Runtime Security Attestation for Cloud Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security technologies are inadequate in providing dynamic operational integrity attestation of application security and user reputation at runtime, especially in cloud computing environments, as they fail to address emerging threats and do not offer effective remediation, leading to high rates of false positives and negatives, and lack integration with user risk posture and external threat intelligence.

Innovation Solution

The development of systems and methods for continuous monitoring and dynamic attestation of systems, which include correlation engines, risk calculus, and user reputation scoring, to detect anomalies and threats without requiring OS hooks, and provide real-time remediation and threat identification using network and endpoint sensors, and a calculus of risk based on sensory inputs from network and endpoint sensors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional signature-based security technologies are used, then detection of known threats is improved, but detection of emerging and signature-less threats deteriorates

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidability to detect emerging threats
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic security attestation that continuously monitors runtime operational integrity of applications and systems. Instead of relying on static signatures, the system dynamically evaluates security posture through continuous attestation processes that adapt to emerging threats and changing system states, enabling detection of both known and unknown threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent replaces traditional mechanical signature-matching security mechanisms with a behavioral and contextual analysis system. By substituting signature-based detection with runtime attestation that monitors system behavior, resource usage patterns, and operational integrity, the system can identify emerging threats that lack known signatures.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If coarse-grained access controls are implemented, then implementation simplicity is improved, but security effectiveness deteriorates

Engineering Contradiction:
Improveaccess control implementationVSAvoidsecurity protection effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements fine-grained access controls by evaluating security attributes and risk postures at the individual user, device, and application level. Instead of applying uniform coarse-grained controls, the system assigns different security requirements and attestation levels to different subjects based on their specific risk profiles, enabling both simplicity and effectiveness.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes security parameters dynamically based on runtime attestation results. Access control decisions are made by evaluating multiple parameters including user reputation scores, device integrity states, application security postures, and contextual risk factors, allowing the system to adapt security effectiveness without sacrificing operational simplicity.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If traditional security technologies operate independently, then system complexity is reduced, but security orchestration capability deteriorates

Engineering Contradiction:
Improvesecurity system structureVSAvoidsecurity orchestration capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The system merges multiple independent security technologies into a unified attestation framework. By combining user reputation services, device integrity monitoring, application security evaluation, and threat intelligence into a single coordinated system, the patent achieves effective security orchestration while managing complexity through integrated architecture.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal attestation platform that performs multiple security functions through a common framework. The same infrastructure supports user reputation scoring, device integrity verification, application security attestation, and threat detection, enabling versatile security orchestration without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If high-volume security scanning is performed, then threat detection coverage is improved, but data center operating capacity deteriorates

Engineering Contradiction:
Improvethreat detection coverageVSAvoiddata center operating capacity
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system implements continuous lightweight attestation processes that run in the background without interrupting normal operations. Instead of periodic high-volume scanning that disrupts productivity, the system maintains continuous monitoring of security-relevant parameters through efficient sensors and agents that operate with minimal performance overhead.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The patent applies security scanning selectively based on risk assessment rather than uniformly across all systems. By performing partial scanning focused on high-risk areas and using excessive action only when necessary (such as during suspected compromise events), the system maintains thorough detection coverage while preserving data center operating capacity during normal conditions.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9092616B2Systems and methods for threat identification and remediation
Publication Date: 2015.07.28 TAASERA LICENSING LLC
  • US9092616B2 patent drawing
  • US9092616B2 patent drawing
  • US9092616B2 patent drawing

AI summary

Instrumented networks and platforms having target subjects (devices, transactions, services, users, organizations) are disclosed. A security orchestration service generates runtime operational integrity profiles representing and identifying a level of threat or contextual trustworthiness, at near real time, of subjects and applications on the instrumented target platform. Systems and methods for threat identification and remediation for computing platforms based upon reconnaissance-based intelligence correlation and network/application monitoring are disclosed. In an embodiment, a method provides runtime operational integrity of a system by receiving: a dynamic context including endpoint events; and network endpoint assessments. The method generates temporal events based on the network endpoint assessments and correlates the endpoint events and temporal events before generating an integrity profile for the system. In another embodiment, flow level remediation is provided to isolate infected or compromised systems from a computing network fabric using a network trust agent, an endpoint trust agent, and a trust orchestrator.