Natural Language API for Validated Cloud Security Graph Queries

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges in constructing effective cloud resource queries due to the complexity of cloud maps, understanding query results, and identifying security vulnerabilities, which are obscured by large volumes and technical nature, making it difficult to prioritize or construct meaningful follow-up queries.

Innovation Solution

A natural language API that uses a machine learning model to convert user queries into structured sentences, validate their legality, and generate cloud map queries to identify security vulnerabilities, providing query results and suggested follow-ups.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users manually construct cloud resource queries using traditional methods, then query accuracy can be maintained, but the complexity of query construction and understanding results increases significantly

Engineering Contradiction:
Improvequery construction easeVSAvoidcloud map complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a natural language processing intermediary layer that translates user-friendly natural language queries into formal cloud map queries. This mediator handles the complexity of cloud resource relationships, validation, and result interpretation, allowing users to query without understanding the underlying complex cloud map structure while maintaining query accuracy through formal validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the manual mechanical process of constructing complex cloud map queries with an automated natural language processing system. The ML model automatically parses, validates, and translates natural language into formal queries, eliminating the need for users to manually navigate complex cloud resource relationships and query syntax.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If cloud map queries retrieve detailed information about cloud resources, then security vulnerability identification capability is improved, but the volume of query results increases making analysis difficult

Engineering Contradiction:
Improvevulnerability identification precisionVSAvoidquery results volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts and highlights only the critical security-relevant information from comprehensive cloud map query results. The system identifies and presents specific vulnerability indicators, risk levels, and actionable findings while filtering out extraneous detailed data, allowing precise vulnerability identification without overwhelming users with excessive information volume.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If the system provides comprehensive query results, then security analysis completeness is improved, but the time required to analyze results and construct follow-up queries increases

Engineering Contradiction:
Improvesecurity analysis completenessVSAvoidanalysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary organization, validation, and structuring of query results before presentation to users. The system pre-processes comprehensive security data into organized, prioritized findings with contextual information and suggested follow-up actions, reducing the time users need to spend on analysis while maintaining complete security coverage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms that provide users with contextual information, risk prioritization, and suggested follow-up queries based on initial results. This feedback loop guides users through the analysis process efficiently, highlighting the most critical findings first and suggesting relevant next steps, thereby reducing overall analysis time while maintaining comprehensive security coverage.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12380096B1Natural language API for security graph exploration
Publication Date: 2025.08.05 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12380096B1 patent drawing
  • US12380096B1 patent drawing
  • US12380096B1 patent drawing

AI summary

Disclosed are techniques for identifying security vulnerabilities in cloud computing resources. To investigate the configuration of cloud resources, a cloud map query is constructed based on a natural language sentence. In some configurations, a machine learning (ML) model converts the sentence to a structured sentence that conveys the intention of the natural language sentence but in machine readable form. The structured sentence is validated to ensure it represents a legal arrangement of cloud resources. The validated structured sentence is then used to generate a cloud map query. The cloud map query retrieves information about a client's cloud resources. In some configurations, query results are analyzed to identify security vulnerabilities and/or follow-up queries are suggested.