Cloud Workload Security Alert Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud workload security systems face high false positive rates, leading to missed true-positive alerts and compromised security defenses, as both runtime and pre-deployment security testing struggle to validate alerts effectively.

Innovation Solution

Combining development testing and runtime monitoring to share insights between pre and post-deployment environments, using techniques such as application log analysis, call graphs, and error handling to generate and escalate accurate performance and security alerts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If runtime security monitoring and pre-deployment security testing are performed separately, then security coverage is maintained, but false positive rates remain high and true positives are missed

Engineering Contradiction:
Improvealert accuracyVSAvoidmissed true positives
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent combines pre-deployment security testing data with runtime security monitoring data into a unified analysis system. By merging these previously separate security functions, the system correlates alerts across both phases, reducing false positives and improving detection accuracy without losing coverage in either phase.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If security monitoring produces comprehensive alerts, then security coverage is improved, but false positive rate increases causing systems to ignore alerts

Engineering Contradiction:
Improvesecurity coverageVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system implements feedback loops where alerts from both pre-deployment testing and runtime monitoring are correlated and validated against each other. This feedback mechanism allows the system to distinguish true positives from false positives by checking consistency across different monitoring phases, thereby maintaining comprehensive coverage while improving alert precision.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If pre-deployment security testing is performed thoroughly, then security weaknesses are detected, but time and resources are consumed without validation of alerts

Engineering Contradiction:
Improvealert validationVSAvoidtesting time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary security testing during the pre-deployment phase to establish a baseline of security weaknesses and generate initial alerts. This preliminary action is then validated against runtime monitoring data, allowing the system to efficiently identify which pre-deployment alerts represent true security issues without requiring exhaustive manual validation of each alert.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11947444B2Sharing insights between pre and post deployment to enhance cloud workload security
Publication Date: 2024.04.02 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11947444B2 patent drawing
  • US11947444B2 patent drawing
  • US11947444B2 patent drawing

AI summary

Embodiments may provide techniques that may provide more accurate and actionable alerts by cloud workload security systems so as to improve overall cloud workload security. For example, in an embodiment, a method may be implemented in a computer system comprising a processor, memory accessible by the processor, and computer program instructions stored in the memory and executable by the processor, and the method may comprise generating performance and security information relating to a software system during development of the software system, generating performance and security information relating to the software system during deployed operation of the software system, matching the performance and security information generated during development of the software system with the performance and security information generated during deployed operation of the software system to determine performance and security alerts to escalate, and reporting the escalated performance and security alerts.