Cloud Service Risk Assessment via Usage Behavior Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for cloud services risk assessment are labor-intensive, costly, and time-consuming, relying on manual questionnaires and third-party validation, which are not always cooperative and lack real-time data, especially in cloud-based environments where traditional controls are absent.

Innovation Solution

A cloud service usage risk assessment system that analyzes enterprise cloud service usage behavior and provider risk scores, generating a risk exposure index by combining network event data with continuous, real-time provider information from a cloud service registry, using a risk assessment engine to evaluate attributes across multiple risk categories.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual questionnaire-based assessment methods are used, then third-party validation and compliance verification can be achieved, but the process becomes labor-intensive, expensive, and time-consuming

Engineering Contradiction:
Improvecompliance verification reliabilityVSAvoidassessment efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces manual mechanical assessment processes with automated electronic systems. The risk assessment engine automatically collects data from cloud service providers through APIs and electronic interfaces, eliminating the need for manual questionnaire completion and third-party auditor intervention while maintaining assessment reliability

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables cloud service providers to self-report and self-assess their risk attributes through automated electronic interfaces. Providers input their own security controls and compliance data directly into the system, which then automatically processes this information through the risk assessment engine, reducing dependency on external validators

Inventive Principle:
Principle #25Self-service

2Reliability

If traditional questionnaire-based risk assessment is used, then some level of risk evaluation can be performed, but real-time data and continuous monitoring are not achieved

Engineering Contradiction:
Improverisk evaluation capabilityVSAvoidreal-time data availability
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements continuous risk assessment through automated electronic data collection from cloud service providers. The system continuously monitors and updates risk attributes by automatically retrieving current data from provider systems via APIs, ensuring real-time risk evaluation rather than periodic manual assessments

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system establishes continuous feedback loops where risk assessment results are automatically generated and fed back to enterprises in real-time. The risk assessment engine continuously processes incoming data from cloud service providers and updates risk scores dynamically, providing timely feedback for immediate decision-making

Inventive Principle:
Principle #23Feedback

3Measurement precision

If comprehensive risk assessment data collection is implemented, then accurate risk exposure measurement is achieved, but system complexity and data processing requirements increase

Engineering Contradiction:
Improverisk exposure measurement accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the complex risk assessment process into distinct modular components: data collection modules that interface with specific cloud service providers, a risk assessment engine that processes individual risk attributes, and a scoring module that aggregates results. This segmentation allows comprehensive data collection while managing system complexity through modular architecture

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The risk assessment engine is designed as a universal multi-functional system that can evaluate multiple types of cloud service providers (SaaS, PaaS, IaaS) using a standardized framework. The engine handles diverse risk attributes uniformly through a single platform, reducing overall system complexity despite comprehensive assessment capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12014306B2Cloud service usage risk assessment
Publication Date: 2024.06.18 SKYHIGH SECURITY LLC
  • US12014306B2 patent drawing
  • US12014306B2 patent drawing
  • US12014306B2 patent drawing

AI summary

A method of assessing a risk level of an enterprise using cloud-based services from one or more cloud service providers includes assessing provider risk scores associated with the one or more cloud service providers; assessing cloud service usage behavior and pattern of the enterprise; and generating a risk score for the enterprise based on the provider risk scores and on the cloud service usage behavior and pattern of the enterprise. The risk score is indicative of the risk of the enterprise relating to the use of the cloud-based services from the one or more cloud service providers.