Cloud Security Tool for Multi-Environment Vulnerability Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As the complexity and number of cloud environments grow, organizations face challenges in appropriately monitoring and resolving security vulnerabilities across different types, leading to increased susceptibility to attacks and unauthorized access to sensitive information.

Innovation Solution

A cloud security tool that determines the type of each cloud environment and selects appropriate monitoring tools and configurations to detect and address security vulnerabilities, communicating solutions to mitigate identified threats and optimize resource consumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single monitoring tool is used for all cloud environments, then device complexity is reduced, but security effectiveness deteriorates due to inability to address specific vulnerabilities of different cloud types

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the monitoring approach by cloud environment type, maintaining separate tool configurations for IaaS, PaaS, and SaaS environments. This allows each cloud type to be monitored with specialized tools while the overall system remains unified through centralized management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The monitoring system is designed with multi-functionality to handle multiple cloud environment types through a single unified platform. The system automatically detects cloud types and applies appropriate monitoring strategies, making it universally applicable across different cloud infrastructures without requiring separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If cloud environment type detection is implemented, then monitoring precision is improved, but processing time increases due to additional analysis requirements

Engineering Contradiction:
Improvecloud environment identification accuracyVSAvoidinitialization time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring monitoring tools and parameters for different cloud environment types. When a new cloud environment is detected, the system quickly matches it against known type profiles and applies pre-prepared configurations, avoiding time-consuming setup processes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system efficiently changes monitoring parameters based on detected cloud environment types. By maintaining predefined parameter sets for different cloud types and rapidly switching between them based on detection results, the system achieves accurate identification without excessive time loss.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10374906B2Cloud security tool
Publication Date: 2019.08.06 BANK OF AMERICA CORP
  • US10374906B2 patent drawing
  • US10374906B2 patent drawing
  • US10374906B2 patent drawing

AI summary

An apparatus includes a scanner and a cloud engine. The scanner determines that a first cloud environment is of a first type and that a second cloud environment is of a second type that is different from the first type. The cloud engine selects a first tool and a second tool. The cloud engine also sets a first parameter and a first configuration for the first tool and a second parameter and a second configuration for the second tool. The cloud engine further receives a first alert that a security vulnerability in the first cloud environment has been detected and a second alert that resource consumption in the second cloud environment has exceeded a threshold. The cloud engine communicates a first solution to resolve the security vulnerability in the first cloud environment and a second solution to lower resource consumption in the second cloud environment.