Cloud Identity Mapping Database for Coordinated Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud computing environments face challenges in quickly and accurately detecting complex and slow-developing malicious activities due to the structure and timeliness of data feeds, making it difficult to identify coordinated attacks across multiple identities.
Innovation Solution
A system and method for creating an identity mapping database that tracks relationships among user identities in a cloud environment, using audit logs, application programming interfaces, and workload scans to identify related identities and calculate threat scores based on joint probabilities of entity threat scores.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional logging and publication methods are used for cloud activities, then data is available for external consumption, but the structure and timeliness of the data feed make it difficult to quickly and accurately detect complex malicious activity
Solution Approach 1:
The patent combines multiple data sources including audit logs, resource properties, and workload information into a unified identity mapping database. This merging of previously separate data feeds into a single structured database enables comprehensive threat detection while simplifying the data structure, directly resolving the contradiction between detection reliability and data complexity
Solution Approach 2:
The identity mapping database serves as an intermediary layer between raw cloud activity data and threat detection analysis. This intermediate structured database transforms complex, multi-source data into a standardized format that improves both the accuracy of threat detection and the manageability of data structures
2Reliability
If traditional logging methods are used, then individual activities are recorded, but coordinated attacks across multiple identities remain obscured and difficult to detect
Solution Approach 1:
The patent merges data from multiple identities into unified entity records within the identity mapping database, preserving relationships between identities while consolidating information. This allows detection of coordinated attacks by analyzing patterns across previously separate identity data streams, resolving the contradiction between detecting coordinated attacks and preventing information loss
Solution Approach 2:
The patent adds a new dimension of analysis by organizing data around entity relationships rather than individual identities. This dimensional shift from identity-centric to relationship-centric data organization enables detection of coordinated attacks while preserving all original identity information through the relationship framework
3Reliability
If multiple data sources are integrated into an identity mapping database, then threat detection capability is improved, but the complexity of data collection and processing increases
Solution Approach 1:
The patent segments the data collection and processing system into distinct modular components: audit log processing, resource property fetching, workload information collection, and identity mapping database construction. This segmentation reduces overall complexity by making each component independent and manageable while maintaining the benefits of integrated multi-source data for improved threat detection
Data Source
AI summary
A variety of techniques are used to locate and characterize relationships among user identities in a cloud computing environment, and to create a persistent database of identity mappings. The resulting identity mapping database can enable improved threat detection in the cloud computing environment, particularly in cases where an attack might otherwise be obscured as a number of low-severity detections associated with different entities. For example, the identity mapping database can facilitate threat scoring for a group of related entities and the detection of attacks that are coordinated among two or more such identities. The identity mapping database may also or instead be used to identify an attacker that hides an attack by switching identities during the attack.


