Automated AWS Account Discovery and Security Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for managing and securing computing environments, especially in large organizations with complex account hierarchies, are prone to errors and require significant manual effort, relying heavily on the expertise of IT administrators, leading to potential oversight of important components and increased complexity with ephemeral AWS accounts.
Innovation Solution
An automated system for continuous discovery of computing components and services within organizational units, which uses a high-level account combined with organizational API capabilities to obtain temporary credentials, automatically determining the importance and service type of machines or components without manual registration, and providing a hierarchical structure for enhanced accessibility and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual account configuration and monitoring is performed in large organizations with thousands of AWS accounts, then access control and security can be maintained, but the process becomes repetitive, error-prone, and time-consuming
Solution Approach 1:
The system enables self-service automation where the account discovery component automatically discovers, configures, and monitors AWS accounts without requiring manual intervention. The system autonomously performs account hierarchy discovery, credential management, and resource inventory updates, eliminating the repetitive manual work while maintaining security and access control.
Solution Approach 2:
The patent replaces manual mechanical processes (administrators manually configuring accounts) with an automated computational system. The account discovery component uses API calls and automated credential assumption to discover and configure accounts programmatically, substituting human manual operations with automated software agents that can handle thousands of accounts efficiently.
2Loss of information
If individual account querying is performed to fetch resources and services, then complete inventory data can be obtained, but the process is tedious and time-consuming for large numbers of accounts
Solution Approach 1:
The system merges individual account discovery operations into a unified automated process. The account discovery component simultaneously discovers multiple accounts and their hierarchies by making coordinated API calls, combining what would be thousands of separate manual operations into a single automated workflow that efficiently retrieves complete inventory data across all accounts.
Solution Approach 2:
The system performs preliminary automated account discovery and hierarchy mapping before resource inventory collection. By pre-establishing the account hierarchy structure and credentials through automated assumption processes, the system prepares the groundwork that enables efficient subsequent inventory gathering across all discovered accounts without requiring repeated setup operations.
3Ease of operation
If control accounts assume roles in linked accounts to obtain temporary credentials, then access to linked accounts is enabled, but there is no way to understand which linked accounts trust which control account
Solution Approach 1:
The account discovery component implements feedback mechanisms that automatically query and map trust relationships between control accounts and linked accounts. By systematically attempting credential assumption and analyzing API responses, the system builds and maintains an accurate representation of which linked accounts trust which control accounts, providing visibility into the trust topology without manual configuration.
Data Source
AI summary
A feature selection methodology is disclosed. In a computer-implemented method, components of a computing environment are automatically monitored, and have a feature selection analysis performed thereon. Provided the feature selection analysis determines that features of the components are well defined, a classification of the features is performed. Provided the feature selection analysis determines that features of the components are not well-defined access to those features are discarded. Results of the feature selection methodology are generated.


