Multi-Layer Cloud Event Normalization for Transparent Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity threat detection solutions for cloud computing environments are ineffective across multiple cloud layers due to inconsistent and non-transparent AI/ML models, requiring separate solutions for each infrastructure and layer, which complicates threat detection and response.
Innovation Solution
A method and system for generating a normalized event log across multiple cloud layers, using a predefined data schema to unify event data and apply a unified rule engine for consistent threat detection, reducing redundancy and improving response time.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate AI/ML solutions are deployed for each cloud infrastructure and layer, then each solution can be optimized for that specific infrastructure, but the system complexity increases and consistent threat detection across multiple layers becomes difficult
Solution Approach 1:
The patent merges multiple cloud event sources from different cloud providers and layers into a unified event log with a standardized schema. This consolidation allows a single rule engine to process events across all cloud environments, eliminating the need for separate AI/ML solutions for each infrastructure while maintaining consistent threat detection across all layers.
Solution Approach 2:
The patent creates a universal event schema that can accommodate events from multiple cloud providers (AWS, Azure, GCP) and different cloud layers (IaaS, PaaS, SaaS). This universal schema enables a single rule engine to handle diverse event types uniformly, achieving multi-functionality without requiring separate specialized solutions for each cloud environment.
2Difficulty of detecting and measuring
If AI/ML models are used for anomaly detection in large event logs, then detection capability improves, but the models become non-transparent and inconsistent in their outputs
Solution Approach 1:
The patent replaces the opaque AI/ML decision-making process with a transparent rule-based engine. Instead of relying on black-box machine learning models that provide inconsistent outputs, the system uses explicit, interpretable rules that can be traced and understood, maintaining full transparency while effectively detecting anomalies in normalized event logs.
3Adaptability or versatility
If multiple separate solutions are managed independently for different cloud environments, then each solution can be customized, but the management overhead and time to detect threats across environments increases
Solution Approach 1:
The patent performs preliminary normalization of events from different cloud providers into a unified schema before threat detection. By pre-standardizing the event structure and creating a common event log format, the system eliminates the need for separate processing pipelines, enabling faster cross-environment threat detection while preserving the ability to handle provider-specific event types through the universal schema.
Data Source
AI summary
A system and method improves cloud detection and response by generating a normalized event log from a plurality of cloud computing layers. The method includes receiving a plurality of events, wherein a first event is generated in a first cloud layer of a cloud computing environment provided by a cloud service provider (CSP) and a second event is generated in a second cloud layer of the cloud computing environment; extracting data from each event; generating a normalized event based on the extracted data and further based on a predefined data schema, the predefined schema including a plurality of data fields, at least a portion of which are related to cloud layers; storing the normalized event in a transactional database having stored therein a normalized event log; and applying a rule from a rule engine on the normalized event to detect a cybersecurity threat in the cloud computing environment.


