Proxy Device Cyber Threat Detection for Cloud Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing platforms are inadequate in detecting unauthorized access and evaluating threat levels for cloud-based applications, failing to prevent cyber-attacks and ensure secure access.

Innovation Solution

A method and system utilizing a proxy device to analyze application-layer parameters from current and previous sessions, computing a risk score to detect potential cyber threats and perform mitigation actions such as generating alerts or blocking access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud computing platforms rely on traditional security capabilities to protect infrastructure, then infrastructure protection is improved, but detection of unauthorized access to cloud-based applications is insufficient

Engineering Contradiction:
Improveinfrastructure protectionVSAvoiddetection capability
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments security detection into multiple layers: network-layer protection for infrastructure (traditional security) and application-layer analysis for cloud-based applications (new detection capability). This allows both infrastructure protection and application detection to function simultaneously without conflict.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces session analysis as an intermediary mechanism that bridges infrastructure security and application security. By analyzing application-layer parameters and session behavior, the system detects unauthorized access without compromising infrastructure protection capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If cloud computing platforms implement basic security measures, then implementation simplicity is improved, but threat level evaluation capability is insufficient

Engineering Contradiction:
Improvesecurity implementationVSAvoidthreat evaluation capability
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic threat level evaluation by continuously analyzing session parameters and comparing them against baseline behavior. The system adapts to different threat scenarios by adjusting analysis depth and response actions based on detected anomalies, providing both ease of implementation and adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes security from static rules to dynamic parameter analysis. By monitoring application-layer parameters (session duration, request patterns, data access patterns) and comparing them to established baselines, the system achieves versatile threat evaluation while maintaining implementation simplicity through automated analysis.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If cloud computing platforms use conventional security approaches, then system complexity is reduced, but detection of sophisticated cyber-attacks is insufficient

Engineering Contradiction:
Improvesecurity systemVSAvoidcyber-threat detection
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent implements feedback loops where session analysis results feed into threat level determination, which then triggers appropriate responses. This feedback mechanism enables sophisticated attack detection through continuous monitoring and adaptation without requiring complex manual intervention or system reconfiguration.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs self-service security analysis by automatically collecting application-layer parameters, analyzing session behavior, determining threat levels, and executing responses without external intervention. This maintains low system complexity while achieving sophisticated detection through automated, intelligent analysis.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3369232B1Detection of cyber threats against cloud-based applications
Publication Date: 2020.04.15 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3369232B1 patent drawingFigure 1
  • EP3369232B1 patent drawingFigure 2
  • EP3369232B1 patent drawingFigure 3

AI summary

A method and proxy device for detecting cyber threats against cloud-based application are presented. The method includes receiving a request from a client device, the request directed to a cloud-based application computing platform, wherein the client device is associated with a user attempting to access the cloud-based application; determining whether the received request belongs to a current session of the client device accessing the cloud-based application; extracting, from the received request, at least one application-layer parameter of the current session; comparing the at least one extracted application-layer parameter to application-layer parameters extracted from previous sessions to determine at least one risk factor; and computing a risk score based on the determined at least one risk factor, wherein the risk score is indicative of a potential cyber threat.