Cloud Security Remediation Workflow for Automated Cross-Platform Response
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security solutions for cloud resources lack efficient remediation capabilities and often require manual user input, leading to prolonged delays between detection and remediation of security issues, and are limited by vendor lock-in and lack of interoperability.
Innovation Solution
A security engine system comprising a transformation module, main message broker, and remediation server automatically determines security events, sends them to a decision server for recommended remediation actions, and executes these actions without user input, using an abstraction layer to facilitate interoperability across different cloud environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If security findings hubs are used to detect security issues, then detection capability is improved, but remediation capability deteriorates due to lack of automated remediation means
Solution Approach 1:
The patent introduces a security orchestration, automation, and response system as an intermediary between the security findings hub and remediation actions. This mediator receives security events from the findings hub, processes them through transformation modules and message brokers, and automatically executes remediation scripts, thereby bridging the gap between detection and remediation capabilities
Solution Approach 2:
The system enables automated self-service remediation by configuring the orchestration system to automatically process security events and execute remediation actions without human intervention. The automated workflow transforms security events into remediation tasks and executes them through remediation servers, allowing the system to remediate its own detected issues independently
2Extent of automation
If third-party security orchestration systems are used to enable automated remediation, then remediation automation is improved, but interoperability deteriorates due to lack of native API integration with security findings hubs
Solution Approach 1:
The patent implements a universal integration approach where the security orchestration system can communicate with multiple types of security findings hubs through standardized protocols and APIs. The transformation module and message broker architecture enables the system to handle different event formats and protocols, making it universally compatible with various cloud providers and security tools without requiring vendor-specific customizations
3Reliability
If manual user input is required for remediation actions, then control and security are improved, but remediation speed deteriorates due to delays between detection and remediation
Solution Approach 1:
The system performs preliminary configuration of remediation workflows, scripts, and policies in advance before security events occur. Security events are pre-configured with associated remediation actions, and the orchestration system is pre-configured with the authority to execute these actions automatically. When a security event is detected, the pre-configured remediation workflow can be executed immediately without requiring real-time user approval, thereby maintaining control through pre-established policies while achieving rapid remediation
Data Source
AI summary
A method performed by a security engine system to remediate a security issue of a computing resource. A transformation module may determine a security event from a description of the security issue, and a main message broker may send the security event to a decision server to obtain a sequence of recommended remediation actions based on the security event. A remediation server may then execute remediation scripts, each remediation script implementing at least a remediation action from the sequence of recommended remediation actions, each remediation action being applied to the computing resource.

