Cloud Access Key Abuse Detection via Baseline Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based systems face increased security risks due to the extended enterprise network perimeter into the Internet, with unsecured and unmanaged devices posing threats to access key abuse detection.

Innovation Solution

A cloud-based system that receives activity data related to access keys, generates a baseline, monitors activities, and calculates a score for each activity based on a comparison to the baseline, sending alerts for high-risk activities and updating the baseline for low-risk activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cloud-based systems extend the enterprise network perimeter into the Internet to enable remote access, then user accessibility and flexibility are improved, but security risks and vulnerability to access key abuse increase

Engineering Contradiction:
Improveuser accessibilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by generating a baseline of normal access key activities before monitoring for anomalies. This baseline is created by analyzing historical activity data to establish what constitutes normal behavior, enabling the system to detect deviations that may indicate security threats before they cause harm.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback by monitoring access key activities, comparing them against the established baseline, and dynamically updating the baseline based on new information. This feedback loop enables adaptive security monitoring that improves detection accuracy over time while maintaining ease of access for legitimate users.

Inventive Principle:
Principle #23Feedback

2Reliability

If the system monitors all access key activities in real-time to detect abuse, then security detection capability is improved, but system complexity and computational resources increase

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts only the essential features and patterns from access key activity data that are relevant to detecting abuse. By focusing on specific behavioral indicators rather than analyzing every detail of all activities, the system maintains high detection capability while reducing computational complexity and resource requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes parameters by transforming raw activity data into normalized scores and comparisons against baseline values. This parameter transformation simplifies the monitoring process by converting complex activity patterns into comparable metrics that can be efficiently evaluated for anomalies.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If the system generates a baseline from historical activity data to identify normal usage, then accuracy in detecting anomalies is improved, but time for baseline generation and data processing increases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidbaseline generation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies partial action by generating the baseline from a representative subset of historical activity data rather than processing every single data point. This approach achieves sufficient detection accuracy while significantly reducing the time and computational resources required for baseline generation.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12341789B2Access key abuse detection
Publication Date: 2025.06.24 ZSCALER INC
  • US12341789B2 patent drawing
  • US12341789B2 patent drawing
  • US12341789B2 patent drawing

AI summary

Systems and methods for access key abuse detection, the systems and methods including steps of receiving activity data relating to an access key from cloud providers associated with a cloud-based system, generating a baseline for the access key based on the activity data, monitoring activities associated with the access key in the cloud-based system, and calculating a score for monitored activities based on a comparison of the monitored activities to the baseline. The present scoring system helps identify an abnormal and risky activity that indicates an attacker is abusing the access key. In addition, a baseline is created for a plurality of selected attributes that present the normal access key usage in order to identify malicious abnormal activities.