Cloud Security Alert Aggregation via Kill Chain Consolidation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of cyber attacks on cloud resources leads to overwhelming amounts of detection signals for security officers, causing alert fatigue and making it difficult to identify and respond to the most critical security threats effectively, as existing solutions are not scalable and often require prior knowledge of specific attacks.

Innovation Solution

A system and method that uses machine learning techniques to aggregate multiple alerts into a unified 'kill chain' scenario, representing alerts in a multidimensional array format and generating compound alerts to reduce the number of alerts and improve the efficiency of security data representation, allowing for a more concise and relevant presentation of security data in a unified dashboard.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple detection signals and alerts are generated to detect advanced attack methods, then the detection capability is improved, but the number of alerts overwhelms security officers causing alert fatigue

Engineering Contradiction:
Improvedetection capabilityVSAvoidnumber of alerts
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple related alerts into a single consolidated alert representing an entire attack kill chain. Instead of presenting numerous individual detection signals for each attack stage, the system combines alerts from multiple resources and attack stages into one unified alert that represents the complete attack scenario, reducing alert volume while maintaining comprehensive detection coverage

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal alert structure that can represent multiple attack types and kill chain scenarios through a standardized format. The consolidated alert framework is designed to handle diverse attack methods (brute force, credential stuffing, etc.) and multiple attack stages within a single unified alert structure, making the system adaptable to various threat types without requiring separate alert mechanisms

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If comprehensive monitoring of multiple cloud resources is implemented, then security coverage is improved, but the complexity of managing and analyzing security data increases

Engineering Contradiction:
Improvesecurity coverageVSAvoiddata management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex security monitoring system into distinct hierarchical layers: individual resource monitoring, kill chain detection, and consolidated alerting. Each layer handles specific aspects of security monitoring independently, with clear data flow between layers. This segmentation allows comprehensive monitoring of multiple cloud resources while managing complexity through structured organization of monitoring functions

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary processing layer that sits between resource monitoring and alert generation. This intermediate layer detects kill chain patterns by analyzing relationships between events across multiple resources, transforming raw monitoring data into meaningful attack scenarios before presenting consolidated alerts to security officers, thereby reducing the complexity of data management

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If traditional alert aggregation methods are used, then some alert reduction is achieved, but scalability is limited and prior knowledge of specific attacks is required

Engineering Contradiction:
Improvealert reduction efficiencyVSAvoidscalability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic kill chain detection that adapts to different attack types and scenarios without requiring pre-defined rules for each specific attack. The system dynamically identifies relationships between events and constructs kill chain representations based on observed patterns, allowing the alert aggregation mechanism to scale to new attack types and methodologies while maintaining effective alert reduction

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3938937B1Cloud security using multidimensional hierarchical model
Publication Date: 2024.03.27 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3938937B1 patent drawingFigure 1
  • EP3938937B1 patent drawingFigure 2~3
  • EP3938937B1 patent drawingFigure 4

AI summary

Generally discussed herein are devices, systems, and methods for computer or other network device security. A method can include identifying a profile associated with event data regarding an operation performed on a cloud resource, determining whether the event data is associated with anomalous customer interaction with the cloud resource, in response to determining the event data is associated with anomalous customer interaction, identifying whether another cloud resource of the cloud resources with a lower granularity profile that is associated with the profile of the cloud resource has previously been determined to be a target of an anomalous operation, and providing a single alert to a client device indicating the anomalous behavior on the cloud resource in response to determining both the event data is associated with anomalous customer interaction and the another cloud resource is determined to be the target of the anomalous operation.