Cloud Scanner Schema Detection for In-Place Sensitive Data Discovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in understanding the data posture and breadth of access to sensitive data stored in cloud environments, making it difficult to identify which users have access to which data and which data may be exposed to malicious or unauthorized users, both inside and outside the organization, despite existing security infrastructure.
Innovation Solution
A cloud security posture analysis system that deploys agent-less scanners within the cloud service to analyze and take action on the security posture by discovering sensitive data and access patterns, providing real-time visibility and control through metadata analysis, and generating visualizations of resource configurations and breach paths.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cloud storage services provide on-demand network access to shared pool of configurable resources, then accessibility and flexibility are improved, but security control and data protection become more difficult to manage
Solution Approach 1:
The patent introduces a cloud security posture analysis system as an intermediary between cloud storage services and users. This system continuously analyzes cloud resources, identifies security vulnerabilities, and provides recommendations without requiring direct user intervention in the complex cloud infrastructure, thus maintaining accessibility while improving security control.
Solution Approach 2:
The system continuously monitors cloud resources and provides feedback about security posture through automated analysis. It identifies vulnerabilities in real-time and generates recommendations for remediation, creating a closed-loop security management system that adapts to changing cloud configurations while maintaining strong security controls.
2Reliability
If existing security infrastructure is deployed in cloud environments, then basic security protection is provided, but understanding data posture and access patterns remains difficult
Solution Approach 1:
The system performs preliminary analysis of cloud resources by continuously scanning and cataloging data stores, databases, and other storage resources. It proactively identifies security vulnerabilities and maps access patterns before breaches occur, providing advance warning and enabling preventive security measures.
Solution Approach 2:
The patent adds a new dimension of analysis by examining not just the presence of security controls, but also the relationships between resources, users, and data. It creates a comprehensive view of data posture and access patterns by analyzing metadata and configuration relationships, transforming isolated security data into actionable insights.
3Measurement precision
If comprehensive security analysis is performed on cloud data, then vulnerability identification is improved, but data exposure risk increases
Solution Approach 1:
The security posture analysis system acts as an intermediary that analyzes cloud data metadata and configurations without accessing or exposing the actual sensitive data content. It performs security assessments on the structure and access patterns of data stores while maintaining data privacy and minimizing exposure risk.
Solution Approach 2:
The system segments the security analysis process into separate analytical functions that examine different aspects of cloud resources independently. It analyzes data store configurations, access patterns, and vulnerability indicators as separate data streams, processing security information without creating unnecessary exposure of the underlying sensitive data.
Data Source
AI summary
The technology disclosed relates to a computing system configured to execute a cloud scanner in a cloud environment to discover one or more data stores in the cloud environment and return metadata representing a data schema of data objects in the one or more data stores, traverse the data objects in the one or more data stores based on the metadata to identify a plurality of data items, execute a content-based data classifier against the plurality of data items to identify a set of data items, in the plurality of data items, as conforming to one or more data profiles, and generate a graphical interface including one or more graphical objects configured to display a representation of the one or more data profiles, wherein the graphical interface is configured to filter the plurality of data items based on a selected data profile selected from the one or more data profiles.


