Cloud Security System Service Action Categorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in effectively monitoring and securing cloud-based services due to the vast number of applications and service actions provided by multiple cloud service providers, which lack standardization, making it difficult for information security officers to detect threats and enforce security policies without prior knowledge of each service.

Innovation Solution

Implementing a cloud security system that categorizes service actions into a limited set of service action categories, using user role identification and intent and sequence-based contextual identification, allowing for threat detection and security policy enforcement without requiring knowledge of specific cloud applications or service actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud service providers offer a large number of applications and service actions, then service functionality and versatility are improved, but security monitoring complexity and difficulty increase

Engineering Contradiction:
Improveservice functionalityVSAvoidsecurity monitoring complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the vast number of cloud service actions into a manageable set of categories (e.g., data access, data modification, authentication, administrative actions). This segmentation allows security systems to monitor categorized actions rather than individual service actions, reducing monitoring complexity while maintaining comprehensive security coverage across diverse cloud services.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal categorization framework that can be applied across multiple cloud service providers and their diverse applications. This universal category system enables a single security monitoring approach to handle various service actions from different providers, reducing the need for provider-specific monitoring expertise while maintaining versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If cloud service providers provide diverse applications without standardization, then service variety is improved, but threat detection accuracy deteriorates

Engineering Contradiction:
Improveservice varietyVSAvoidthreat detection accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent applies local quality by tailoring specific detection rules and policies to different service action categories while maintaining a unified categorization framework. Each category can have customized security rules appropriate to its nature (e.g., stricter controls for data modification actions vs. data access actions), enabling accurate threat detection across diverse services without requiring deep knowledge of each specific application.

Inventive Principle:
Principle #3Local quality

3Reliability

If information security officers monitor each individual cloud service action, then threat detection completeness is improved, but time consumption and operational efficiency worsen

Engineering Contradiction:
Improvethreat detection completenessVSAvoidmonitoring time consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges multiple individual service action monitoring tasks into consolidated category-level monitoring. By grouping related service actions into categories and monitoring at the category level, the system maintains comprehensive threat detection coverage while significantly reducing the time and resources required for monitoring compared to examining each individual service action separately.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11729219B2Cloud security system implementing service action categorization
Publication Date: 2023.08.15 SKYHIGH SECURITY LLC
  • US11729219B2 patent drawing
  • US11729219B2 patent drawing
  • US11729219B2 patent drawing

AI summary

A service action category based cloud security system and method implement cloud security by categorizing service actions of cloud service providers into a set of service action categories. The service action categorization is performed agnostic to the applications or functions provided by the cloud service providers and also agnostic to the cloud service providers. With the service actions of cloud service providers thus categorized, cloud security monitoring and threat detection can be performed based on service action categories. Thus, cloud security can be implemented without requiring knowledge of the applications supported by the cloud service providers and without knowing all of the individual service actions supported by the cloud service providers.