Cross-Platform Cloud Security Incident Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for monitoring and securing cloud-based application platforms struggle to efficiently detect and respond to security incidents across multiple third-party platforms, leading to vulnerabilities in unauthorized activities and threats.

Innovation Solution

A system and method that utilize data from various cloud-based platforms to construct a graphical representation of user activities and states, generating predictive models to identify deviations from normal behavior, and facilitate remedial actions, thereby enhancing security detection and minimizing the attack surface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional monitoring methods are used across multiple cloud platforms, then implementation simplicity is maintained, but security incident detection efficiency deteriorates

Engineering Contradiction:
Improvesecurity incident detection efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges data from multiple independent cloud-based application platforms into a unified analysis system. By consolidating activity data and state data from various platforms (Salesforce, Workday, Box, Dropbox, etc.) into a single security monitoring system that uses graph databases and predictive analytics, the system achieves cross-platform security incident detection efficiency while managing complexity through standardized data processing pipelines and unified analytical models.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an intermediary layer consisting of graph databases and predictive analytics engines that mediate between raw data from multiple cloud platforms and security detection outcomes. This intermediary infrastructure standardizes and normalizes data from heterogeneous sources, enabling efficient security incident detection across platforms without requiring direct integration between each platform pair.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive data collection from multiple platforms is implemented, then security detection accuracy is improved, but data processing time increases

Engineering Contradiction:
Improvesecurity incident detection accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-processing and normalizing data from multiple cloud platforms as it is collected, transforming raw activity data and state data into standardized formats suitable for graph database storage and predictive analytics. This pre-processing step, including entity resolution and relationship mapping, is performed before security analysis is needed, reducing the time required for actual security incident detection while maintaining comprehensive data collection for accurate detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the data processing workflow into distinct stages: data collection from various platforms, data normalization and entity resolution, graph database construction, predictive analytics execution, and security incident detection. This segmentation allows parallel processing of different data streams and enables the system to handle comprehensive multi-platform data collection without proportionally increasing overall processing time, as each segment can be optimized independently.

Inventive Principle:
Principle #1Segmentation

3Reliability

If cross-platform activity attribution is implemented, then threat detection capability is improved, but computational resources required increase

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements self-service mechanisms where the graph database structure automatically optimizes query performance and the predictive analytics models are trained on historical data to efficiently identify security patterns. The system uses the inherent relationships in the graph data model to quickly traverse and analyze user activities across platforms without requiring excessive computational resources for each analysis query, as the graph structure pre-computes and stores relationship paths for efficient retrieval.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes parameters by transforming raw activity data into normalized graph representations with standardized entity types and relationship schemas. This parameter transformation includes converting various platform-specific data formats into a unified graph model where users, activities, and resources are represented as nodes and edges with consistent attributes. This standardization reduces computational complexity by eliminating the need for platform-specific processing logic during security analysis, thereby improving threat detection capability while reducing overall resource consumption.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12170680B2Systems and methods for detecting security incidents across cloud-based application services
Publication Date: 2024.12.17 OBSIDIAN SECURITY INC
  • US12170680B2 patent drawing
  • US12170680B2 patent drawing
  • US12170680B2 patent drawing

AI summary

A method, a system, and an article are provided for identification of security-related activities based on usage of a plurality of independent cloud-based, hosted application platforms. An example method includes: receiving, from the application platforms, activity data and state data for a plurality of users of the application platforms; generating one or more predictive models configured to detect deviations from normal user behavior across the application platforms; providing, as input to the one or more predictive models, the activity data and the state data for at least one of the users; receiving, from the one or more predictive models, an indication that an activity of the at least one of the users deviates from the normal user behavior; and facilitating a remedial action to address the indicated deviation.