Cloud Log Forensics Using Security Graph Vulnerability Tracing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud computing environments face vulnerabilities due to their shared and external nature, leading to potential cyberattacks that are difficult to detect and mitigate efficiently, as existing forensic methods are labor-intensive and impractical for large data volumes, often resulting in delayed response to cybersecurity breaches.
Innovation Solution
A method and system that utilize cloud logs and security graphs to automatically trace suspicious activities by detecting events, extracting identifiers, traversing security graphs to identify connected cybersecurity vulnerabilities, and initiating mitigation actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual examination of cloud logs is performed by security personnel, then detailed forensic analysis can be conducted, but the process is labor intensive and time consuming
Solution Approach 1:
The patent introduces an automated forensic analysis system that acts as an intermediary between cloud logs and security personnel. This system processes cloud logs, identifies suspicious events, and generates forensic reports automatically, eliminating the need for manual examination while maintaining high accuracy through structured analysis frameworks
Solution Approach 2:
The patent replaces the mechanical manual examination process with an automated computational system. The system uses algorithms to detect suspicious events, traverse security graphs, and generate forensic reports, substituting human labor with machine-based automation that operates faster and without fatigue
2Reliability
If comprehensive cloud log monitoring is implemented, then all suspicious events can be detected, but the vast amount of data makes it impractical for human operators to identify events timely
Solution Approach 1:
The patent implements a self-service automated system that independently processes cloud logs, identifies suspicious events, and generates forensic reports without human intervention. The system automatically traverses security graphs, correlates events, and produces actionable insights, enabling the organization to handle its own security analysis needs efficiently
Solution Approach 2:
The patent transforms the unmanageable volume of raw log data into structured, analyzable information by changing parameters such as event classification categories, severity levels, and temporal aggregation. This transformation makes the data suitable for automated processing while maintaining detection completeness
3Measurement precision
If specialized knowledge is required for manual forensic examination, then accurate breach detection can be achieved, but the knowledge is not easily transferable and requires extensive training
Solution Approach 1:
The patent introduces an automated forensic analysis system that encapsulates specialized knowledge within its algorithms and security graph structures. This intermediary translates complex forensic expertise into automated decision-making logic, making accurate breach detection accessible to operators without requiring extensive specialized training
Solution Approach 2:
The patent creates a digital copy of forensic expertise embedded in the automated system's algorithms, security graphs, and analysis frameworks. This copied knowledge can be consistently applied across multiple cases and operators, eliminating the need for individual expertise while maintaining high detection accuracy
Data Source
AI summary
A system and method traces suspicious activity to a workload based on a forensic log. The method includes detecting in at least one cloud log of a cloud computing environment a plurality of events, each event indicating an action in the cloud computing environment; extracting from an event of the plurality of events an identifier of a cloud entity, wherein the event includes an action which is predetermined as indicative of a suspicious event; traversing a security graph to detect a node representing the cloud entity, wherein the security graph further includes a representation of the cloud computing environment; detecting that the node representing the cloud entity is connected to a node representing a cybersecurity vulnerability; and initiating a mitigation action for the cloud entity based on the cybersecurity vulnerability.


