Cloud Native Security System for Misconfiguration Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security practices fail to effectively develop compliant cloud native applications due to infrastructure security misconfigurations and unaddressed security violations, leading to non-compliance issues, monetary penalties, and loss of trust for cloud service providers.

Innovation Solution

A security system that receives cloud application data, performs dynamic flow analysis, identifies sensitive attributes and assets, uses machine learning to detect misconfigurations, and generates remediation actions to correct these issues, ensuring compliance and security in cloud computing environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If current security practices are used to develop cloud native applications, then development speed and ease of deployment are improved, but security compliance and reliability deteriorate due to infrastructure security misconfigurations and unaddressed security violations

Engineering Contradiction:
Improvedevelopment speedVSAvoidsecurity compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary security analysis by generating a data flow graph and identifying sensitive attributes and assets before deployment. Security misconfigurations and violations are detected in advance, allowing developers to correct issues before they become compliance problems, thus maintaining both development speed and security reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides automated feedback by analyzing cloud application data, identifying security issues, and generating remediation recommendations. This feedback loop enables developers to quickly understand and fix security misconfigurations, maintaining productivity while improving security compliance through iterative corrections.

Inventive Principle:
Principle #23Feedback

2Reliability

If comprehensive security analysis is performed on cloud applications, then security compliance and reliability are improved, but computational resources and time consumption increase

Engineering Contradiction:
Improvesecurity complianceVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system extracts only the critical elements needed for security analysis by identifying sensitive attributes and assets from the cloud application data flow. Instead of analyzing the entire application comprehensively, it focuses on extracting and analyzing only the sensitive data sources and assets, reducing computational overhead while maintaining security compliance.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies different analysis depths to different parts of the cloud application. It performs detailed analysis on sensitive assets and data sources identified through the data flow graph, while using lighter analysis on non-sensitive components. This localized quality approach ensures security compliance is maintained for critical areas without wasting computational resources on non-essential analysis.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If manual security assessment and remediation processes are used, then accuracy in identifying misconfigurations is improved, but time consumption and operational complexity increase

Engineering Contradiction:
Improveaccuracy in identifying misconfigurationsVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs automated self-assessment of cloud application security by generating data flow graphs, identifying sensitive attributes, and detecting misconfigurations without manual intervention. The automated machine learning models maintain high accuracy in identifying security issues while significantly reducing the time consumption associated with manual security assessment processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces manual mechanical security assessment processes with automated computational analysis. Machine learning models and automated data flow analysis substitute for human analysts, maintaining measurement precision in identifying misconfigurations while eliminating the time loss and operational complexity of manual review processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20240005032A1Discovering, assessing, and remediating cloud native application risks due to security misconfigurations
Publication Date: 2024.01.04 ACCENTURE GLOBAL SOLUTIONS LTD
  • US20240005032A1 patent drawing
  • US20240005032A1 patent drawing
  • US20240005032A1 patent drawing

AI summary

A device may generate a knowledge model based on a knowledge model schema, data residency constraints, and a data classification ontology associated with a cloud application, and may perform a dynamic flow analysis of the cloud application data and the data source identifiers to generate a data flow graph. The device may process the data flow graph, with the knowledge model, to determine sensitive attributes in the data flow graph, and may identify sensitive data sources that include the sensitive attributes and sensitive assets based on the data flow graph and the sensitive data sources. The device may process the sensitive data sources and the sensitive assets, with a machine learning model, to determine methods for identifying misconfigurations, and may utilize the methods to identify misconfigurations and severities of the misconfigurations. The device may generate remediation actions for correcting the cloud application based on the severities of the misconfigurations.