Graph Database Cloud Security Policy Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing environments face significant security challenges due to the proliferation of network attacks and malicious content, with attackers breaching internal networks and public clouds to steal critical data by exploiting East-West traffic flows, necessitating effective security policy validation to protect enterprise assets.

Innovation Solution

A method and system utilizing a graph database to represent cloud workloads as nodes and relationships, receiving a security policy to identify violations, and providing a list of unauthorized relationships to users, enabling visualization and dynamic security policy management to protect against unauthorized communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security monitoring methods are used in cloud environments, then security threats can be detected, but the complexity of managing security policies across dynamic workloads increases significantly

Engineering Contradiction:
Improvesecurity threat detectionVSAvoidsecurity policy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a graph database that is a simplified copy or representation of the complex cloud workload relationships. This graph database captures essential security-relevant relationships without replicating the full complexity of the cloud environment, enabling easier policy validation while maintaining security monitoring effectiveness

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent transforms security policy validation from a complex operational process into a graph query operation. By changing the parameter of how validation is performed (from traditional methods to graph-based queries), the system achieves simpler policy management while maintaining reliable threat detection

Inventive Principle:
Principle #35Parameter changes

2Reliability

If comprehensive security policies are enforced across all workload relationships, then unauthorized access is prevented, but the impact on legitimate East-West traffic flows increases

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidlegitimate traffic flow
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system uses graph database queries to validate security policies and provides feedback about violations. This feedback mechanism allows security policies to be enforced accurately while identifying only actual violations, preventing over-blocking of legitimate traffic and maintaining productivity while ensuring security

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary validation of security policies using graph queries before enforcement. This preliminary action identifies potential violations in advance, allowing for fine-tuned policy configuration that prevents unauthorized access while minimizing impact on legitimate traffic flows

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security policies are validated in real-time against all workload relationships, then security violations are detected immediately, but the computational overhead and time required for validation increases

Engineering Contradiction:
Improvesecurity violation detection timelinessVSAvoidpolicy validation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent maintains a graph database that is a simplified copy of the cloud workload relationships, optimized for security validation. This copy structure enables efficient graph queries that can validate policies quickly without analyzing every single workload relationship in detail, reducing validation time while maintaining timely violation detection

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces traditional mechanical security validation methods with graph database query operations. Graph queries are computationally more efficient for relationship-based analysis, substituting heavy computational mechanics with optimized database operations that reduce validation time while maintaining detection effectiveness

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11310284B2Validation of cloud security policies
Publication Date: 2022.04.19 GRYPHO5 LLC
  • US11310284B2 patent drawing
  • US11310284B2 patent drawing
  • US11310284B2 patent drawing

AI summary

Methods and systems for validating security policy in a cloud computing environment are provided. An example method includes providing a graph database, the graph database representing workloads of the cloud computing environment as nodes and relationships between the workloads as edges, receiving a security policy, the security policy logically describing rules for the relationships between the workloads, determining, based on the security policy and the graph database, a list of violations, the list of violations including at least one relationship from the relationships between the workloads in the graph database, the at least one relationship being not allowed by at least one of the rules in the security policy, and providing the list of violations to a user.