Cloud Security Analysis System for Container Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing size and complexity of computer networks make them more vulnerable to security incidents, such as network attacks by adversaries, necessitating efficient methods to identify and remediate security incidents.

Innovation Solution

A cloud-based response system that retrieves logs from computer networks, parses and filters them into data sets, creates an event timeline, and analyzes it to identify unauthorized access, generating suggested tasks for isolating compromised hosts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the size and complexity of computer networks are increased to handle more data and users, then the network's processing capability and coverage are improved, but the network becomes more vulnerable to security incidents and attacks

Engineering Contradiction:
Improvenetwork processing capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a cloud-based response system as an intermediary layer between the computer network and potential security threats. This system includes specialized components for detecting, analyzing, and responding to security incidents, effectively mediating the security protection without requiring changes to the core network infrastructure. The intermediary system processes security logs and coordinates remediation actions across the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements automated self-service mechanisms where the security system automatically detects security incidents, analyzes them using machine learning models, and executes remediation tasks without human intervention. The system autonomously monitors network logs, identifies compromised hosts, and applies isolation or remediation measures, enabling the network to protect itself continuously and adaptively.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If traditional security monitoring methods are used in large-scale networks, then implementation simplicity is maintained, but the ability to identify and respond to security incidents efficiently deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity incident response efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent replaces traditional manual or rule-based security monitoring mechanisms with machine learning-based automated analysis systems. Instead of relying on static security rules that require manual configuration and updating, the system uses trained machine learning models to automatically analyze security logs, detect anomalies, and identify security incidents, significantly improving response efficiency while maintaining ease of operation through centralized cloud-based management.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent implements preliminary action by pre-training machine learning models with extensive security data before deployment. The system performs preliminary analysis of security patterns and establishes baseline behaviors in advance, enabling it to quickly detect and respond to security incidents as they occur without requiring real-time human analysis or complex rule configuration during actual security events.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If comprehensive log analysis is performed on all network data, then security detection accuracy is improved, but the computational resources and time required increase significantly

Engineering Contradiction:
Improvesecurity detection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the comprehensive log analysis into distinct functional components: log collection from multiple sources, preliminary filtering of irrelevant data, extraction of security-relevant events, and detailed analysis by specialized machine learning models. This segmentation allows parallel processing of different log types and reduces the time required for complete analysis while maintaining detection accuracy through focused examination of critical security indicators.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by focusing analysis resources on the most critical security indicators and high-risk events identified through preliminary filtering. Instead of analyzing every single log entry with equal depth, the system performs comprehensive analysis on suspicious events while using lighter-weight monitoring for routine operations, thereby achieving high detection accuracy for security incidents while reducing overall computational time and resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250148076A1Automated security analysis and response of container environments
Publication Date: 2025.05.08 DARKTRACE HLDG LTD
  • US20250148076A1 patent drawing
  • US20250148076A1 patent drawing
  • US20250148076A1 patent drawing

AI summary

A computer security method for analyzing data sets for remediating security incidents in a cloud-based response system. Logs of data are retrieved from a computer network. The logs of data are parsed and filtered into the data sets. The logs of data are filtered by creating an event timeline of the computer network by identifying events from the data sets. An event timeline of the computer network is analyzed from the data sets to identify whether data from the logs of data is accessed by an unauthorized computing system. Based on a result of the identification of whether data from the logs of data is accessed by an unauthorized computing system, a set of suggested tasks, wherein each suggested task of the set of suggested tasks represents techniques for isolating a host connected to the computer network if the data has been compromised.