Cloud Risk Detection Engine With Severity-Based Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity systems face challenges in achieving accurate and relevant risk detection, with excessive false positives leading to alert fatigue and false negatives allowing critical threats to go unnoticed, while also struggling with the volume and complexity of data in large-scale or multi-cloud environments.
Innovation Solution
A detection engine that utilizes an enriched event record from a cloud log, incorporating runtime data and entity states, determines a severity score, prioritizes mitigation actions, and executes appropriate responses based on these scores, using a combination of data from various sources like the data plane, control plane, Version Control System, and identity provider.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If detection sensitivity is increased to detect more threats, then threat detection coverage is improved, but false positive rate increases leading to alert fatigue
Solution Approach 1:
The patent applies parameter changes by dynamically adjusting detection thresholds and sensitivity levels based on contextual factors such as entity reputation, historical behavior patterns, and threat intelligence data. This allows the system to maintain high detection coverage while adapting false positive rates to specific contexts, resolving the contradiction between comprehensive threat detection and alert fatigue.
Solution Approach 2:
The system implements dynamics by continuously adapting detection parameters and alert thresholds based on real-time data analysis, entity states, and learned patterns. Rather than using static detection rules, the system dynamically modifies its sensitivity and prioritization to balance comprehensive threat detection with minimizing false alarms, directly addressing the technical contradiction.
2Measurement precision
If detection rules are made more specific to reduce false positives, then precision is improved, but detection capability for nuanced threats decreases
Solution Approach 1:
The patent resolves this contradiction by adding another dimension to detection analysis through multi-factor scoring systems that evaluate threats across multiple attributes simultaneously (e.g., entity reputation, behavioral patterns, threat intelligence, contextual factors). This dimensional expansion allows the system to maintain specific detection criteria while still capturing nuanced threats through composite assessment, rather than relying on single-dimension rules.
Solution Approach 2:
The system applies composite materials principle by combining multiple detection signals, data sources, and analysis layers into a composite risk assessment. Rather than using单一 detection rules, the system integrates diverse indicators and contextual information to form a comprehensive evaluation that maintains precision while detecting subtle, multi-faceted threats.
3Measurement precision
If advanced analytics are applied to parse complex data, then risk detection accuracy is improved, but resource consumption increases
Solution Approach 1:
The patent applies partial action by implementing tiered or staged analytics processing where not all data undergoes the most computationally intensive analysis. Instead, the system applies appropriate levels of analytical depth based on data priority, entity risk profiles, and contextual factors, achieving high detection accuracy for critical threats while conserving resources on lower-priority events.
Solution Approach 2:
The system segments analytics processing into multiple stages or layers, applying different computational intensities to different data types and threat contexts. This segmentation allows resource-efficient filtering and preliminary analysis for routine events, while reserving advanced analytics for high-priority or ambiguous cases, thereby balancing detection accuracy with resource consumption.
Data Source
AI summary
A system and method for executing mitigation actions in a cloud computing environment based on a severity of a detected cybersecurity risk is presented. The method includes detecting a cybersecurity risk based on an enriched event record from a cloud log, the enriched event record including runtime data from a resource deployed in a cloud computing environment and a state of an entity detected in the runtime data; determining a severity score for the detected cybersecurity risk of the enriched event record; prioritizing a plurality of mitigation actions based on the severity score; and executing at least a mitigation action in the cloud computing environment based on the prioritization.


