Cloud Threat Detection via Cross-Service Contextual Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional threat detection systems often experience false positives and miss malicious actors that operate across platforms and cloud providers, as they rely on simplistic one-to-one mappings of events rather than contextual analysis over time.
Innovation Solution
A cloud-based threat detection system that analyzes activity data from multiple cloud services to identify potentially harmful actions across user accounts and services, using contextual information to determine security violations and reduce false positives.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional threat detection systems use simplistic one-to-one event mappings, then the system complexity is low, but the detection precision is poor and false positives occur
Solution Approach 1:
The patent combines multiple event data from different cloud services and time points into a unified analysis framework. The system aggregates events from various sources (e.g., login events, file access events, API calls) and analyzes them collectively to identify malicious actors, thereby improving detection precision through comprehensive contextual analysis rather than isolated event evaluation.
Solution Approach 2:
The patent introduces temporal and contextual dimensions to traditional event analysis. Instead of analyzing events in isolation, the system incorporates time-based patterns, user behavior contexts, and cross-service correlations, transforming the analysis from a single-dimension event check to a multi-dimensional behavioral pattern recognition system.
2Reliability
If the system analyzes activity data from multiple cloud services with contextual information, then the detection precision improves, but the processing time and system complexity increase
Solution Approach 1:
The system performs preliminary actions by pre-processing and normalizing event data as it is collected from various cloud services. Event data is standardized, categorized, and stored in a unified format in advance, which enables faster real-time analysis without requiring complex processing during threat detection events, thus reducing processing time while maintaining high reliability.
3Reliability
If the system uses contextual analysis over time across multiple platforms, then false positives are reduced, but the data processing complexity and computational resources increase
Solution Approach 1:
The patent segments the complex analysis task into distinct modular components: event data collection from multiple sources, event normalization and standardization, contextual pattern matching, and threat determination. Each module handles a specific aspect of the analysis, making the overall system more manageable and efficient despite the complexity of cross-platform contextual analysis.
Data Source
AI summary
In certain embodiments, a security system is provided to receive activity data associated with a first source. The security system may scan the activity data to determine if there are one or more actions of interest associated with a first user account in the activity data. The security system may retrieve, from memory, security rules associated with the first cloud-based service and/or an organization associated the first user account. The security system may compare the actions of interest associated with the first user account to the security rules to determine if there are one or more security violations. In certain embodiments, the security system may retrieve additional activity data from a second source. The security system may scan the additional activity data to determine if there are one or more actions of interest associated with the second user account in the additional activity data.


