Cloud Threat Detection via Cross-Service Contextual Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional threat detection systems often experience false positives and miss malicious actors that operate across platforms and cloud providers, as they rely on simplistic one-to-one mappings of events rather than contextual analysis over time.

Innovation Solution

A cloud-based threat detection system that analyzes activity data from multiple cloud services to identify potentially harmful actions across user accounts and services, using contextual information to determine security violations and reduce false positives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional threat detection systems use simplistic one-to-one event mappings, then the system complexity is low, but the detection precision is poor and false positives occur

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent combines multiple event data from different cloud services and time points into a unified analysis framework. The system aggregates events from various sources (e.g., login events, file access events, API calls) and analyzes them collectively to identify malicious actors, thereby improving detection precision through comprehensive contextual analysis rather than isolated event evaluation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces temporal and contextual dimensions to traditional event analysis. Instead of analyzing events in isolation, the system incorporates time-based patterns, user behavior contexts, and cross-service correlations, transforming the analysis from a single-dimension event check to a multi-dimensional behavioral pattern recognition system.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If the system analyzes activity data from multiple cloud services with contextual information, then the detection precision improves, but the processing time and system complexity increase

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-processing and normalizing event data as it is collected from various cloud services. Event data is standardized, categorized, and stored in a unified format in advance, which enables faster real-time analysis without requiring complex processing during threat detection events, thus reducing processing time while maintaining high reliability.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the system uses contextual analysis over time across multiple platforms, then false positives are reduced, but the data processing complexity and computational resources increase

Engineering Contradiction:
Improvesecurity violation detection accuracyVSAvoiddata processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex analysis task into distinct modular components: event data collection from multiple sources, event normalization and standardization, contextual pattern matching, and threat determination. Each module handles a specific aspect of the analysis, making the overall system more manageable and efficient despite the complexity of cross-platform contextual analysis.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11637844B2Cloud-based threat detection
Publication Date: 2023.04.25 ORACLE INT CORP
  • US11637844B2 patent drawing
  • US11637844B2 patent drawing
  • US11637844B2 patent drawing

AI summary

In certain embodiments, a security system is provided to receive activity data associated with a first source. The security system may scan the activity data to determine if there are one or more actions of interest associated with a first user account in the activity data. The security system may retrieve, from memory, security rules associated with the first cloud-based service and/or an organization associated the first user account. The security system may compare the actions of interest associated with the first user account to the security rules to determine if there are one or more security violations. In certain embodiments, the security system may retrieve additional activity data from a second source. The security system may scan the additional activity data to determine if there are one or more actions of interest associated with the second user account in the additional activity data.