Cloud Native Security Agent for Asset Discovery and Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud native environments face challenges in securing and managing the security posture of numerous assets across different geographical locations, especially in larger enterprises where manual management is impractical due to frequent changes and large-scale deployments.
Innovation Solution
A method and system for cloud native discovery and protection that identifies cloud assets using API endpoints, determines which assets lack active security protection, and reconfigures the environment to ensure all assets have active security measures in place, utilizing cloud credentials and metadata for continuous monitoring and mitigation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual management of cloud asset security posture is implemented, then security protection can be applied to cloud assets, but the complexity and impracticality increases significantly in larger enterprises with frequent changes and large-scale deployments
Solution Approach 1:
The system enables self-service automation where the cloud environment automatically discovers assets, evaluates their security posture, and applies protective configurations without human intervention. The automated agent continuously monitors and self-adjusts security settings based on detected changes in the cloud native environment.
Solution Approach 2:
The system performs preliminary security configurations and protective measures before security vulnerabilities or threats are detected. By continuously monitoring and pre-configuring security policies, the system prepares protective measures in advance rather than reacting to security incidents after they occur.
2Reliability
If manual management of cloud asset security is implemented, then security posture can be maintained, but the time and resources required become unsustainable in dynamic cloud native environments
Solution Approach 1:
The system implements continuous security monitoring and protection rather than periodic manual checks. The automated agent continuously evaluates security posture, detects changes in real-time, and maintains protective configurations without interruption, ensuring uninterrupted security coverage across all cloud assets.
Solution Approach 2:
The automated security management system operates autonomously without requiring continuous human time investment. Once deployed, the system self-manages security posture evaluation, asset discovery, and configuration application, freeing organizational resources while maintaining constant security protection.
3Reliability
If comprehensive security monitoring of all cloud assets is implemented, then security breaches can be detected, but the complexity of tracking and managing numerous assets across different geographical locations increases
Solution Approach 1:
The automated security agent implements a universal approach that works across diverse cloud assets including containers, microservices, serverless functions, and virtual machines regardless of their location or type. The system uses standardized evaluation criteria and protective configurations that can be applied uniformly across all cloud native assets, simplifying management while maintaining comprehensive coverage.
Solution Approach 2:
The automated security agent acts as an intermediary between cloud assets and security management, centralizing the complexity of tracking and monitoring numerous distributed assets. The agent mediates between the diverse cloud infrastructure and security policies, translating various asset types into a unified security evaluation framework that simplifies overall management.
Data Source
AI summary
A system and method for cloud native discovery and protection. The method includes discovering instances of a plurality of cloud assets in a cloud native environment based on a plurality of application programming interface (API) endpoints in the cloud native environment, wherein the plurality of API endpoints is identified based on cloud credentials for each of the plurality of cloud assets; determining at least one cloud asset instance that lacks active security protection based on a configuration of at least one entity deployed in the cloud native environment; and reconfiguring at least a portion of the cloud native environment with respect to the at least one cloud asset instance that lacks active security protection.


