Cloud Runtime Sensor Correlation for Identity Misuse Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Identity misuse in cloud computing environments poses significant risks, including unauthorized access to sensitive information, cybercrimes, and erosion of trust in digital systems, necessitating robust security measures to mitigate these threats.
Innovation Solution
Deploying a runtime sensor in a cloud computing environment to continuously monitor and analyze workload activities, generate an activity baseline, detect anomalous events, and associate them with cloud identities, using a system that includes a sensor backend server, inspection controller, and security database to enforce policies and detect cybersecurity threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional identity management systems are used in cloud computing environments, then basic authentication is provided, but they cannot detect or prevent identity misuse effectively
Solution Approach 1:
The system performs preliminary actions by continuously monitoring workload activities and establishing baselines before identity misuse can occur. Runtime sensors collect data about normal operations, and the system proactively identifies deviations from established patterns, enabling prevention rather than just detection of security incidents.
Solution Approach 2:
The patent introduces runtime sensors as intermediary components that bridge traditional identity management systems and cloud workloads. These sensors act as mediators that collect runtime data, analyze behaviors, and provide additional security intelligence without replacing existing authentication mechanisms, thus enhancing security while maintaining system compatibility.
2Measurement precision
If runtime monitoring is continuously performed to detect identity misuse, then security detection capability is improved, but computational resources and system overhead increase
Solution Approach 1:
The system applies partial monitoring by focusing computational resources on analyzing only the most critical runtime parameters and behaviors relevant to identity misuse. Rather than monitoring all possible system activities equally, the runtime sensors prioritize collection and analysis of data points that are most indicative of security threats, reducing overall computational overhead while maintaining detection accuracy.
Solution Approach 2:
The monitoring system operates periodically by establishing baselines from historical data and then comparing current runtime activities against these baselines at scheduled intervals. This periodic approach allows the system to balance continuous security monitoring with resource conservation, performing intensive analysis only when necessary to detect deviations from normal behavior patterns.
3Reliability
If multiple security sensors and analysis components are deployed to detect cloud identity misuse, then detection capability is enhanced, but system complexity and deployment difficulty increase
Solution Approach 1:
The patent merges multiple security functions into a unified runtime monitoring system. Rather than deploying separate sensors for different security concerns, the system combines identity misuse detection, anomaly detection, and behavior analysis into integrated runtime sensors that perform multiple functions simultaneously, simplifying deployment while maintaining comprehensive security monitoring.
Solution Approach 2:
The runtime sensors are designed with multi-functionality, capable of performing various security analysis tasks including collecting runtime data, establishing baselines, detecting anomalies, and correlating events across different cloud services. This universal approach allows a single sensor deployment to address multiple security requirements, reducing the number of components needed and simplifying system operation.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system and method for detecting cloud identity misuse in a cloud computing environment is presented. The method includes: deploying a runtime sensor on a workload in a cloud computing environment; continuously receiving data from the runtime sensor; generating an activity baseline based on the continuously received data, wherein the runtime sensor is configured to detect runtime processes on the workload; detecting an event in a cloud log, the event including an identifier of the workload; associating a runtime process detected by the runtime sensor on the workload with the event detected in the cloud log; and determining that the event is an anomalous event based on the generated activity baseline.