Containerized Application Identity Audit Trail and Privilege Escalation Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing systems face security and legal compliance issues due to the obfuscation of human identities when using service accounts, leading to unauthorized access and lack of audit trails for network activities, which can result in privilege escalation and compliance violations.

Innovation Solution

The system associates network activities with the identity of human system operators by recording and encrypting their actions, using ephemeral virtual network interfaces and access control lists to prevent unauthorized access and maintain an audit trail, allowing for granular testing and compliance with legal requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If service accounts are used to obfuscate human identities in distributed computer services, then automation and ease of operation are improved, but security and accountability deteriorate due to loss of identity information

Engineering Contradiction:
ImproveautomationVSAvoididentity information
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent introduces an intermediary system that sits between the service account and the human operator, capturing and preserving identity information through contextualization layers and audit trails. This intermediary maintains the automation benefits of service accounts while preventing information loss by recording the human operator's identity and intent separately from the automated service account actions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If service accounts are used to simplify access to distributed services, then ease of operation is improved, but security deteriorates due to potential privilege escalation

Engineering Contradiction:
Improveaccess simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by establishing identity association and access control checks before service account actions are executed. The system pre-configures contextualization layers that bind human operator identities to service account actions, and performs preliminary authorization verification to prevent privilege escalation before it can occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs feedback mechanisms through comprehensive audit trails that track and record service account actions back to their human operator origins. This feedback loop enables continuous monitoring and detection of unauthorized privilege escalation attempts, allowing the system to respond to security violations in real-time.

Inventive Principle:
Principle #23Feedback

3Extent of automation

If service accounts obfuscate human identities, then automation is improved, but legal compliance deteriorates due to lack of audit trails

Engineering Contradiction:
Improveservice account automationVSAvoidaudit trail information
Core Design Contradiction:
Extent of automationVSLoss of information

Solution Approach 1:

The patent applies segmentation by separating the automated service account identity from the human operator identity into distinct contextualization layers. This segmentation allows the system to maintain automated service account operations while simultaneously preserving separate, traceable audit trails that link actions back to human operators for compliance purposes.

Inventive Principle:
Principle #1Segmentation

4Ease of operation

If access control is not enforced on service accounts, then ease of operation is improved, but security deteriorates due to unauthorized access

Engineering Contradiction:
Improveaccess freedomVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary anti-action by establishing access control lists and authorization checks that prevent unauthorized access before it can occur. The system proactively blocks potentially harmful actions by verifying human operator identities and permissions against configured access control policies, countering unauthorized access attempts before they can execute.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS12160426B2Human system operator identity associated audit trail of containerized network application with prevention of privilege escalation, online black-box testing, and related systems and methods
Publication Date: 2024.12.03 HASAN ASAD
  • US12160426B2 patent drawing
  • US12160426B2 patent drawing
  • US12160426B2 patent drawing

AI summary

Human system operator identity audit trail systems, methods and products for improving computer technology, including in the field of cloud security in the use of computer networks and legal compliance of computer systems and networks is disclosed. An audit trail of a human system operator's identity and time-stamp to network activities of a containerized application may be established. A human system operator may be prevented from escalating privilege and making unauthorized use of service accounts available to the containerized application in order to issue commands such as higher privilege queries and requests than the ones within the granted access of the human system operator. Granular black-box testing mechanisms may also be provided to assess functional changes across software versions using boundary-scan techniques.