Cloud Database Snapshots for Data Posture Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in understanding the data posture and breadth of access to sensitive data stored in cloud environments, making it difficult to identify which users have access to which data and which data is exposed to unauthorized users, both inside and outside the organization, despite existing security infrastructures.

Innovation Solution

A cloud security posture analysis system that analyzes data posture using snapshots of cloud environment databases, employing a different authentication requirement to access these snapshots, generating representations of the databases, and scanning them to provide a data posture analysis result, while utilizing cloud provider roles for efficient access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cloud environments provide on-demand availability of computer resources without direct active management, then ease of operation is improved, but security visibility and control are worsened

Engineering Contradiction:
Improveease of operationVSAvoidsecurity visibility
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The system creates a snapshot copy of the cloud database to enable analysis of data posture and access requirements without affecting the actual production database. This copy allows security analysis while maintaining the on-demand availability and operational simplicity of the original cloud environment.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system introduces an intermediary analysis layer that examines snapshots and access control data to bridge the gap between operational simplicity and security visibility. This intermediary layer processes data to identify which users have access to which data without requiring direct management of the cloud resources themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If cloud storage services provide on-demand network access to shared pool of configurable resources, then adaptability is improved, but understanding data posture and access control becomes more difficult

Engineering Contradiction:
ImproveadaptabilityVSAvoiddata posture information
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The system performs preliminary analysis by creating snapshots of databases before security assessments are needed. This allows the system to proactively analyze data posture and access control configurations, maintaining adaptability while preventing information loss about data security posture.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system generates feedback by analyzing snapshots and access control data to identify security vulnerabilities and data exposure risks. This feedback mechanism provides visibility into data posture information that would otherwise be lost in the flexible, on-demand cloud environment.

Inventive Principle:
Principle #23Feedback

3Productivity

If organizations store sensitive data in cloud environments with multiple users, then productivity is improved, but identifying unauthorized access becomes more difficult

Engineering Contradiction:
ImproveproductivityVSAvoidunauthorized access detection
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The system segments the analysis process by examining individual user access requirements against the snapshot data structure. This segmentation allows the system to identify which specific users have access to which specific data, improving unauthorized access detection while maintaining the collaborative productivity enabled by multiple users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

By working with a snapshot copy rather than the live production database, the system can thoroughly analyze access control data and identify security vulnerabilities without interfering with ongoing user productivity. The snapshot provides a static view that facilitates comprehensive security assessment.

Inventive Principle:
Principle #26Copying

4Adaptability or versatility

If cloud environments use different authentication requirements for databases and snapshots, then adaptability is improved, but access control complexity increases

Engineering Contradiction:
ImproveadaptabilityVSAvoidaccess control complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system uses the snapshot as an intermediary object that bridges the authentication requirements of the cloud environment and the analysis needs of the security system. By analyzing the snapshot with different authentication requirements, the system manages access control complexity while maintaining adaptability to various cloud configurations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12388847B2Data posture analysis in a cloud environment using database snapshots
Publication Date: 2025.08.12 PROOFPOINT INC
  • US12388847B2 patent drawing
  • US12388847B2 patent drawing
  • US12388847B2 patent drawing

AI summary

The technology disclosed relates to streamlined analysis of security posture of a cloud environment. In particular, the disclosed technology relates to a system that analyzes data posture in a cloud environment database using a snapshot of the database. A computer-implemented method includes receiving a request to access a database in the cloud environment, wherein the database includes a first authentication requirement. The method includes identifying a snapshot of the database, wherein the snapshot includes a second authentication requirement that is different than the first authentication requirement. The method includes accessing the snapshot using the second authentication requirement, generating a representation of the database using the snapshot, and generating a data posture analysis result indicative of a data posture of the database based on scanning the representation of the database.