Cloud Security Monitoring via Behavioral Graph Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security monitoring and control systems in cloud environments generate numerous false positives due to the 'cold boot problem' and changes in usage patterns, leading to inefficient alert management and potential missed security risks.

Innovation Solution

A system that analyzes user actions in a cloud service by generating a weighted directed graph to detect anomalies and adjust security controls and policies, recommending modifications based on actual user behavior patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security monitoring systems are used to detect all user actions, then security coverage is improved, but false positives increase due to cold boot problem and usage pattern changes

Engineering Contradiction:
Improvesecurity detection accuracyVSAvoidfalse positives
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The system performs preliminary actions by learning and establishing baseline user behavior patterns before actual security monitoring begins. The behavioral graph is constructed in advance from historical activity data, capturing normal user actions and sequences. This preliminary learning phase enables the system to distinguish between normal variations in usage patterns and actual security anomalies, reducing false positives while maintaining comprehensive security coverage.

Inventive Principle:
Principle #10Preliminary action

2Object-generated harmful factors

If security controls are adjusted based on actual user behavior patterns, then false positives are reduced, but system complexity increases due to behavioral graph construction

Engineering Contradiction:
Improvefalse positivesVSAvoidmonitoring system complexity
Core Design Contradiction:
Object-generated harmful factorsVSDevice complexity

Solution Approach 1:

The system implements feedback mechanisms where the constructed behavioral graph continuously informs and adjusts security control parameters. The graph's representation of normal user behavior patterns provides feedback that automatically tunes alert thresholds and control sensitivity. This feedback loop enables the system to adapt to changing usage patterns without manual intervention, reducing false positives while the automated nature of the process prevents complexity from escalating unmanageably.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If comprehensive activity data is collected from all users, then anomaly detection accuracy is improved, but data processing requirements and system resource usage increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoiddata processing load
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system extracts and focuses only on the essential behavioral elements needed for anomaly detection rather than processing all raw activity data uniformly. The behavioral graph construction process selectively extracts meaningful user actions, sequences, and patterns from the comprehensive activity data, discarding redundant information. This extraction approach maintains high anomaly detection accuracy by preserving critical behavioral signals while significantly reducing the data processing load required to analyze comprehensive user activity.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12160449B2Autonomous monitoring of applications in a cloud environment
Publication Date: 2024.12.03 ORACLE INT CORP
  • US12160449B2 patent drawing
  • US12160449B2 patent drawing
  • US12160449B2 patent drawing

AI summary

Provided are systems and methods for analyzing actions performed by users in using a cloud service, and adjusting the configuration of a security management and control system based on the analysis. In various examples, the analysis can include generating a weighted directed graph that reflects a user's use of the cloud service, and/or reflects the tenant's overall use of the cloud service. When the security monitoring and control system generates security alerts, the actions that resulted in the alerts can be compared to the graph to determine whether the actions are in accordance with prior behavior of the users. When the actions do correspond to the graph, the system can recommend that the security control or security policy that triggered the alert be modified. In various examples, the graphs can also be used to determine whether any user's actions are anomalous as compared to earlier behavior.