Cloud Service Anomaly Filtering via Trusted Location Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in managing risk exposure associated with cloud-based services due to the lack of enterprise-level controls when users access these services from diverse locations, leading to potential security threats and the need for effective anomaly detection and filtering.
Innovation Solution
A system and method for detecting anomalies in cloud service usage activities using trusted location analysis, which designates locations as trusted or non-trusted based on user activity logs, filters out low-risk anomalies, and upgrades/downgrades risk levels, allowing for focused investigation on high-risk anomalies from non-trusted locations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cloud-based services are adopted to support business operations from diverse locations, then accessibility and flexibility are improved, but security risk exposure increases due to lack of enterprise-level controls
Solution Approach 1:
The patent introduces an intermediary system that acts as a mediator between cloud service users and the enterprise security infrastructure. This intermediary analyzes user locations, activity patterns, and cloud service usage to dynamically apply security controls, enabling secure access from diverse locations while maintaining enterprise-level security posture without requiring direct integration with every cloud service provider.
Solution Approach 2:
The system dynamically changes security parameters based on user location and behavior patterns. By monitoring location data and activity characteristics, the system adjusts security controls (such as access permissions, authentication requirements, and monitoring intensity) in real-time, allowing flexible access while adapting security measures to the specific risk context of each user location.
2Reliability
If anomaly detection systems monitor all cloud service activities, then security coverage is improved, but the volume of anomalies requiring investigation increases
Solution Approach 1:
The system performs preliminary analysis of user locations and activity patterns before anomalies are detected. By establishing baseline behavior patterns and trusted location profiles in advance, the system can pre-filter and prioritize anomalies based on their likelihood of being malicious, reducing the number of false positives and low-risk anomalies that require manual investigation while maintaining comprehensive security coverage.
Solution Approach 2:
The anomaly detection system is segmented into multiple analysis layers that process different types of data at different levels of detail. The system segments security monitoring into location-based analysis, behavior-based analysis, and activity-based analysis, allowing selective investigation of anomalies based on their classification and risk level, thereby reducing the total number of anomalies requiring full investigation.
3Measurement precision
If manual investigation of all detected anomalies is performed, then thoroughness is improved, but time consumption and operational burden increase
Solution Approach 1:
The system implements self-service anomaly analysis where automated location-based filtering and risk assessment mechanisms independently evaluate and triage anomalies without requiring manual intervention for all cases. The system automatically identifies trusted locations, applies behavior-based filtering, and prioritizes investigations based on risk scores, allowing thorough analysis of high-risk anomalies while automatically handling low-risk cases, thereby reducing time consumption and operational burden.
Data Source
AI summary
A system and method for filtering detected anomalies in cloud service usage activities associated with an enterprise uses a trusted location analysis to filter detected anomalies. The locations from which the cloud usage activities are made are analyzed and designated as trusted or non-trusted. The trusted location determination is used to filter the detected anomalies that are associated with trusted locations and therefore may be of low risk. In this manner, actions can be taken only on detected anomalies that are associated with non-trusted locations and therefore may be high risk. The system and method of the present invention enable security incidents, anomalies and threats from cloud activity to be detected, filtered and annotated based on the location heuristics. The trusted location analysis identifies trusted locations automatically using cloud activity usage data and does not rely on potentially unreliable location data from user input.


