Cloud Native Security Agent for Asset Discovery and Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud native environments face challenges in securing and managing the security posture of numerous assets across different geographical locations, especially in larger enterprises where manual management is impractical due to frequent changes and large-scale deployments.

Innovation Solution

A method and system for cloud native discovery and protection that identifies cloud assets using API endpoints, determines which assets lack active security protection, and reconfigures the environment to ensure all assets have active security measures in place, utilizing cloud credentials and metadata for continuous monitoring and mitigation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual management of cloud asset security posture is implemented, then security protection can be applied to cloud assets, but the complexity and impracticality increases significantly in larger enterprises with frequent changes and large-scale deployments

Engineering Contradiction:
Improvesecurity protectionVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service automation where the cloud environment automatically discovers assets, evaluates their security posture, and applies protective configurations without human intervention. The automated agent continuously monitors and self-adjusts security settings based on detected changes in the cloud native environment.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary security configurations and protective measures before security vulnerabilities or threats are detected. By continuously monitoring and pre-configuring security policies, the system prepares protective measures in advance rather than reacting to security incidents after they occur.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual management of cloud asset security is implemented, then security posture can be maintained, but the time and resources required become unsustainable in dynamic cloud native environments

Engineering Contradiction:
Improvesecurity postureVSAvoidmanagement time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements continuous security monitoring and protection rather than periodic manual checks. The automated agent continuously evaluates security posture, detects changes in real-time, and maintains protective configurations without interruption, ensuring uninterrupted security coverage across all cloud assets.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The automated security management system operates autonomously without requiring continuous human time investment. Once deployed, the system self-manages security posture evaluation, asset discovery, and configuration application, freeing organizational resources while maintaining constant security protection.

Inventive Principle:
Principle #25Self-service

3Reliability

If comprehensive security monitoring of all cloud assets is implemented, then security breaches can be detected, but the complexity of tracking and managing numerous assets across different geographical locations increases

Engineering Contradiction:
Improvesecurity detectionVSAvoidtracking complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The automated security agent implements a universal approach that works across diverse cloud assets including containers, microservices, serverless functions, and virtual machines regardless of their location or type. The system uses standardized evaluation criteria and protective configurations that can be applied uniformly across all cloud native assets, simplifying management while maintaining comprehensive coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The automated security agent acts as an intermediary between cloud assets and security management, centralizing the complexity of tracking and monitoring numerous distributed assets. The agent mediates between the diverse cloud infrastructure and security policies, translating various asset types into a unified security evaluation framework that simplifies overall management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11689576B2Cloud native discovery and protection
Publication Date: 2023.06.27 PALO ALTO NETWORKS INC
  • US11689576B2 patent drawing
  • US11689576B2 patent drawing
  • US11689576B2 patent drawing

AI summary

A system and method for cloud native discovery and protection. The method includes discovering instances of a plurality of cloud assets in a cloud native environment based on a plurality of application programming interface (API) endpoints in the cloud native environment, wherein the plurality of API endpoints is identified based on cloud credentials for each of the plurality of cloud assets; determining at least one cloud asset instance that lacks active security protection based on a configuration of at least one entity deployed in the cloud native environment; and reconfiguring at least a portion of the cloud native environment with respect to the at least one cloud asset instance that lacks active security protection.