Hybrid Sensor Backend for Cloud Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity solutions for cloud computing environments face challenges due to the impracticality of agent-based systems, which require heavy resource usage and root privileges, and the incompleteness of agentless solutions that lack real-time threat detection, leading to undetected threats.
Innovation Solution
A hybrid approach combining sensors that collect runtime data and perform static analysis, with a sensor backend server managing inspections and prioritizing mitigation actions based on threat validation, utilizing a security graph for comprehensive threat detection and response.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If agent-based solutions are deployed to detect cybersecurity threats, then complete picture of cybersecurity status and real-time threat detection are achieved, but heavy compute resources and root privileges are required
Solution Approach 1:
The patent introduces sensors as intermediary components that collect runtime data from workloads and transmit it to a backend server for analysis. This mediator architecture allows the system to obtain real-time threat detection capabilities without requiring heavy agent-based solutions on each endpoint, thereby reducing compute resource consumption while maintaining reliability.
Solution Approach 2:
The patent extracts the heavy computational analysis function from the endpoint agents and relocates it to a centralized backend server. By taking out the resource-intensive threat analysis from individual workloads and performing it centrally, the system achieves complete threat detection without imposing heavy compute resource demands on each endpoint.
2Use of energy by moving object
If static analysis is used to inspect workloads, then resource overhead is reduced, but real-time threat detection capability is lost
Solution Approach 1:
The patent merges static analysis with runtime data collection by combining sensors that gather runtime information with inspection mechanisms that analyze workload states. This hybrid approach maintains low resource overhead while recovering real-time threat detection capability, as the system continuously monitors runtime data to detect threats as they occur.
Solution Approach 2:
The patent implements preliminary actions by deploying sensors on workloads that continuously collect runtime data before threats can fully manifest or spread. This proactive data collection enables the backend server to perform timely analysis and detect threats in real-time, preventing time loss associated with reactive threat response.
3Reliability
If both agent-based and agentless solutions are deployed, then comprehensive threat detection is achieved, but computational costs become prohibitive
Solution Approach 1:
The patent creates a universal sensor-based platform that performs multiple functions: collecting runtime data, enabling static analysis, and supporting real-time threat detection. This multi-functional approach replaces the need for separate agent-based and agentless solutions, achieving comprehensive threat detection while reducing overall computational costs by consolidating functionality into a single efficient architecture.
Data Source
AI summary
A system and method for validating cybersecurity issues utilizing runtime data is disclosed. In an embodiment the method includes: inspecting a workload deployed in a computing environment for a cybersecurity issue; deploying a sensor on the workload, the sensor configured to collect runtime data from the workload; initiating a first mitigation action with a first priority in the computing environment in response to validating the cybersecurity issue from the collected runtime data; initiating a second mitigation action with a second priority, which is lower than the first priority, in response to failing to validate the cybersecurity issue from the collected runtime data.


