Cloud Service Usage Monitoring via Network Traffic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for cloud services risk assessment are labor-intensive, costly, and lack effective controls, relying on manual questionnaires and third-party validation, which are inefficient and expensive, and do not adequately address the security concerns of cloud-based services adoption by enterprises.

Innovation Solution

A cloud service usage assessment system that analyzes network traffic and generates analytics by deploying a log processor on-premises to filter and anonymize data, which is then transmitted to an off-premises analysis engine for risk assessment, providing insights into cloud service usage and risk exposure without requiring extensive on-premises hardware or traditional questionnaire-based methods.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual questionnaire-based assessment methods are used for cloud service risk assessment, then service providers can be evaluated for compliance, but the process becomes labor-intensive, expensive, and time-consuming

Engineering Contradiction:
Improvecompliance assessment reliabilityVSAvoidassessment efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces manual mechanical assessment processes with automated electronic monitoring systems. Network event data is automatically collected, processed, and analyzed through computational algorithms rather than human reviewers manually examining questionnaires. This substitution dramatically improves productivity while maintaining assessment reliability through consistent automated evaluation criteria.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system creates digital copies of compliance assessment processes through automated data collection and analysis. Instead of original manual reviews, the system generates replicated assessments from network event data, enabling multiple evaluations without additional manual labor. This copying mechanism allows scalable assessment across numerous cloud services simultaneously.

Inventive Principle:
Principle #26Copying

2Reliability

If traditional third-party validation methods are employed for cloud service assessment, then compliance can be verified, but the cost and time requirements increase significantly

Engineering Contradiction:
Improvecompliance verification reliabilityVSAvoidvalidation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary compliance verification by continuously monitoring network event data before formal assessments are needed. Baseline compliance status is established through ongoing automated analysis, so when validation is required, the work is already substantially complete. This eliminates the need for time-consuming ad hoc third-party investigations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous automated monitoring of cloud service compliance through persistent network event data collection and analysis. Rather than periodic discrete validation events, the system maintains ongoing surveillance that continuously updates compliance status, making validation instantaneous and eliminating traditional time losses associated with scheduling and executing separate validation processes.

Inventive Principle:
Principle #20Continuity of useful action

3Measurement precision

If comprehensive network traffic analysis is performed for cloud service monitoring, then detailed risk assessment is achieved, but data privacy and security concerns increase

Engineering Contradiction:
Improveusage analysis precisionVSAvoiddata privacy risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system extracts only the specific network event data elements necessary for compliance and risk assessment while excluding sensitive information. Through selective data extraction focused on relevant metrics (data transfer volumes, service categories, compliance indicators), the system achieves precise measurement without capturing or storing privacy-sensitive details that would create security risks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary processing layer that anonymizes and aggregates network event data before analysis. This intermediary transformation preserves the analytical value needed for precise risk assessment while removing personally identifiable information and sensitive details. The intermediary layer acts as a buffer that protects data privacy while enabling comprehensive monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9825819B2Cloud service usage monitoring system
Publication Date: 2017.11.21 SKYHIGH SECURITY LLC
  • US9825819B2 patent drawing
  • US9825819B2 patent drawing
  • US9825819B2 patent drawing

AI summary

A cloud service usage assessment system analyzes network traffic from an enterprise data network and generates cloud service usage analytics for the enterprise. In some embodiments, the cloud service usage analytics may include cloud service usage risk assessment. The cloud service usage assessment system is advantageous applied to assess network security in view of an enterprise's adoption of multiple cloud based services.