Cloud Security Alert Aggregation via Kill Chain Consolidation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing complexity of cyber attacks on cloud resources leads to overwhelming amounts of detection signals for security officers, causing alert fatigue and making it difficult to identify and respond to the most critical security threats effectively, as existing solutions are not scalable and often require prior knowledge of specific attacks.
Innovation Solution
A system and method that uses machine learning techniques to aggregate multiple alerts into a unified 'kill chain' scenario, representing alerts in a multidimensional array format and generating compound alerts to reduce the number of alerts and improve the efficiency of security data representation, allowing for a more concise and relevant presentation of security data in a unified dashboard.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple detection signals and alerts are generated to detect advanced attack methods, then the detection capability is improved, but the number of alerts overwhelms security officers causing alert fatigue
Solution Approach 1:
The patent merges multiple related alerts into a single consolidated alert representing an entire attack kill chain. Instead of presenting numerous individual detection signals for each attack stage, the system combines alerts from multiple resources and attack stages into one unified alert that represents the complete attack scenario, reducing alert volume while maintaining comprehensive detection coverage
Solution Approach 2:
The patent creates a universal alert structure that can represent multiple attack types and kill chain scenarios through a standardized format. The consolidated alert framework is designed to handle diverse attack methods (brute force, credential stuffing, etc.) and multiple attack stages within a single unified alert structure, making the system adaptable to various threat types without requiring separate alert mechanisms
2Reliability
If comprehensive monitoring of multiple cloud resources is implemented, then security coverage is improved, but the complexity of managing and analyzing security data increases
Solution Approach 1:
The patent segments the complex security monitoring system into distinct hierarchical layers: individual resource monitoring, kill chain detection, and consolidated alerting. Each layer handles specific aspects of security monitoring independently, with clear data flow between layers. This segmentation allows comprehensive monitoring of multiple cloud resources while managing complexity through structured organization of monitoring functions
Solution Approach 2:
The patent introduces an intermediary processing layer that sits between resource monitoring and alert generation. This intermediate layer detects kill chain patterns by analyzing relationships between events across multiple resources, transforming raw monitoring data into meaningful attack scenarios before presenting consolidated alerts to security officers, thereby reducing the complexity of data management
3Productivity
If traditional alert aggregation methods are used, then some alert reduction is achieved, but scalability is limited and prior knowledge of specific attacks is required
Solution Approach 1:
The patent implements dynamic kill chain detection that adapts to different attack types and scenarios without requiring pre-defined rules for each specific attack. The system dynamically identifies relationships between events and constructs kill chain representations based on observed patterns, allowing the alert aggregation mechanism to scale to new attack types and methodologies while maintaining effective alert reduction
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
Generally discussed herein are devices, systems, and methods for computer or other network device security. A method can include identifying a profile associated with event data regarding an operation performed on a cloud resource, determining whether the event data is associated with anomalous customer interaction with the cloud resource, in response to determining the event data is associated with anomalous customer interaction, identifying whether another cloud resource of the cloud resources with a lower granularity profile that is associated with the profile of the cloud resource has previously been determined to be a target of an anomalous operation, and providing a single alert to a client device indicating the anomalous behavior on the cloud resource in response to determining both the event data is associated with anomalous customer interaction and the another cloud resource is determined to be the target of the anomalous operation.