Automated Cloud Infrastructure Compliance via IaC Graph Parsing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication and accreditation processes for cloud-based IT environments are manual and cumbersome, failing to provide the necessary elasticity and security for modern cloud environments, especially for public entities that require higher security standards.

Innovation Solution

A system that accesses an infrastructure-as-code (IaC) template for a virtualized and cloud-based IT environment, deconstructs it into a graph database representation using a parser, and determines the environment's state by implementing a predefined cloud resource ontology, providing a digital output on the environment's compliance and changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual authentication and accreditation processes are used for cloud-based IT environments, then security compliance can be verified, but the process becomes cumbersome and lacks elasticity

Engineering Contradiction:
Improvesecurity complianceVSAvoidprocess complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces manual mechanical processes (human reviewers physically examining configurations) with an automated computer-implemented system that uses machine learning models and algorithms to automatically analyze cloud infrastructure configurations, security controls, and compliance requirements, thereby eliminating the cumbersome manual nature while maintaining security compliance verification

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service by allowing the automated compliance checking system to independently perform authentication and accreditation processes without requiring manual human intervention for each review, while still providing reliable security compliance verification through automated analysis and decision-making

Inventive Principle:
Principle #25Self-service

2Reliability

If manual authentication and accreditation processes are used, then security standards can be enforced, but the processes lack elasticity for modern cloud environments

Engineering Contradiction:
Improvesecurity standardsVSAvoidelasticity
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic adaptability by designing the automated system to continuously learn from new cloud configurations, security threats, and compliance requirements through machine learning, allowing it to dynamically adjust its analysis methods and maintain security standards across diverse and evolving cloud environments without rigid manual processes

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system achieves universality by creating a multi-functional automated platform that can handle various cloud service models (IaaS, PaaS, SaaS), different compliance frameworks, and multiple security standards simultaneously, providing elastic adaptability across modern cloud environments while maintaining enforcement of security requirements

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If automated compliance checking is implemented, then production pace can be maintained, but complex analysis of infrastructure templates is required

Engineering Contradiction:
Improveproduction paceVSAvoidanalysis system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by breaking down the complex infrastructure template analysis into distinct modular components including separate machine learning models for different analysis tasks, individual processing modules for configuration examination, and segmented evaluation frameworks that can independently assess specific security controls while maintaining overall production pace

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10255370B2Automated compliance checking through analysis of cloud infrastructure templates
Publication Date: 2019.04.09 RAYTHEON CO
  • US10255370B2 patent drawing
  • US10255370B2 patent drawing
  • US10255370B2 patent drawing

AI summary

Systems and methods for determining a state of an information technology (IT) environment are disclosed. A server accesses an infrastructure-as-code (IaC) template for the IT environment, where the IT environment is virtualized and cloud-based. The server deconstructs, using a parser for the IaC template, the IaC template to a graph database representation of the IT environment, wherein the graph database representation implements a predefined cloud resource ontology (CRO). The server determines, using the graph database representation, the state of the IT environment. The server provides, as a digital transmission, an output corresponding to the determined state of the IT environment.