Cloud Security Posture Management System for Misconfiguration Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud security misconfigurations lead to data breaches and compliance violations, especially in public clouds where enterprises face challenges in governing and ensuring security across complex, dynamic environments, with misconfiguration being the primary cause of successful attacks.

Innovation Solution

A cloud-based Cloud Security Posture Management (CSPM) system that automatically identifies and remediates misconfigurations in SaaS, IaaS, and PaaS applications, providing unified visibility and automated remediation to prevent data loss, breaches, and downtime, while enabling secure use of public cloud technologies with private cloud-like security benefits.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If enterprises use public cloud technologies, then productivity and flexibility are improved, but security control and compliance visibility deteriorate

Engineering Contradiction:
Improvecloud deployment flexibilityVSAvoidsecurity control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The CSPM system acts as an intermediary between enterprises and public cloud providers. It continuously monitors cloud configurations, compares them against security policies, and provides remediation guidance, thereby enabling enterprises to use public cloud technologies while maintaining security control and compliance visibility through this mediating layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements continuous feedback loops by monitoring cloud resource configurations in real-time, comparing them against defined security policies, and providing immediate feedback through alerts and automated remediation. This feedback mechanism allows enterprises to maintain security control despite the dynamic nature of public cloud environments.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If manual security monitoring is performed, then measurement precision is improved, but productivity and time efficiency deteriorate

Engineering Contradiction:
Improvemisconfiguration detection accuracyVSAvoidsecurity assessment speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The CSPM system performs self-service by automatically monitoring its own cloud environment, continuously scanning for misconfigurations, and generating remediation recommendations without requiring manual intervention. This automation maintains high measurement precision for security monitoring while dramatically improving productivity and time efficiency.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system provides continuous monitoring and assessment of cloud security postures, eliminating the interruptions and delays inherent in manual security audits. The continuous action of automated scanning and real-time policy comparison ensures both high measurement precision and improved productivity through uninterrupted security oversight.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If comprehensive cloud security monitoring is implemented, then reliability is improved, but device complexity and system overhead increase

Engineering Contradiction:
Improvesecurity posture managementVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The CSPM system achieves multi-functionality by combining configuration monitoring, security policy enforcement, compliance assessment, and automated remediation guidance into a single unified platform. This universal approach improves reliability through comprehensive security monitoring while reducing device complexity by consolidating multiple security functions into one system rather than requiring separate tools for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11722522B2Cloud security posture management systems and methods with a cloud-based system
Publication Date: 2023.08.08 ZSCALER INC
  • US11722522B2 patent drawing
  • US11722522B2 patent drawing
  • US11722522B2 patent drawing

AI summary

Cloud Security Posture Management (CSPM) systems and methods include, in a node in a cloud-based system, obtaining a plurality of security policies and one or more compliance frameworks for a tenant of a cloud provider where the tenant has a cloud application deployed with the cloud provider, wherein each security policy defines a configuration and an expected value, and wherein each compliance framework includes one or more of the security policies; obtaining configurations of the cloud application; identifying misconfigurations of the cloud application based on a comparison of the obtained configurations with the plurality of security policies; analyzing the misconfigurations to determine risks including prioritization of the risks based on their likelihood of exposure to security breaches; and causing remediation of the identified misconfigurations and the determined risks, wherein the cloud-based system performs the CSPM service in addition to one or more additional cloud services.