Cloud Resource Log Analysis for Cross-Resource Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud resource security systems focus on endpoint protection, failing to detect sophisticated attacks that span multiple cloud resources and require a holistic organizational view, such as phishing and data exfiltration.
Innovation Solution
A method using cloud resource management logs and collaborative filtering to analyze user operations across an organization, generating a bipartite graph and scoring actions for anomalies, providing alerts on suspicious activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If endpoint protection techniques are used, then individual user or resource security is improved, but detection of sophisticated attacks spanning multiple cloud resources deteriorates
Solution Approach 1:
The patent merges individual user/resource monitoring data into an organizational-level view by combining logs from multiple cloud resources. The system integrates user operations across different resources into a unified analysis framework, enabling detection of attacks that span multiple endpoints simultaneously.
Solution Approach 2:
The patent transitions from monitoring at the individual user or resource level to organizational-level monitoring. This dimensional shift allows the system to observe patterns across multiple resources and users, revealing sophisticated attacks that would be invisible at lower levels of granularity.
2Difficulty of detecting and measuring
If cloud resource management logs are analyzed at organizational level, then detection of complex attacks is improved, but system complexity increases
Solution Approach 1:
The patent segments the analysis process into distinct components: log collection from multiple resources, data aggregation at organizational level, anomaly detection using machine learning models, and alert generation. This segmentation makes the complex system more manageable and maintainable while preserving its enhanced detection capability.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Generally discussed herein are devices, systems, and methods for improving cloud resource security. A method can include obtaining a cloud resource management log that details actions performed by users of cloud resources in a cloud portal, the actions including entries comprising at least two of a user identification (ID) of a user of the users, an operation of operations performed on the cloud resource, a uniform resource identifier (URI) of a cloud resource of the cloud resources that is a target of the operation, or a time the operation was performed. The method can include determining a respective score for each action in the cloud resource management log, comparing the respective score to a specified criterion, and providing an indication of anomalous action in response to determining the respective score satisfies the specified criterion.