Cloud Data Platform Attack Path Mapping and Runtime Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data platforms struggle to effectively monitor and mitigate attack paths in complex cloud environments, lacking comprehensive real-time and historical data analysis capabilities to detect insider threats and anomalies.

Innovation Solution

A data platform that integrates data ingestion, processing, and user interface resources to collect, analyze, and visualize data from cloud environments, utilizing agents to monitor compute assets and generate polygraphs to identify anomalous behavior patterns, enabling real-time anomaly detection and risk mitigation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive data collection and analysis is implemented to detect insider threats and anomalies, then security monitoring capability is improved, but system complexity and resource requirements increase

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments data collection by type (static configuration data vs. runtime behavior data) and by source (compute assets, storage assets, network assets). Each segment is processed through dedicated pipelines that combine specific data sources and apply targeted analysis, reducing the complexity of handling comprehensive data while maintaining thorough security monitoring.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a data platform as an intermediary layer between security tools and cloud resources. This platform ingests data from multiple sources, normalizes formats, stores data in structured repositories, and provides unified access points for analysis. The intermediary absorbs the complexity of data handling, allowing security tools to focus on analysis rather than data collection infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If real-time data processing is implemented to detect anomalies quickly, then response time to threats is improved, but processing resources and computational overhead increase

Engineering Contradiction:
Improveanomaly detection speedVSAvoidprocessing resources
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary processing of static configuration data outside the real-time window, indexing and pre-analyzing asset information before runtime events occur. This allows the runtime anomaly detection to focus only on event stream processing rather than re-processing all historical data, significantly reducing real-time computational overhead while maintaining fast response capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements periodic batch processing for historical data analysis and real-time streaming for current event monitoring. The system periodically reprocesses historical data for updated threat models while maintaining continuous real-time monitoring. This periodic approach allows intensive analysis to be performed during low-activity periods without impacting real-time response capability.

Inventive Principle:
Principle #19Periodic action

3Measurement precision

If historical data is analyzed to understand attack paths, then detection accuracy is improved, but data storage requirements and retrieval complexity increase

Engineering Contradiction:
Improvedetection accuracyVSAvoiddata storage requirements
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system extracts and separates static configuration data from runtime event data, storing them in different structured repositories. Configuration data is extracted once and indexed for rapid retrieval, while runtime events are stored as time-ordered streams. This extraction allows the system to retrieve only the necessary historical configuration information when analyzing current threats, reducing overall storage requirements while maintaining high detection accuracy through comprehensive historical context.

Inventive Principle:
Principle #2Taking out (Extraction)

4Adaptability or versatility

If multiple data sources are integrated to provide comprehensive visibility, then security coverage is improved, but data integration complexity and interoperability challenges increase

Engineering Contradiction:
Improvesecurity coverageVSAvoiddata integration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The data platform is designed as a universal ingestion layer that accepts multiple data formats and sources through standardized interfaces. The platform provides multi-functional capabilities including data collection, normalization, storage, and analysis for various asset types (compute, storage, network). This universal design allows the system to integrate diverse data sources without requiring separate integration solutions for each source type, reducing overall integration complexity while expanding security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12463997B1Attack path risk mitigation by a data platform using static and runtime data
Publication Date: 2025.11.04 FORTINET INC
  • US12463997B1 patent drawing
  • US12463997B1 patent drawing
  • US12463997B1 patent drawing

AI summary

An illustrative method includes identifying, based on static workload data associated with a compute environment, one or more attack paths from a network to one or more datasets associated with an entity, accessing runtime workload data associated with the compute environment, and performing, based on the runtime workload data, a risk mitigation operation associated with the one or more attack paths.