Cloud Security Graph Subgraph Generation for Scalable Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity solutions for cloud environments are inefficient and ineffective in monitoring security threats and vulnerabilities across multiple cloud environments, leading to inconsistent policies and increased complexity in managing security at scale.

Innovation Solution

The proposed solution involves generating a subgraph view of a security graph, which includes nodes representing principals and resources within a cloud environment, using a graph database. This allows for a scalable, efficient, and cross-platform approach to security monitoring by associating nodes with tags and generating subgraphs that include parent nodes and their child nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple separate monitoring solutions are deployed for each cloud environment, then comprehensive security coverage is achieved, but system complexity and operational overhead increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple cloud environment monitoring into a single unified security monitoring system that can simultaneously monitor multiple cloud environments. The system consolidates security data from different cloud providers and environments into one centralized platform, reducing the number of separate monitoring solutions needed while maintaining comprehensive security coverage across all environments.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The monitoring system is designed with universal capabilities to handle multiple cloud environments and various cloud providers through a single platform. It provides multi-functional security monitoring that can adapt to different cloud infrastructure types and configurations, eliminating the need for environment-specific monitoring solutions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate monitoring teams are assigned to each cloud environment, then specialized monitoring is achieved, but resource efficiency decreases due to duplication

Engineering Contradiction:
Improvemonitoring effectivenessVSAvoidresource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system merges the functions of multiple specialized monitoring teams into a single unified monitoring platform that serves all cloud environments. This consolidation eliminates redundant monitoring activities and allows a single team to efficiently monitor multiple environments simultaneously, improving resource efficiency while maintaining effective security monitoring.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If a unified security monitoring system is implemented across multiple cloud environments, then operational efficiency improves, but difficulty in managing environment-specific policies increases

Engineering Contradiction:
Improveoperational efficiencyVSAvoidpolicy management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The unified monitoring system implements segmentation by organizing security data and policies according to cloud environment, provider, or organizational unit. This hierarchical segmentation allows the system to maintain a unified operational interface while preserving environment-specific policy distinctions, making policy management more manageable despite the multi-environment scope.

Inventive Principle:
Principle #1Segmentation

4Reliability

If security monitoring scales with cloud environment expansion, then comprehensive coverage is maintained, but system performance and response time may deteriorate

Engineering Contradiction:
Improvesecurity coverageVSAvoidmonitoring response time
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system segments security monitoring into modular components that can independently process data from different cloud environments. This segmentation allows parallel processing of security events across multiple environments, maintaining comprehensive coverage while preventing performance degradation through distributed, concurrent operation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The monitoring system transitions from a single-threaded, sequential processing model to a multi-dimensional, parallel processing architecture. By adding the dimension of parallelism across multiple cloud environments, the system maintains comprehensive security coverage while improving overall response time through concurrent event processing.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12333010B1System and method for generating a partitioned view of a security graph in a cloud computing environment
Publication Date: 2025.06.17 WIZ INC
  • US12333010B1 patent drawing
  • US12333010B1 patent drawing
  • US12333010B1 patent drawing

AI summary

A cybersecurity system provides the ability to detect security risks in a cross-platform cloud solution. A unified data schema is used to abstract resources, principals and others across multiple platforms. A security graph is generated to present a unified view of cloud environments, which are then easily queried using the structure of the data schema. The solution allows a compact representation of cloud environments, which is scalable and multi-layered. The security graph allows for representation of production environments, staging environments, as well as code for deploying workloads in the cloud environment. Thus the solution is also able to present a complete picture of a user's entire cloud environment. The solution further allows to generate subgraph views, by associating a tag to certain nodes, then rendering a view based on nodes which include the tag, and all children nodes thereof.