Multi-Cloud API Threat Mapping via Feature Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security solutions primarily focus on single cloud environments, limiting their effectiveness in identifying and addressing security threats related to interactions across diverse cloud environments.

Innovation Solution

A method for mapping API functions to threat actions in multiple cloud environments, utilizing a server that generates feature information for API functions, identifies matching API functions across different cloud environments, and maps these API functions to corresponding threat actions using an attack technique database.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security solutions focus on a single cloud environment, then the solution design is simple, but the effectiveness in identifying and addressing threats across diverse cloud environments is limited

Engineering Contradiction:
Improveeffectiveness in identifying and addressing threatsVSAvoidsolution design complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal security solution that operates across multiple cloud environments (AWS, Azure, GCP) by establishing a common threat action taxonomy and mapping mechanism. The system universally maps API functions from different cloud providers to standardized threat actions, enabling consistent threat identification and response across diverse cloud platforms without requiring separate security solutions for each environment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary mapping layer between cloud-specific API functions and standardized threat actions. This intermediary mechanism translates diverse API functions from different cloud environments into a unified threat action representation, enabling the security system to handle multiple cloud environments through a single coordinated framework rather than requiring separate security systems for each cloud provider.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the system maps API functions from multiple cloud environments to threat actions, then the comprehensive security coverage is improved, but the system complexity increases

Engineering Contradiction:
Improvesecurity coverage across cloud environmentsVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent transforms the complexity management by changing the representation parameters of threat actions. Instead of maintaining separate threat models for each cloud environment, the system uses a standardized parameter set of threat actions that can be universally applied. This parameter transformation allows the system to adapt to multiple cloud environments while maintaining a consistent internal representation, thereby reducing cognitive complexity despite increased versatility.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent segments the mapping process into distinct manageable components: (1) collecting API function descriptions from different cloud environments, (2) generating feature information from these descriptions, (3) matching features against a standardized threat action taxonomy, and (4) establishing mappings. This segmentation allows the complex task of multi-cloud threat mapping to be broken down into discrete, manageable steps that can be implemented systematically.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If the system generates feature information and identifies matching API functions across cloud environments, then the accuracy of threat identification is improved, but the processing time increases

Engineering Contradiction:
Improveaccuracy of threat identificationVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-establishing a standardized threat action taxonomy and pre-processing API function descriptions to extract key features before actual threat identification occurs. The system pre-defines the mapping criteria and feature extraction rules, so that when new API functions need to be analyzed, the system only needs to apply the pre-established mapping logic rather than creating mappings from scratch, significantly reducing processing time while maintaining high accuracy.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250181414A1Method for mapping API functions to threat actions in multiple cloud environments
Publication Date: 2025.06.05 ASTRON SECURITY INC
  • US20250181414A1 patent drawing
  • US20250181414A1 patent drawing
  • US20250181414A1 patent drawing

AI summary

A method for mapping API functions to threat actions by a server in multiple cloud environments includes the steps of a) mapping a first API function used in a first cloud environment provided by a first cloud server to a first threat action included in an attack technique database where a plurality of threats classified into multiple types is stored, b) generating feature information of the first API function based on descriptive information for the first API function provided by the first cloud server, c) based on the feature information of the first API function, identifying a second API function matching the first API function among at least one API function used in a second cloud environment provided by a second cloud server, and d) mapping the second API function to the first threat action.