Cloud Visibility Logic for Detecting Misconfigurations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a lack of effective and easy-to-use trusted third-party schemes for customers to detect whether their cloud-hosted resources have been compromised or misconfigured in public cloud networks, which are prone to cyberattacks and operational issues due to increased complexity and user or provider misconfigurations.

Innovation Solution

A cloud resource monitoring system with cloud visibility logic that gains access to cloud accounts, collects and analyzes operational log data and meta-information to identify potential cybersecurity threats and misconfigurations, providing visualization tools and alerts for administrators to remediate issues, and can be deployed within the cloud or on-premises with hybrid configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If customers use public cloud networks with multi-tenant architecture and shared resources, then resource scalability and cost efficiency are improved, but security risks and susceptibility to cyberattacks increase

Engineering Contradiction:
Improveresource scalabilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments cloud account data and operational logs into isolated containers that are individually analyzed. Each customer's cloud account data is processed separately through the analytics engine, preventing cross-contamination while maintaining comprehensive security monitoring across all tenants in the multi-tenant environment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a trusted third-party analytics system as an intermediary between cloud service providers and customers. This intermediary independently analyzes operational logs and detects compromises without requiring direct access to customer data, thereby maintaining security while enabling detection of cyberattacks in the shared cloud environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If cloud service providers handle software updates and modifications without customer involvement, then labor and cost savings are improved, but risk of account compromise and misconfiguration increases

Engineering Contradiction:
Improvelabor savingsVSAvoidaccount security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements continuous feedback loops where the analytics engine constantly monitors operational logs for anomalies caused by software updates. When suspicious changes are detected after provider-initiated updates, the system generates alerts and can trigger automated responses, providing ongoing verification without requiring customer involvement in the update process itself.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary analysis of software updates and configuration changes before they are fully deployed. The analytics engine examines operational logs to predict potential security issues or misconfigurations that may result from upcoming updates, allowing customers to take preventive actions before vulnerabilities are introduced.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If cloud account data is isolated from other customers in multi-tenant architecture, then data security between tenants is improved, but ability to detect cross-account threats and aggregate anomalies decreases

Engineering Contradiction:
Improvedata isolationVSAvoidthreat detection capability
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent adds a new analytical dimension by examining correlations across multiple isolated cloud accounts simultaneously. While individual account data remains isolated and secure, the analytics engine operates in a higher-dimensional space that considers patterns across many accounts, enabling detection of coordinated attacks or aggregate anomalies that would be invisible when analyzing single accounts in isolation.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11750618B1System and method for retrieval and analysis of operational data from customer, cloud-hosted virtual resources
Publication Date: 2023.09.05 MAGENTA SECURITY HOLDINGS LLC
  • US11750618B1 patent drawing
  • US11750618B1 patent drawing
  • US11750618B1 patent drawing

AI summary

A system for protecting public cloud-hosted virtual resources features cloud visibility logic. According to one embodiment, the cloud visibility logic includes credential evaluation logic, data collection logic, correlation logic, and reporting logic. The credential evaluation logic is configured to gain authorized access to a cloud account within a first public cloud network. The data collection logic is configured to retrieve account data from the cloud account, while the correlation logic is configured to conduct analytics on the account data to determine whether the cloud account is subject to a cybersecurity threat or misconfiguration. The reporting logic is configured to generate an alert when the cloud account is determined by the correlation logic to be subject to the cybersecurity threat or misconfiguration.