Cloud Security Vulnerability Detector Using Story Graphs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional validation services and databases, such as MITRE ATT&CK™ Enterprise, fail to effectively identify and report security vulnerabilities in cloud-based environments, particularly cloud-native techniques and kill chains, due to their focus on operating system-based security and inability to adapt to cloud deployments.

Innovation Solution

The implementation of a security vulnerability detector that utilizes resource monitoring, artificial intelligence models, and threat intelligence to identify and correlate cloud-based security vulnerabilities, including misconfigurations and API logs, to generate a story graph indicating potential remediation actions and threat intelligence feeds.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional validation services and databases (MITRE ATT&CK Enterprise) are used, then operating system-based security validation is achieved, but cloud-based security vulnerabilities cannot be effectively identified

Engineering Contradiction:
Improvesecurity vulnerability detection accuracyVSAvoidcloud environment adaptability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent segments security validation into two distinct components: OS-based validation (using traditional MITRE ATT&CK Enterprise) and cloud-based validation (using cloud-specific indicators, misconfiguration detection, and cloud kill chain identification). This segmentation allows each component to specialize in its domain, resolving the contradiction between maintaining OS validation capabilities and adapting to cloud environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to security validation by introducing cloud-specific validation layers beyond traditional OS-based approaches. This includes validating cloud configurations, IAM policies, storage bucket settings, and cloud-native attack vectors, thereby expanding the validation space from two-dimensional (OS-based) to three-dimensional (OS + cloud configurations + cloud services).

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If cloud-specific validation is implemented, then cloud-based security vulnerabilities are detected, but validation complexity increases

Engineering Contradiction:
Improvecloud security validation reliabilityVSAvoidvalidation system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal validation framework that handles both OS-based and cloud-based security validation through a single system. The validation service can dynamically select and execute appropriate validation routines based on the target environment, whether it's traditional OS infrastructure or cloud-based infrastructure, thereby managing complexity while maintaining comprehensive coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary validation layer that sits between the validation service and the target infrastructure. This intermediary handles the complexity of cloud-specific validations by abstracting cloud provider-specific details (AWS, Azure, GCP) into standardized validation patterns, reducing the overall system complexity while maintaining reliable cloud security validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If comprehensive cloud validation is performed, then all cloud-based vulnerabilities are identified, but validation time increases

Engineering Contradiction:
Improvevulnerability identification completenessVSAvoidvalidation execution time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements partial validation by focusing on the most critical cloud security areas (IAM configurations, storage bucket policies, security group rules, known cloud kill chains) rather than attempting to validate every possible cloud configuration. This selective approach maintains high vulnerability identification completeness for cloud-specific threats while reducing validation time compared to exhaustive validation.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent performs preliminary actions by pre-configuring validation rules, cloud kill chain patterns, and misconfiguration templates before actual validation execution. This allows the validation service to quickly match observed cloud configurations against known vulnerability patterns without performing complex real-time analysis, thereby reducing validation time while maintaining identification completeness.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12126644B2Methods and apparatus to identify and report cloud-based security vulnerabilities
Publication Date: 2024.10.22 SKYHIGH SECURITY LLC
  • US12126644B2 patent drawing
  • US12126644B2 patent drawing
  • US12126644B2 patent drawing

AI summary

Methods, apparatus, systems, and articles of manufacture are disclosed to identify and report cloud-based security vulnerabilities. An example apparatus includes memory, instructions, and processor circuitry. The example processor circuitry is to execute the instructions to assess a first security vulnerability associated with an application programming interface (API) of a cloud compute network, the first security vulnerability corresponding to at least one call to the API that deviates from a baseline report, the baseline report based on at least one communication in the cloud compute network, and assess a second security vulnerability associated with identity and access management in the cloud compute network based on an entity in the cloud compute network permitted to access a service provided by the cloud compute network, the second security vulnerability corresponding to an unauthorized request to access at least one of a device of the cloud compute network or the service.