Normalized Cloud Event Logs for Cross-Layer Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity threat detection systems for multi-layered cloud environments are inconsistent and lack transparency, leading to challenges in detecting threats across different cloud layers and requiring redundant rule engines for each layer, which increases the risk of gaps and cybersecurity vulnerabilities.

Innovation Solution

A method and system for generating a normalized event log across multiple cloud layers using a predefined data schema to unify event logs, allowing a single rule engine to detect cybersecurity threats and reduce redundancy by applying consistent rules across different cloud layers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single rule engine is used to detect threats across multiple cloud layers, then device complexity is reduced, but measurement precision deteriorates due to the heterogeneity of events from different cloud layers

Engineering Contradiction:
Improverule engine complexityVSAvoidthreat detection precision
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent segments the event processing by creating a normalized event log that separates and standardizes events from different cloud layers (IaaS, PaaS, SaaS) into a unified format with consistent fields and schemas. This segmentation allows a single rule engine to process heterogeneous events uniformly while maintaining the ability to detect layer-specific threats with precision.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms events from multiple cloud layers by changing their parameters into a normalized format. Each event is converted to have consistent fields, data types, and schemas regardless of its source layer, enabling the single rule engine to process all events with the same detection logic while preserving the ability to identify layer-specific anomalies.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If AI/ML solutions are used for anomaly detection, then productivity is improved, but reliability deteriorates due to inconsistent outputs and lack of transparency

Engineering Contradiction:
Improveanomaly detection efficiencyVSAvoiddetection consistency
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a normalized event log as an intermediary layer between raw cloud events and the rule engine. This intermediary standardizes the input data format, ensuring that the rule engine receives consistent, transparent, and traceable events. The normalization process maintains detection efficiency while improving reliability by eliminating the inconsistency and opacity problems associated with direct AI/ML processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If separate solutions are deployed for each cloud infrastructure, then reliability is improved for each individual infrastructure, but device complexity increases due to multiple independent systems

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal normalized event log schema that can handle events from multiple cloud infrastructures (AWS, Azure, GCP, Oracle) and all cloud layers (IaaS, PaaS, SaaS) through a single system. This multi-functional approach maintains the reliability of infrastructure-specific detection by preserving event-specific fields while reducing system complexity by eliminating the need for separate independent solutions for each cloud provider.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250350619A1System and method for generating normalized event logs for cloud detection and response in a multi-layered cloud environment
Publication Date: 2025.11.13 WIZ INC
  • US20250350619A1 patent drawing
  • US20250350619A1 patent drawing
  • US20250350619A1 patent drawing

AI summary

A system and method for improving CDR by generating a normalized event log from a plurality of cloud computing layers is presented. The method includes receiving a plurality of events, wherein a first event is generated from a first cloud layer of a cloud computing environment provided by a cloud service provider (CSP) and a second event is generated from a second cloud layer of the cloud computing environment, and wherein each event includes a data record; generating a first normalized event based on data extracted from the first event; generating a second normalized event based on data extracted from the second event; applying a rule on the first normalized event and the second normalized event; detecting a cybersecurity threat based on a result of applying the rule; and initiating an active response in the cloud computing environment based on the detected cybersecurity threat.