Cloud Identity Misuse Detection Using Runtime and Static Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud identity misuse detection systems face challenges due to the complexity of cloud environments, dynamic infrastructure, lack of standardized protocols, sophisticated attack techniques, and privacy concerns, leading to issues like false positives, missed detections, and incomplete visibility.

Innovation Solution

A system and method that utilizes a sensor application to detect runtime processes and inspect disks for cybersecurity objects through static analysis, generating enriched logs with associated identities and events, and applying cybersecurity policies to remediate threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If runtime data analysis and static analysis are used to detect cloud identity misuse, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the detection process into two distinct analysis paths: runtime data analysis (monitoring actual cloud identity activities) and static analysis (examining configuration files and policies). This segmentation allows each analysis type to specialize in its strength while working together through a unified detection framework, improving overall detection accuracy without creating monolithic complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary detection framework that bridges runtime data and static configuration analysis. This intermediary layer correlates findings from both analysis types, resolving conflicts and synthesizing results, thereby improving detection precision while managing system complexity through structured integration

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If comprehensive monitoring of cloud identity activities is implemented, then visibility into misuse is improved, but false positives increase

Engineering Contradiction:
ImprovevisibilityVSAvoidfalse positives
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The system merges runtime activity monitoring with static configuration analysis to achieve comprehensive visibility. By combining dynamic behavior data with contextual configuration information, the system can distinguish legitimate activities from actual misuse, reducing false positives while maintaining complete visibility into cloud identity activities

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The detection framework implements feedback mechanisms where results from runtime analysis inform static analysis priorities and vice versa. This feedback loop allows the system to learn from false positives and adjust detection thresholds, improving reliability while maintaining comprehensive monitoring coverage

Inventive Principle:
Principle #23Feedback

3Loss of information

If multiple cloud platforms are integrated for detection, then completeness of identity data is improved, but integration complexity increases

Engineering Contradiction:
Improvecompleteness of identity dataVSAvoidintegration complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent implements a universal detection framework that can interface with multiple cloud platforms through standardized adapters. This multi-functional architecture allows the same core detection logic to work across different cloud providers, improving data completeness while managing integration complexity through reuse of common components

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4672052A1Techniques for detecting cloud identity misuse based on runtime context and static analysis
Publication Date: 2025.12.31 WIZ INC
  • EP4672052A1 patent drawingFigure 1
  • EP4672052A1 patent drawingFigure 2
  • EP4672052A1 patent drawingFigure 3

AI summary

A system and method for identifying cloud identity misuse based on run-time time data and static analysis is presented. The method includes: detecting a workload in a cloud computing environment; configuring the workload to deploy a sensor configured to detect data respective of a runtime process executed on the workload; detecting an original disk associated with the workload; generating an inspectable disk based on the original disk; inspecting the inspectable disk for a cybersecurity object; detecting in a log of the cloud computing environment an event based on an identifier of the workload; inspecting a code object for an identity object, the code object utilized in deploying the workload in the cloud computing environment; associating the runtime process with the event based on: an identifier of the workload, the identity object, and the cybersecurity object; and generating an enriched log including an identifier of the runtime process.