Cloud Security Graph Database for East-West Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing environments face significant security threats as attackers breach internal networks and public clouds to steal critical data, exploiting East-West traffic flows and moving laterally to critical enterprise assets, highlighting the need for effective security management systems.

Innovation Solution

A method for cloud security management involves gathering data on workloads and applications, updating a graph database with this information, receiving a security template, creating a security policy using the template and graph database data, and deploying the policy within the cloud environment to protect targeted assets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security management approaches are used in cloud environments, then security policies can be implemented, but the system cannot effectively track and respond to lateral movement attacks and East-West traffic flows

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidability to adapt to changing cloud environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security policies that automatically adapt to changing cloud environments by continuously monitoring workload relationships and attack patterns. The system updates security rules in real-time based on graph database analysis of East-West traffic flows and lateral movement detection, making the security infrastructure flexible and responsive rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where security events and attack patterns are continuously monitored, analyzed through graph database queries, and used to automatically refine and update security policies. This closed-loop approach allows the system to learn from attacks and improve protection effectiveness over time.

Inventive Principle:
Principle #23Feedback

2Difficulty of detecting and measuring

If comprehensive security monitoring is implemented across all cloud workloads, then attack detection capability is improved, but system complexity and computational requirements increase

Engineering Contradiction:
Improveattack detection capabilityVSAvoidsecurity system complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent introduces a graph database as an intermediary layer between raw security data and analysis systems. This intermediary structures complex workload relationship data into queryable graph representations, simplifying the detection of attack patterns while maintaining comprehensive monitoring coverage without proportionally increasing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the cloud environment into discrete workload nodes and relationships that can be independently monitored and analyzed. By breaking down the complex cloud infrastructure into manageable graph components, the system can detect attacks efficiently without being overwhelmed by overall system complexity.

Inventive Principle:
Principle #1Segmentation

3Manufacturing precision

If security policies are manually created and updated for each cloud workload, then policy precision can be maintained, but the time and resources required for policy management increase

Engineering Contradiction:
Improvesecurity policy precisionVSAvoidsecurity policy deployment speed
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The system implements self-service security policy generation where the graph database automatically analyzes workload relationships and generates appropriate security rules without manual intervention. This automated approach maintains policy precision by base.ing rules on actual workload dependencies while dramatically improving deployment speed and reducing manual management overhead.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary analysis of workload relationships and potential attack vectors before security threats materialize. By pre-computing security rules based on graph database analysis of workload dependencies, the system prepares security policies in advance, enabling rapid deployment when threats are detected without sacrificing policy precision.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11575563B2Cloud security management
Publication Date: 2023.02.07 GRYPHO5 LLC
  • US11575563B2 patent drawing
  • US11575563B2 patent drawing
  • US11575563B2 patent drawing

AI summary

Methods and systems for managing security in a cloud computing environment are provided. Exemplary methods include: gathering data about workloads and applications in the cloud computing environment; updating a graph database using the data, the graph database representing the workloads of the cloud computing environment as nodes and relationships between the workloads as edges; receiving a security template, the security template logically describing targets in the cloud computing environment to be protected and how to protect the targets; creating a security policy using the security template and information in the graph database; and deploying the security policy in the cloud computing environment.