AI Cloud Risk Scoring From Real-Time Activity Patterns
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud assets in cloud computing environments face challenges with complex management due to frequent creation, deletion, and changes, and there is a growing risk of hacking, making it difficult to quickly identify and respond to security anomalies.
Innovation Solution
An AI-based security risk prediction system that collects and classifies cloud and system logs, identifies new activities through machine learning, and calculates risk scores based on activity patterns and vulnerability diagnoses to predict potential security threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cloud assets are frequently created, deleted, and changed to meet diverse computing needs, then cloud service flexibility and adaptability improve, but management complexity increases and security risk identification becomes more difficult
Solution Approach 1:
The system segments cloud assets into organized hierarchies (regions, availability zones, accounts, resources) and applies AI analysis separately to each segment. This allows flexible asset management while maintaining security oversight through modular, scalable analysis units that can handle individual assets or groups independently.
Solution Approach 2:
The AI-based risk prediction system acts as an intermediary layer between cloud asset operations and security management. It automatically analyzes asset changes, identifies security risks, and provides predictions without requiring direct human intervention in the complex asset management process, thus maintaining flexibility while reducing management burden.
2Ease of manufacture
If traditional security monitoring methods are used to detect hacking risks, then implementation simplicity is maintained, but the ability to quickly identify and respond to security anomalies deteriorates
Solution Approach 1:
The system performs preliminary AI-based analysis of asset configurations, activity patterns, and vulnerability data before security incidents occur. By pre-establishing baselines and predicting potential risks in advance, the system enables faster response to actual anomalies while maintaining simple deployment through automated preprocessing of security data.
Solution Approach 2:
The patent replaces traditional manual or rule-based security monitoring with AI-based automated analysis. The AI model processes security data, identifies patterns, and predicts risks automatically, substituting complex mechanical monitoring processes with intelligent algorithms that improve both speed and simplicity simultaneously.
3Reliability
If comprehensive security analysis of all cloud assets is performed, then security coverage and reliability improve, but computational resources and analysis time increase
Solution Approach 1:
The system applies different levels of AI-based security analysis to different cloud assets based on their specific risk profiles, asset types, and vulnerability characteristics. High-value or high-risk assets receive more intensive analysis while lower-risk assets receive streamlined analysis, optimizing computational resource usage while maintaining comprehensive security coverage through differentiated quality of analysis.
Solution Approach 2:
The AI model dynamically adjusts analysis parameters such as scanning depth, frequency, and intensity based on asset criticality, historical risk data, and current threat levels. This parameter optimization allows the system to maintain high security reliability for critical assets while reducing computational overhead for less critical assets, achieving balanced resource utilization across the entire cloud environment.
Data Source
AI summary
Disclosed are artificial intelligence (AI)-based security risk prediction system and method for targets to be protected in a cloud environment. The method includes: collecting cloud logs and system logs for the targets to be protected in real time; learning all activity logs included in the cloud logs and the system logs for the targets to be protected of a corresponding member company through an AI algorithm; identifying a new activity among activities for the targets to be protected based on a learning process through the AI algorithm, and in response to the identified new activity being a new activity related to security, identifying a first activity pattern comprising the corresponding new activity; identifying an order of an preparatory activity for the new activity in the first activity pattern; identifying a risk score corresponding to the order of the preparatory activity for the new activity; and calculating a risk score of each target to be protected by summing identified risk scores of all new activities.


