Automated IaC Monitoring for Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual inspection of changes in Infrastructure as Code (IaC) for compliance with regulation controls is complex, error-prone, and only partially addressed by existing tools, necessitating an automated monitoring solution to detect anomalous changes and ensure security during the pre-deployment phase.

Innovation Solution

Implementing an automated monitoring system that learns the security architecture and history of IaC systems, detects anomalies in source code changes, and blocks or alerts on suspicious modifications, using User and Entity Behavior Analytics to propagate changes into models and affect the CI/CD pipeline.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual inspection of IaC changes is performed, then compliance with regulation controls can be verified, but the process becomes highly complex and error-prone

Engineering Contradiction:
Improvecompliance verification reliabilityVSAvoidinspection process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces manual mechanical inspection processes with automated computer-based analysis systems. The system automatically parses IaC code, compares changes against regulated resources, and generates compliance reports without human intervention, thereby reducing complexity while maintaining reliability

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an intermediary automated analysis system that acts as a mediator between IaC code changes and compliance verification. This intermediary system handles the complex analysis work, providing reliable compliance checking while shielding users from the underlying complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If existing security tools are used for IaC monitoring, then partial security risks are addressed, but comprehensive anomaly detection remains insufficient

Engineering Contradiction:
Improvesecurity risk detectionVSAvoidanomaly detection coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal monitoring system that performs multiple functions: parsing IaC code, detecting anomalies, analyzing changes against regulated resources, and generating compliance reports. This multi-functional system provides comprehensive security coverage that adapts to various IaC formats and regulatory requirements

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements a dynamic monitoring system that adapts to changing IaC code and regulatory requirements. The system continuously learns from new code patterns and adjusts its anomaly detection thresholds, providing versatile coverage that evolves with emerging security threats and compliance standards

Inventive Principle:
Principle #15Dynamics

3Productivity

If automated monitoring of IaC changes is implemented, then manual effort and errors are reduced, but system complexity increases

Engineering Contradiction:
Improvecompliance checking efficiencyVSAvoidmonitoring system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the automated monitoring system into distinct modular components: code parsing module, anomaly detection module, change analysis module, and reporting module. Each module handles a specific aspect of the compliance checking process, improving productivity while managing complexity through modular design

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary actions by pre-configuring regulated resource definitions, anomaly detection thresholds, and compliance rules before actual IaC code monitoring begins. This preparation work is done once and reused across multiple monitoring cycles, enhancing productivity without proportionally increasing ongoing system complexity

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11550567B2User and entity behavior analytics of infrastructure as code in pre deployment of cloud infrastructure
Publication Date: 2023.01.10 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11550567B2 patent drawing
  • US11550567B2 patent drawing
  • US11550567B2 patent drawing

AI summary

The present invention relates to novel techniques for monitoring changes to source code of Infrastructure as Code systems to detect attempted anomalous changes and block such changes from the code. For example, a method may comprise learning a security architecture and history of an infrastructure as code system to be deployed in at least one cloud account, monitoring changes to source code of the infrastructure as code system that are made before deployment of the infrastructure as code system to detect an anomaly, determining whether the detected anomaly affects regulated resources of the infrastructure as code system, and blocking changes to the source code of the infrastructure as code system that produce the detected anomaly that affects regulated resources of the infrastructure as code system.