Cloud Resource Risk Assessment With Runtime-Based Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud resource management systems lack comprehensive and real-time monitoring and remediation capabilities to detect and respond to security threats and anomalies within cloud environments, leading to potential data breaches and compliance violations.

Innovation Solution

A data platform is deployed to monitor and manage cloud environments, utilizing agents to collect data from compute assets, perform data ingestion, processing, and provide user interfaces, with features for anomaly detection, security monitoring, and remediation, leveraging data warehouses, data lakes, and data marts for data storage and analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive monitoring and remediation capabilities are implemented, then security threat detection and response improve, but system complexity increases

Engineering Contradiction:
Improvesecurity threat detectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments monitoring functions by deploying agents at specific locations (compute assets, network devices, cloud infrastructure) and organizing data flow through distinct components (data ingestion services, data warehouses, data lakes, data marts). This segmentation allows comprehensive monitoring while managing complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components including data ingestion services that bridge agents and data warehouses, and data marts that mediate between data lakes and analytical tools. These intermediaries simplify the overall system by providing standardized interfaces and data transformation layers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If real-time data collection from multiple sources is implemented, then anomaly detection capability improves, but data processing complexity increases

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoiddata processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The data processing function is segmented into specialized components: data ingestion services handle collection and validation, data warehouses store structured data, data lakes store raw data, and data marts provide processed data for analysis. This segmentation enables real-time processing while managing complexity through functional separation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary data processing and transformation in data marts before analysis, pre-aggregating and formatting data to reduce processing complexity during actual anomaly detection operations.

Inventive Principle:
Principle #10Preliminary action

3Speed

If automated remediation actions are implemented, then response time to security threats improves, but system automation complexity increases

Engineering Contradiction:
Improveresponse timeVSAvoidautomation complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The system implements feedback mechanisms where anomaly detection results automatically trigger remediation actions, which are then monitored and fed back into the detection system. This closed-loop feedback enables automated response while managing complexity through standardized feedback protocols.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs self-service remediation by automatically executing predefined security responses without human intervention, such as isolating affected compute assets or blocking network traffic, thereby reducing response time while containing automation complexity through predefined action templates.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12537837B2Cloud resource risk scenario assessment and remediation
Publication Date: 2026.01.27 FORTINET INC
  • US12537837B2 patent drawing
  • US12537837B2 patent drawing
  • US12537837B2 patent drawing

AI summary

An illustrative method for performing a risk scenario assessment and remediation may include identifying, based on posture data associated with a compute environment, one or more compute resources deployed in the compute environment that are configured to be connected to a network, accessing runtime workload data associated with the one or more compute resources representative of network activity for the one or more compute resources, and performing, based on the posture data and the runtime workload data, a remediation operation associated with the one or more compute resources.