Cloud Risk Assessment Using Security Graph Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing environments lack a unified benchmark for security measurement and existing tools are often tailored to specific types of environments or workloads, leading to inconsistent and inefficient cybersecurity vulnerability management across different cloud platforms.

Innovation Solution

A method and system for generating a contextual cloud risk assessment using a security graph, applying cloud assessment policies to represent multiple cloud environments uniformly, and initiating mitigation actions based on risk assessment reports.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing security tools are tailored to specific cloud environments, then they can provide detailed security analysis for that environment, but they cannot provide consistent security measurement across different cloud platforms

Engineering Contradiction:
Improvesecurity measurement consistencyVSAvoidcloud platform compatibility
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal security assessment framework that can be applied across multiple cloud platforms (AWS, Azure, GCP, etc.) by defining platform-agnostic security policies and risk metrics. The system translates platform-specific security configurations into a common assessment model, enabling consistent security measurement across diverse cloud environments while maintaining the ability to assess each platform's unique characteristics.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If comprehensive security assessments are performed across all cloud environments, then all vulnerabilities can be identified, but the complexity and time required for assessment increases significantly

Engineering Contradiction:
Improvevulnerability detection completenessVSAvoidassessment system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security assessment process into distinct modular components: policy definition modules, data collection modules, analysis modules, and reporting modules. Each module handles specific aspects of security assessment independently, allowing the system to maintain comprehensive vulnerability detection while reducing overall system complexity through modular architecture and specialized sub-systems.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by pre-defining security policies, risk metrics, and assessment criteria before actual security assessments are conducted. This upfront preparation includes establishing baseline security configurations, pre-configuring detection rules, and setting up assessment frameworks, which streamlines the actual assessment process and reduces real-time complexity.

Inventive Principle:
Principle #10Preliminary action

3Loss of time

If frequent security assessments are conducted, then vulnerabilities can be detected timely, but the computational resources and time required increase

Engineering Contradiction:
Improvevulnerability detection timeVSAvoidassessment efficiency
Core Design Contradiction:
Loss of timeVSProductivity

Solution Approach 1:

The patent implements periodic security assessments at strategically determined intervals based on risk levels, cloud environment changes, and vulnerability criticality. The system schedules assessments dynamically, performing more frequent checks on high-risk configurations and less frequent checks on stable, low-risk environments, thereby achieving timely vulnerability detection while optimizing resource utilization and maintaining assessment efficiency.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS20260046304A1System and method for risk monitoring of cloud based computing environments
Publication Date: 2026.02.12 WIZ INC
  • US20260046304A1 patent drawing
  • US20260046304A1 patent drawing
  • US20260046304A1 patent drawing

AI summary

A system and method for generating a contextual cloud risk assessment of a cloud computing environment. The method includes accessing a plurality of cloud assessment policies, wherein a policy including a query executable on a security graph; applying the plurality of cloud assessment policies to the representation of the first cloud computing environment; generating a risk assessment report based on an output generated by applying a policy of the plurality of cloud assessment polices; and initiating a mitigation action based on a cybersecurity risk from the risk assessment report.