynamically build a three-dimensional knowledge graph that includes asset hierarchical relationships, account permission dependencies, and network traffic paths. The intelligent analysis layer includes a multimodal fusion engine that integrates five dimensions of data: logs, traffic, asset topology, threat intelligence, and security indicators. Based on graph neural networks and deep learning models, it enables dynamic analysis of attack links and intelligent alarm noise reduction. The policy management layer has a built-in international and domestic compliance template library, combines natural language processing technology to parse custom rules, and automatically generates unified cross-cloud security policies; The automated execution layer is equipped with a closed-loop vulnerability management system and an AKSK permission governance module, supporting automated vulnerability remediation and dynamic AKSK permission management based on role profiles. The interactive display layer provides a visual interface for security situation presentation and interaction.
2. An AI-based multi-cloud security governance method, applied to the system described in claim 1, characterized in that: The following steps are involved: Data collection steps: AI Agent is used to collect resource data in a multi-cloud environment and perform standardized processing; Knowledge graph construction steps: Integrate business architecture and resource attribute information to build a dynamic and secure knowledge graph; Risk analysis step: Use a multimodal fusion model to analyze data and generate risk scores and attack path prediction results; Policy generation step: Generate a unified cross-cloud security policy based on compliance templates or custom rules; Automated processing steps: Perform operations such as vulnerability repair and AKSK permission adjustment, and feed the processing results back to the system for model optimization.
3. The system according to claim 1, wherein: The AI Agent adopts a differentiated collection strategy, collecting core resources incrementally every 10 seconds and fully synchronizing static configurations every 5 minutes, achieving initialization and management of multi-cloud assets within 1 minute, with a coverage rate of no less than 99%.
4. The system according to claim 1, wherein: The knowledge graph is stored in the Neo4j graph database, defines node types and relationship types, and uses an event-driven mechanism to achieve second-level updates of resource changes.
5. The system according to claim 1, wherein: The policy management layer has built-in international and domestic compliance templates, and uses natural language processing technology to parse the security rules entered by users into unified cross-cloud policies, including converting entity recognition results such as regions, protocols, and actions into security group rules or access control list configurations for corresponding cloud vendors.
6. The system according to claim 1, wherein: The vulnerability closed-loop management system is connected to the NVD vulnerability library and the cloud vendor's official patch library, updates vulnerability information daily, automatically matches repair solutions, and calls the cloud vendor's automated tools to perform repairs after authorization, with a repair success rate of no less than 90%.
7. The system according to claim 1, wherein: The AKSK permission management module builds role portraits based on characteristics such as operation time and resource access frequency, monitors abnormal operations in real time, and has a detection accuracy rate of no less than 98%. When an abnormality occurs, the circuit breaker mechanism is triggered and the entire link log is recorded.
8. The method according to claim 2, characterized in that In the data collection step, AI Agent supports breakpoint resuming and automatically recollects unsynchronized data after network interruption is restored.
9. The method according to claim 2, characterized in that In the knowledge graph construction step, an event-driven mechanism is adopted to trigger incremental updates of the graph when cloud resources change.
10. The method according to claim 2, characterized in that In the risk analysis step, intelligent alarm noise reduction is achieved through the following methods: Combine external threat intelligence with the company's historical alert data to train classification models; Automatically filter low-risk events, reduce the false alarm rate from 70% to below 10%, and prioritize high-risk alerts.
11. The method according to claim 2, characterized in that In the strategy generation step, transfer learning technology is used for industries such as finance and healthcare to fine-tune the AI model based on industry-specific compliance data, and complete strategy adaptation within 24 hours.
12. The method according to claim 2, characterized in that In the automated handling step, the vulnerability repair includes automatic repair and manual repair. When the automatic repair fails, the system automatically generates a manual handling work order and marks an alternative solution.
Citation Information
Cited By
Trusted cloud level AI intelligent library system based on formalization theory construction and query
CN121599135A
Method and device for constructing cloud native AI operation and maintenance auditing based on security control calculation
CN121887539A