LLM-Based Cloud Configuration Recommendation and Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current asset and cloud configuration management systems face challenges in efficiently recommending and validating configurations due to the diversity and volume of assets, leading to scalability issues and increased vulnerability to security incidents, as they rely on manual definition of restrictive access permissions and rule-based validation processes.

Innovation Solution

The implementation of a generative artificial intelligence system using large language models (LLMs) to recommend and validate asset and cloud configurations, which trains on semantic matching to generate recommended configurations and validate existing ones, incorporating external signals for intelligent decision-making and continuous security control validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual definition of restrictive access permissions and rule-based validation processes is used, then security control validation can be maintained, but scalability becomes difficult and the system becomes complex

Engineering Contradiction:
Improvesecurity control validationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces manual mechanical processes of defining access permissions and validating configurations with an AI-based system. The LLM automatically generates configuration recommendations and validates them against security policies, eliminating the need for manual rule definition and reducing system complexity while maintaining security validation reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service configuration management where the AI model autonomously generates configuration recommendations, validates them against security policies, and provides explanations. This self-service capability reduces the burden on administrators and simplifies the overall system operation while maintaining reliable security control validation.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual definition of restrictive access permissions is used, then security can be maintained, but productivity decreases due to increased workload

Engineering Contradiction:
ImprovesecurityVSAvoidadministrator efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces manual mechanical processes of defining access permissions and validating configurations with an AI-based system. The LLM automatically generates configuration recommendations and validates them against security policies, eliminating the need for manual rule definition and reducing system complexity while maintaining security validation reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs preliminary action by automatically generating configuration recommendations before they are applied. The AI model pre-validates configurations against security policies and provides explanations in advance, allowing administrators to review and approve configurations more efficiently without compromising security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If rule-based validation processes are used, then configuration validation can be performed, but the volume of rules increases and management becomes difficult

Engineering Contradiction:
Improveconfiguration validationVSAvoidnumber of rules
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent replaces manual mechanical processes of defining access permissions and validating configurations with an AI-based system. The LLM automatically generates configuration recommendations and validates them against security policies, eliminating the need for manual rule definition and reducing system complexity while maintaining security validation reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the fundamental parameter of validation from explicit rule-based checking to AI-based semantic understanding. Instead of managing large numbers of explicit rules, the LLM uses its trained knowledge base to understand and validate configurations, effectively reducing the quantity of rules while maintaining validation reliability.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250023779A1Using large language models to recommend and validate asset and/or cloud configurations
Publication Date: 2025.01.16 CROWDSTRIKE
  • US20250023779A1 patent drawing
  • US20250023779A1 patent drawing
  • US20250023779A1 patent drawing

AI summary

A system and method of using generative AI to recommend and validate asset and/or cloud configurations. The method includes acquiring a set of parameters associated with one or more network entities of a computing network. The method includes providing the set of parameters to a configuration model trained to generate, based on semantic matching, recommended configurations for network entities and validated configurations for the network entities. The method includes generating, by a processing device using the configuration model, one or more recommended configurations for the one or more network entities based on the set of parameters.