Natural Language API for Validated Cloud Security Graph Queries
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face challenges in constructing effective cloud resource queries due to the complexity of cloud maps, understanding query results, and identifying security vulnerabilities, which are obscured by large volumes and technical nature, making it difficult to prioritize or construct meaningful follow-up queries.
Innovation Solution
A natural language API that uses a machine learning model to convert user queries into structured sentences, validate their legality, and generate cloud map queries to identify security vulnerabilities, providing query results and suggested follow-ups.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users manually construct cloud resource queries using traditional methods, then query accuracy can be maintained, but the complexity of query construction and understanding results increases significantly
Solution Approach 1:
The patent introduces a natural language processing intermediary layer that translates user-friendly natural language queries into formal cloud map queries. This mediator handles the complexity of cloud resource relationships, validation, and result interpretation, allowing users to query without understanding the underlying complex cloud map structure while maintaining query accuracy through formal validation.
Solution Approach 2:
The patent replaces the manual mechanical process of constructing complex cloud map queries with an automated natural language processing system. The ML model automatically parses, validates, and translates natural language into formal queries, eliminating the need for users to manually navigate complex cloud resource relationships and query syntax.
2Measurement precision
If cloud map queries retrieve detailed information about cloud resources, then security vulnerability identification capability is improved, but the volume of query results increases making analysis difficult
Solution Approach 1:
The patent extracts and highlights only the critical security-relevant information from comprehensive cloud map query results. The system identifies and presents specific vulnerability indicators, risk levels, and actionable findings while filtering out extraneous detailed data, allowing precise vulnerability identification without overwhelming users with excessive information volume.
3Reliability
If the system provides comprehensive query results, then security analysis completeness is improved, but the time required to analyze results and construct follow-up queries increases
Solution Approach 1:
The patent performs preliminary organization, validation, and structuring of query results before presentation to users. The system pre-processes comprehensive security data into organized, prioritized findings with contextual information and suggested follow-up actions, reducing the time users need to spend on analysis while maintaining complete security coverage.
Solution Approach 2:
The patent implements feedback mechanisms that provide users with contextual information, risk prioritization, and suggested follow-up queries based on initial results. This feedback loop guides users through the analysis process efficiently, highlighting the most critical findings first and suggesting relevant next steps, thereby reducing overall analysis time while maintaining comprehensive security coverage.
Data Source
AI summary
Disclosed are techniques for identifying security vulnerabilities in cloud computing resources. To investigate the configuration of cloud resources, a cloud map query is constructed based on a natural language sentence. In some configurations, a machine learning (ML) model converts the sentence to a structured sentence that conveys the intention of the natural language sentence but in machine readable form. The structured sentence is validated to ensure it represents a legal arrangement of cloud resources. The validated structured sentence is then used to generate a cloud map query. The cloud map query retrieves information about a client's cloud resources. In some configurations, query results are analyzed to identify security vulnerabilities and/or follow-up queries are suggested.


