Cloud Security Automation for Compliance Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems for computer infrastructure on cloud platforms face challenges in automating security compliance, leading to manual errors, difficulty in identifying and implementing necessary controls, and a shortage of skilled experts to interpret data, which can result in security breaches and compliance issues.

Innovation Solution

A system and method that utilize a processor to extract information from cloud platforms, execute compliance tests, generate network topology maps, classify connectivity using machine learning, compute risk metrics, and re-execute tests to ensure security compliance without impacting production environments, while identifying missing controls and providing reports in a machine-readable format.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual collection of system description and information is used, then security systems can be implemented, but clerical errors occur and data becomes stale

Engineering Contradiction:
Improvesecurity system reliabilityVSAvoiddata accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent replaces manual mechanical data collection processes with automated software-based extraction systems. The processor automatically extracts information from cloud platforms and devices, eliminating human clerical errors and ensuring continuous, accurate data collection without manual intervention.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs self-service by automatically extracting, validating, and updating its own operational data. The processor autonomously monitors cloud platforms, devices, and network connections, maintaining accurate system descriptions without requiring manual updates or human verification.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual identification of necessary controls is used, then security compliance can be attempted, but the process is time-consuming and error-prone

Engineering Contradiction:
Improvecompliance assuranceVSAvoidcompliance verification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces manual compliance verification with automated software execution. The processor automatically executes compliance tests against extracted system information, continuously verifying security controls without human intervention and significantly reducing verification time.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system provides continuous compliance verification through automated repeated execution of compliance tests. The processor continuously monitors system changes and re-executes necessary compliance tests, ensuring ongoing security assurance without the periodic interruptions inherent in manual processes.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If manual verification of missing controls is used, then some security checks can be performed, but skilled experts are required and availability is limited

Engineering Contradiction:
Improvesecurity control verificationVSAvoidexpert dependency
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the complex human expertise requirement with automated software algorithms. The processor automatically identifies missing security controls and executes verification tests using programmed compliance rules, eliminating dependency on skilled experts while maintaining verification reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system creates virtual copies of security control verification through automated software instances. Multiple compliance test instances can simultaneously verify different security controls without requiring multiple human experts, allowing parallel processing and scaling.

Inventive Principle:
Principle #26Copying

4Adaptability or versatility

If cloud platform reconfiguration is done using software commands, then system flexibility is improved, but security compliance becomes more difficult to prove and maintain

Engineering Contradiction:
Improvesystem reconfiguration flexibilityVSAvoidsecurity compliance proof
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements continuous feedback loops where the processor automatically monitors cloud platform reconfigurations and updates compliance status accordingly. When software commands modify system configuration, the system automatically detects changes, re-executes compliance tests, and provides continuous proof of compliance maintenance.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system replaces manual compliance documentation with automated digital verification. The processor automatically generates compliance evidence by executing tests against current system configurations, providing provable, auditable records of security compliance that automatically reflect software-based reconfigurations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12015647B2System and method for securing computer infrastructure and devices that depend on cloud platforms
Publication Date: 2024.06.18 TALA SECURE INC
  • US12015647B2 patent drawing
  • US12015647B2 patent drawing
  • US12015647B2 patent drawing

AI summary

The embodiment herein provides a system for securing computer infrastructure and one or more devices that depend on one or more cloud platforms. The system includes a memory, and a processor that stores and executes a set of instructions. The processor is configured to (i) extract one or more information data from at least one of the cloud platforms or the devices that depends on the one or more cloud platforms, (ii) execute compliance tests to identify compliance and non-compliance in the one or more information data, (iii) generate a network topology map by querying the one or more information data, (iv) classify a connectivity between the one or more devices and their nature, (v) compute risk metrics, (vi) re-execute the compliance tests to detect changes, and (vii) implement security compliances without impacting a production or operational environment of the one or more cloud platforms.