Multi-Cloud API Threat Mapping via Feature Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security solutions primarily focus on single cloud environments, limiting their effectiveness in identifying and addressing security threats related to interactions across diverse cloud environments.
Innovation Solution
A method for mapping API functions to threat actions in multiple cloud environments, utilizing a server that generates feature information for API functions, identifies matching API functions across different cloud environments, and maps these API functions to corresponding threat actions using an attack technique database.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security solutions focus on a single cloud environment, then the solution design is simple, but the effectiveness in identifying and addressing threats across diverse cloud environments is limited
Solution Approach 1:
The patent creates a universal security solution that operates across multiple cloud environments (AWS, Azure, GCP) by establishing a common threat action taxonomy and mapping mechanism. The system universally maps API functions from different cloud providers to standardized threat actions, enabling consistent threat identification and response across diverse cloud platforms without requiring separate security solutions for each environment.
Solution Approach 2:
The patent introduces an intermediary mapping layer between cloud-specific API functions and standardized threat actions. This intermediary mechanism translates diverse API functions from different cloud environments into a unified threat action representation, enabling the security system to handle multiple cloud environments through a single coordinated framework rather than requiring separate security systems for each cloud provider.
2Adaptability or versatility
If the system maps API functions from multiple cloud environments to threat actions, then the comprehensive security coverage is improved, but the system complexity increases
Solution Approach 1:
The patent transforms the complexity management by changing the representation parameters of threat actions. Instead of maintaining separate threat models for each cloud environment, the system uses a standardized parameter set of threat actions that can be universally applied. This parameter transformation allows the system to adapt to multiple cloud environments while maintaining a consistent internal representation, thereby reducing cognitive complexity despite increased versatility.
Solution Approach 2:
The patent segments the mapping process into distinct manageable components: (1) collecting API function descriptions from different cloud environments, (2) generating feature information from these descriptions, (3) matching features against a standardized threat action taxonomy, and (4) establishing mappings. This segmentation allows the complex task of multi-cloud threat mapping to be broken down into discrete, manageable steps that can be implemented systematically.
3Measurement precision
If the system generates feature information and identifies matching API functions across cloud environments, then the accuracy of threat identification is improved, but the processing time increases
Solution Approach 1:
The patent applies preliminary action by pre-establishing a standardized threat action taxonomy and pre-processing API function descriptions to extract key features before actual threat identification occurs. The system pre-defines the mapping criteria and feature extraction rules, so that when new API functions need to be analyzed, the system only needs to apply the pre-established mapping logic rather than creating mappings from scratch, significantly reducing processing time while maintaining high accuracy.
Data Source
AI summary
A method for mapping API functions to threat actions by a server in multiple cloud environments includes the steps of a) mapping a first API function used in a first cloud environment provided by a first cloud server to a first threat action included in an attack technique database where a plurality of threats classified into multiple types is stored, b) generating feature information of the first API function based on descriptive information for the first API function provided by the first cloud server, c) based on the feature information of the first API function, identifying a second API function matching the first API function among at least one API function used in a second cloud environment provided by a second cloud server, and d) mapping the second API function to the first threat action.


