Cloud Asset Resource Mapping for Improper Access Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Securing cloud native environments is challenging due to the need for manual management of numerous assets and adapting to frequent changes, especially in large enterprises with many employees accessing and modifying cloud resources.

Innovation Solution

A method and system for protecting cloud native environments by mapping cloud assets to resources based on access data, detecting improper access, and performing mitigation actions, including reconfiguring assets for active security and monitoring resource access to detect deviations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual management of cloud asset security posture is used, then security control is maintained, but operational complexity and time consumption increase significantly

Engineering Contradiction:
Improvesecurity controlVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service by having cloud assets automatically discover themselves, map to resources, and configure security postures without manual administrator intervention. Assets autonomously provide their own metadata and configuration information to the protection system.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by automatically discovering cloud assets and mapping them to resources before security issues arise. The protection system proactively configures security postures and detects improper access attempts before they cause damage.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual management of cloud asset security posture is used, then security control is maintained, but time consumption increases significantly

Engineering Contradiction:
Improvesecurity controlVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service by having cloud assets automatically discover themselves, map to resources, and configure security postures without manual administrator intervention. Assets autonomously provide their own metadata and configuration information to the protection system.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by automatically discovering cloud assets and mapping them to resources before security issues arise. The protection system proactively configures security postures and detects improper access attempts before they cause damage.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If cloud assets are made independent and modular for rapid scaling, then adaptability improves, but security management difficulty increases

Engineering Contradiction:
Improverapid scaling capabilityVSAvoidsecurity management difficulty
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements feedback mechanisms where cloud assets provide continuous updates about their resource access patterns and configurations. The protection system uses this feedback to automatically adjust security postures and detect deviations from expected behavior.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system enables self-service by having cloud assets automatically discover themselves, map to resources, and configure security postures without manual administrator intervention. Assets autonomously provide their own metadata and configuration information to the protection system.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12511414B2Techniques for protecting cloud native environments based on cloud resource access
Publication Date: 2025.12.30 PALO ALTO NETWORKS INC
  • US12511414B2 patent drawing
  • US12511414B2 patent drawing
  • US12511414B2 patent drawing

AI summary

A system and method for method for protecting cloud native environments based on cloud resource access. The method includes determining a mapping of a plurality of cloud assets to a plurality of cloud resources based on resource access data for a cloud native environment, wherein the plurality of cloud assets and the plurality of cloud resources are deployed in the cloud native environment, wherein each of the plurality of cloud assets is mapped to at least one associated cloud resource of the plurality of cloud resources; detecting at least one improper resource access based on the mapping and a cloud access security stream for the cloud native environment, wherein each of the at least one improper resource access deviates from the mapping; and performing at least one mitigation action with respect to the detected at least one improper resource access.