Cloud Log Forensics Using Security Graph Vulnerability Tracing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing environments face vulnerabilities due to their shared and external nature, leading to potential cyberattacks that are difficult to detect and mitigate efficiently, as existing forensic methods are labor-intensive and impractical for large data volumes, often resulting in delayed response to cybersecurity breaches.

Innovation Solution

A method and system that utilize cloud logs and security graphs to automatically trace suspicious activities by detecting events, extracting identifiers, traversing security graphs to identify connected cybersecurity vulnerabilities, and initiating mitigation actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual examination of cloud logs is performed by security personnel, then detailed forensic analysis can be conducted, but the process is labor intensive and time consuming

Engineering Contradiction:
Improveforensic analysis accuracyVSAvoiddetection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent introduces an automated forensic analysis system that acts as an intermediary between cloud logs and security personnel. This system processes cloud logs, identifies suspicious events, and generates forensic reports automatically, eliminating the need for manual examination while maintaining high accuracy through structured analysis frameworks

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical manual examination process with an automated computational system. The system uses algorithms to detect suspicious events, traverse security graphs, and generate forensic reports, substituting human labor with machine-based automation that operates faster and without fatigue

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive cloud log monitoring is implemented, then all suspicious events can be detected, but the vast amount of data makes it impractical for human operators to identify events timely

Engineering Contradiction:
Improvedetection completenessVSAvoidevent processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a self-service automated system that independently processes cloud logs, identifies suspicious events, and generates forensic reports without human intervention. The system automatically traverses security graphs, correlates events, and produces actionable insights, enabling the organization to handle its own security analysis needs efficiently

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent transforms the unmanageable volume of raw log data into structured, analyzable information by changing parameters such as event classification categories, severity levels, and temporal aggregation. This transformation makes the data suitable for automated processing while maintaining detection completeness

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If specialized knowledge is required for manual forensic examination, then accurate breach detection can be achieved, but the knowledge is not easily transferable and requires extensive training

Engineering Contradiction:
Improvebreach detection accuracyVSAvoidoperator accessibility
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent introduces an automated forensic analysis system that encapsulates specialized knowledge within its algorithms and security graph structures. This intermediary translates complex forensic expertise into automated decision-making logic, making accurate breach detection accessible to operators without requiring extensive specialized training

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a digital copy of forensic expertise embedded in the automated system's algorithms, security graphs, and analysis frameworks. This copied knowledge can be consistently applied across multiple cases and operators, eliminating the need for individual expertise while maintaining high detection accuracy

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12615278B2Techniques for forensic tracing of suspicious activity from cloud computing logs
Publication Date: 2026.04.28 WIZ INC
  • US12615278B2 patent drawing
  • US12615278B2 patent drawing
  • US12615278B2 patent drawing

AI summary

A system and method traces suspicious activity to a workload based on a forensic log. The method includes detecting in at least one cloud log of a cloud computing environment a plurality of events, each event indicating an action in the cloud computing environment; extracting from an event of the plurality of events an identifier of a cloud entity, wherein the event includes an action which is predetermined as indicative of a suspicious event; traversing a security graph to detect a node representing the cloud entity, wherein the security graph further includes a representation of the cloud computing environment; detecting that the node representing the cloud entity is connected to a node representing a cybersecurity vulnerability; and initiating a mitigation action for the cloud entity based on the cybersecurity vulnerability.