Event-Driven Cloud Compliance Scanning and Root Cause Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current compliance scanning tools in enterprise information handling systems (IHS) are inadequate as they rely on calendar-based scans, leading to delayed detection of non-compliant configurations, which can result in security vulnerabilities and incorrect root cause analysis, especially in large and complex cloud environments.

Innovation Solution

An automated system that performs real-time configuration scans and root cause analysis by comparing current configuration information with baseline data, invoking remediation operations immediately upon detecting non-compliant changes, and using advanced data processing technologies like HADOOP and AI for pattern recognition across large datasets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If calendar-based compliance scans are used, then infrastructure requirements are reduced, but detection timeliness deteriorates leading to delayed vulnerability identification

Engineering Contradiction:
Improvecompliance detection reliabilityVSAvoiddetection delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system transitions from static calendar-based scanning to dynamic event-driven scanning. Compliance scans are automatically triggered by configuration change events detected through continuous monitoring, allowing the system to adapt scan timing to actual risk conditions. This resolves the contradiction by making detection timely (reducing loss of time) while maintaining automated resource management (preserving reliability).

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements continuous feedback loops where configuration changes are monitored in real-time, triggering immediate compliance scans when changes occur. This feedback mechanism ensures that compliance issues are detected promptly after configuration changes, eliminating detection delays while maintaining automated infrastructure management.

Inventive Principle:
Principle #23Feedback

2Productivity

If automated remediation is implemented, then compliance correction speed is improved, but false negatives increase due to masking underlying issues

Engineering Contradiction:
Improvecompliance correction speedVSAvoidroot cause information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The system performs preliminary root cause analysis and documentation before automated remediation executes. Configuration changes are tracked and analyzed to identify underlying causes, and this information is preserved in a database before remediation actions are taken. This ensures that while automated remediation maintains fast correction speed, the root cause information is captured and analyzed separately to prevent false negatives.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If frequent compliance scans are performed, then detection accuracy is improved, but system resource consumption increases

Engineering Contradiction:
Improvecompliance detection accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system implements periodic compliance scans triggered by configuration change events rather than continuous scanning. When a configuration change is detected, a compliance scan is automatically initiated; if no changes occur, scanning is suspended. This event-driven periodic action maintains high detection accuracy for relevant changes while significantly reducing unnecessary resource consumption during stable periods.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system focuses compliance scanning resources on specific configuration elements that have changed, rather than performing full-system scans. By identifying and scanning only the affected configuration areas triggered by events, the system achieves high detection accuracy for critical changes while minimizing overall computational resource consumption.

Inventive Principle:
Principle #3Local quality

4Measurement precision

If manual root cause analysis processes are used, then analysis thoroughness is improved, but response time deteriorates allowing vulnerabilities to persist

Engineering Contradiction:
Improveroot cause analysis thoroughnessVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system implements automated root cause analysis capabilities that self-analyze configuration changes and compliance violations. Configuration monitoring agents collect data, event detectors identify changes, and compliance evaluators automatically assess violations. This automated self-service analysis maintains thoroughness by systematically examining all relevant configuration data while reducing response time by eliminating manual analysis delays.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary automated analysis of configuration changes and compliance violations immediately when events occur. Root cause information is gathered and documented in advance, enabling rapid response while maintaining analytical thoroughness through automated examination of all relevant configuration data and change history.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11165643B1Cloud compliance drift automation and root cause analysis tool
Publication Date: 2021.11.02 WELLS FARGO BANK NA
  • US11165643B1 patent drawing
  • US11165643B1 patent drawing
  • US11165643B1 patent drawing

AI summary

Automatic detection and remediation of a noncompliant configuration of an information handling system is disclosed. A determination is made whether a triggering event has occurred that has a potential for degrading compliance of the information handling system. In response to determining that the triggering event has occurred, a configuration scan of the hardware and software of the information handling system is performed to obtain current configuration information. The current configuration information is compared to baseline configuration information that was obtained in response to a previous triggering event. Subsequently, a determination is made as to whether any changes determined in the current configuration information are non-compliant based on a comparison to compliance status information. One or more compliance remediation operations are invoked in response to determining that at least one change is non-compliant.