Proxy Device Cyber Threat Detection for Cloud Applications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud computing platforms are inadequate in detecting unauthorized access and evaluating threat levels for cloud-based applications, failing to prevent cyber-attacks and ensure secure access.
Innovation Solution
A method and system utilizing a proxy device to analyze application-layer parameters from current and previous sessions, computing a risk score to detect potential cyber threats and perform mitigation actions such as generating alerts or blocking access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cloud computing platforms rely on traditional security capabilities to protect infrastructure, then infrastructure protection is improved, but detection of unauthorized access to cloud-based applications is insufficient
Solution Approach 1:
The patent segments security detection into multiple layers: network-layer protection for infrastructure (traditional security) and application-layer analysis for cloud-based applications (new detection capability). This allows both infrastructure protection and application detection to function simultaneously without conflict.
Solution Approach 2:
The patent introduces session analysis as an intermediary mechanism that bridges infrastructure security and application security. By analyzing application-layer parameters and session behavior, the system detects unauthorized access without compromising infrastructure protection capabilities.
2Ease of manufacture
If cloud computing platforms implement basic security measures, then implementation simplicity is improved, but threat level evaluation capability is insufficient
Solution Approach 1:
The patent implements dynamic threat level evaluation by continuously analyzing session parameters and comparing them against baseline behavior. The system adapts to different threat scenarios by adjusting analysis depth and response actions based on detected anomalies, providing both ease of implementation and adaptability.
Solution Approach 2:
The patent changes security from static rules to dynamic parameter analysis. By monitoring application-layer parameters (session duration, request patterns, data access patterns) and comparing them to established baselines, the system achieves versatile threat evaluation while maintaining implementation simplicity through automated analysis.
3Device complexity
If cloud computing platforms use conventional security approaches, then system complexity is reduced, but detection of sophisticated cyber-attacks is insufficient
Solution Approach 1:
The patent implements feedback loops where session analysis results feed into threat level determination, which then triggers appropriate responses. This feedback mechanism enables sophisticated attack detection through continuous monitoring and adaptation without requiring complex manual intervention or system reconfiguration.
Solution Approach 2:
The system performs self-service security analysis by automatically collecting application-layer parameters, analyzing session behavior, determining threat levels, and executing responses without external intervention. This maintains low system complexity while achieving sophisticated detection through automated, intelligent analysis.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method and proxy device for detecting cyber threats against cloud-based application are presented. The method includes receiving a request from a client device, the request directed to a cloud-based application computing platform, wherein the client device is associated with a user attempting to access the cloud-based application; determining whether the received request belongs to a current session of the client device accessing the cloud-based application; extracting, from the received request, at least one application-layer parameter of the current session; comparing the at least one extracted application-layer parameter to application-layer parameters extracted from previous sessions to determine at least one risk factor; and computing a risk score based on the determined at least one risk factor, wherein the risk score is indicative of a potential cyber threat.