Cloud Critical Asset Identification and Protective Action Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing environments face challenges in identifying and prioritizing critical assets for enhanced security measures, as malicious entities target these environments to exploit resources for their own purposes, necessitating improved techniques for asset classification and protective action.

Innovation Solution

A system and method for identifying critical assets within a cloud-based computing environment by analyzing configuration data to determine asset criticality, enabling prioritization of protective actions and security measures for these assets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If automated analysis of configuration data is implemented to identify critical assets, then security measurement precision is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity measurement precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the asset identification process into distinct functional modules: configuration data reception module, analysis result generation module, critical asset determination module, and prioritization action module. Each module handles a specific aspect of the analysis, making the complex system manageable and maintainable while achieving precise security measurements through systematic data processing

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary analysis result generation step that processes configuration data before final critical asset determination. This intermediary layer acts as a mediator between raw configuration data and security decisions, enabling precise asset identification while managing system complexity through structured data transformation and analysis

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive configuration data analysis is performed on all assets, then security reliability is improved, but processing time increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by receiving and analyzing configuration data continuously before security threats materialize. Critical assets are identified and prioritized in advance through automated analysis, enabling security measures to be prepared beforehand rather than reacting to threats in real-time, thus improving reliability without excessive processing delays

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial action by focusing analysis resources on generating prioritization results for critical assets rather than uniformly processing all assets with equal depth. The system performs comprehensive analysis only where necessary to identify and prioritize critical assets, reducing overall processing time while maintaining security reliability for the most important assets

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250335585A1Automatic identification of critical assets and protective action prioritization
Publication Date: 2025.10.30 MICROSOFT TECHNOLOGY LICENSING LLC
  • US20250335585A1 patent drawing
  • US20250335585A1 patent drawing
  • US20250335585A1 patent drawing

AI summary

Critical assets are identified, and protective actions are prioritized. In an aspect, configuration data associated with a first asset is received. An analysis result is generated based on an analysis of the configuration data. The first asset is determined to be a critical asset based on the analysis result. A prioritization action is performed based on the determination that the first asset is a critical asset. In a further aspect, a protective action is determined based on the analysis result. In another further aspect, a security vulnerability of the first asset is identified and resolved. In still another aspect, a protective action of the first asset is prioritized over a protective action of another asset.