Normalized Cloud Event Logs for Unified Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity threat detection solutions for cloud computing infrastructures are ineffective across multiple platforms due to inconsistencies in AI/ML outputs, lack of transparency, and the need for separate management of each environment, leading to potential gaps in threat detection and response.

Innovation Solution

A method and system for generating a normalized event log across multiple cloud service providers using a predefined data schema, storing it in a transactional database, and applying a unified rule engine to detect cybersecurity threats, thereby ensuring consistent and unified threat detection across different cloud environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If separate AI/ML solutions are used for each cloud computing infrastructure, then each infrastructure can have customized threat detection, but the solutions do not communicate with each other and require independent management, leading to inconsistency and gaps in threat detection

Engineering Contradiction:
Improvecustomized threat detectionVSAvoidindependent management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple cloud-specific threat detection solutions into a single multi-cloud threat detection platform. The normalization layer consolidates event logs from different cloud providers (AWS, Azure, GCP) into a unified format, allowing a single AI/ML engine to analyze threats across all cloud infrastructures simultaneously, eliminating the need for separate managed solutions.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal threat detection system that can process and analyze event logs from multiple cloud computing infrastructures through a single platform. The normalization layer enables the system to handle diverse cloud event formats universally, allowing one AI/ML model to perform threat detection across AWS, Azure, GCP, and other cloud environments without requiring infrastructure-specific customization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If AI models are used for anomaly detection in event logs, then detection capability is enhanced, but the models are not transparent and may change output based on processing order, leading to inconsistent threat detection

Engineering Contradiction:
Improvedetection capabilityVSAvoidoutput consistency
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent applies preliminary normalization to event logs before they are processed by AI/ML models. By standardizing the format, schema, and structure of event logs from different cloud providers in advance, the system ensures that AI models receive consistent input data regardless of the cloud source, thereby producing consistent and reliable detection outputs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The normalization layer acts as an intermediary between raw cloud event logs and AI/ML processing. This intermediary component transforms diverse cloud-specific event formats into a unified normalized schema, ensuring that AI models process standardized data structures, which improves output consistency and transparency while maintaining high detection capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple cloud environments are deployed to take advantage of different offerings, then service capabilities are enhanced, but managing these environments becomes challenging and cybersecurity risks increase

Engineering Contradiction:
Improveservice capabilitiesVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements a universal threat detection platform that can operate across multiple cloud environments simultaneously. The system provides a single management interface that can detect and respond to threats in AWS, Azure, GCP, and other cloud infrastructures, simplifying the management of multi-cloud security while maintaining the ability to leverage diverse cloud service capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If cloud computing infrastructures are used to reduce costs and improve flexibility, then resource efficiency is enhanced, but cybersecurity threats may present themselves across distributed environments, making detection difficult

Engineering Contradiction:
Improveresource efficiencyVSAvoidthreat detection
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent combines threat detection capabilities across distributed cloud environments into a unified analysis platform. By aggregating and normalizing event logs from multiple cloud infrastructures, the system enables centralized threat detection that can identify cross-cloud attack patterns while maintaining the resource efficiency benefits of distributed cloud computing.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250350612A1System and method for threat detection across multiple cloud environments utilizing normalized event logs
Publication Date: 2025.11.13 WIZ INC
  • US20250350612A1 patent drawing
  • US20250350612A1 patent drawing
  • US20250350612A1 patent drawing

AI summary

A system and method for improving CDR from a plurality of CSPs is presented. The method includes receiving a first event a first CSP and a second event from a second CSP; generating a first normalized event based on data extracted from the first event and a predefined data schema; generating a second normalized event based on data extracted from the second event and the predefined data schema; storing the first normalized event and the second normalized event in a normalized log; detecting a cybersecurity threat based on an event of the normalized log; extracting from the event an identifier of a cloud entity; querying a security database to detect a representation the cloud entity; determining that the detected representation is associated with a cybersecurity risk; and initiating an active response in a cloud computing environment associated with the cloud entity, based on the cybersecurity risk and the detected threat.