Cloud Security Graph Alert Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing solutions for managing cybersecurity alerts in cloud computing environments generate a high volume of alerts, making it difficult for human operators to prioritize and respond effectively to cyber threats in a timely manner, as they lack objective criteria for assessing severity and initiating mitigation actions.

Innovation Solution

A method and system that utilize a security graph to detect alerts, generate a severity index based on contextual factors, and initiate mitigation actions automatically, applying objective criteria to prioritize alerts and allocate resources effectively in a cloud computing environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a comprehensive vulnerability detection system is implemented to monitor all cloud entities, then the coverage of security monitoring is improved, but the number of alerts generated increases making them difficult to manage

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoidalert management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a severity index calculation system as an intermediary between vulnerability detection and alert management. This intermediary processes raw vulnerability data through a standardized scoring mechanism that considers multiple factors (asset criticality, exploitability, impact) to transform unmanageable alert volumes into prioritized security intelligence, enabling effective resource allocation without compromising monitoring coverage

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms the management approach by changing the parameters used to evaluate vulnerabilities. Instead of treating all alerts equally or relying on subjective assessment, the system introduces quantifiable parameters (severity index, asset criticality scores, exploitability metrics) that objectively prioritize alerts, making the management process scalable and consistent across thousands of cloud entities

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If human operators manually assess each vulnerability alert, then detailed analysis can be performed, but the response time becomes too slow to handle real-time threats

Engineering Contradiction:
Improvevulnerability assessment accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements a self-service vulnerability assessment system where the severity index calculation automatically evaluates and prioritizes alerts without human intervention. The system uses predefined criteria and algorithms to assess asset criticality, exploitability, and potential impact, providing accurate prioritization that enables rapid automated response while maintaining assessment quality

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary assessment actions by pre-calculating asset criticality scores and establishing evaluation criteria before threats occur. This preparation enables the system to rapidly prioritize incoming alerts by immediately applying the pre-established framework, eliminating the need for operators to perform time-consuming manual assessments of each new vulnerability

Inventive Principle:
Principle #10Preliminary action

3Reliability

If all vulnerabilities are treated with equal priority, then no important information is missed, but resources are wasted on low-severity issues and critical threats may be overlooked

Engineering Contradiction:
Improvethreat detection completenessVSAvoidresource allocation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by assigning different priority levels to different vulnerabilities based on their specific characteristics and context. Rather than uniform treatment, the severity index calculation considers local factors such as asset criticality, vulnerability exploitability, and potential business impact to determine appropriate response priorities, ensuring resources are allocated where they are most needed

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20230247063A1Techniques for prioritizing risk and mitigation in cloud based computing environments
Publication Date: 2023.08.03 WIZ INC
  • US20230247063A1 patent drawing
  • US20230247063A1 patent drawing
  • US20230247063A1 patent drawing

AI summary

A system and method for prioritizing alerts and mitigation actions against cyber threats in a cloud computing environment. The method includes detecting an alert based on a cloud entity deployed in a cloud computing environment, wherein the alert including an identifier of the cloud entity and a severity indicator, and wherein the cloud computing environment is represented in a security graph; generating a severity index for the received alert based on the identifier of the cloud entity and the severity indicator; and initiating a mitigation action based on the severity index.