Runtime Security Attestation for Cloud Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security technologies are inadequate in providing dynamic operational integrity attestation of application security and user reputation at runtime, especially in cloud computing environments, as they fail to address emerging threats and do not offer effective remediation, leading to high rates of false positives and negatives, and lack integration with user risk posture and external threat intelligence.
Innovation Solution
The development of systems and methods for continuous monitoring and dynamic attestation of systems, which include correlation engines, risk calculus, and user reputation scoring, to detect anomalies and threats without requiring OS hooks, and provide real-time remediation and threat identification using network and endpoint sensors, and a calculus of risk based on sensory inputs from network and endpoint sensors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional signature-based security technologies are used, then detection of known threats is improved, but detection of emerging and signature-less threats deteriorates
Solution Approach 1:
The system implements dynamic security attestation that continuously monitors runtime operational integrity of applications and systems. Instead of relying on static signatures, the system dynamically evaluates security posture through continuous attestation processes that adapt to emerging threats and changing system states, enabling detection of both known and unknown threats.
Solution Approach 2:
The patent replaces traditional mechanical signature-matching security mechanisms with a behavioral and contextual analysis system. By substituting signature-based detection with runtime attestation that monitors system behavior, resource usage patterns, and operational integrity, the system can identify emerging threats that lack known signatures.
2Ease of operation
If coarse-grained access controls are implemented, then implementation simplicity is improved, but security effectiveness deteriorates
Solution Approach 1:
The system implements fine-grained access controls by evaluating security attributes and risk postures at the individual user, device, and application level. Instead of applying uniform coarse-grained controls, the system assigns different security requirements and attestation levels to different subjects based on their specific risk profiles, enabling both simplicity and effectiveness.
Solution Approach 2:
The patent changes security parameters dynamically based on runtime attestation results. Access control decisions are made by evaluating multiple parameters including user reputation scores, device integrity states, application security postures, and contextual risk factors, allowing the system to adapt security effectiveness without sacrificing operational simplicity.
3Device complexity
If traditional security technologies operate independently, then system complexity is reduced, but security orchestration capability deteriorates
Solution Approach 1:
The system merges multiple independent security technologies into a unified attestation framework. By combining user reputation services, device integrity monitoring, application security evaluation, and threat intelligence into a single coordinated system, the patent achieves effective security orchestration while managing complexity through integrated architecture.
Solution Approach 2:
The patent creates a universal attestation platform that performs multiple security functions through a common framework. The same infrastructure supports user reputation scoring, device integrity verification, application security attestation, and threat detection, enabling versatile security orchestration without proportionally increasing system complexity.
4Measurement precision
If high-volume security scanning is performed, then threat detection coverage is improved, but data center operating capacity deteriorates
Solution Approach 1:
The system implements continuous lightweight attestation processes that run in the background without interrupting normal operations. Instead of periodic high-volume scanning that disrupts productivity, the system maintains continuous monitoring of security-relevant parameters through efficient sensors and agents that operate with minimal performance overhead.
Solution Approach 2:
The patent applies security scanning selectively based on risk assessment rather than uniformly across all systems. By performing partial scanning focused on high-risk areas and using excessive action only when necessary (such as during suspected compromise events), the system maintains thorough detection coverage while preserving data center operating capacity during normal conditions.
Data Source
AI summary
Instrumented networks and platforms having target subjects (devices, transactions, services, users, organizations) are disclosed. A security orchestration service generates runtime operational integrity profiles representing and identifying a level of threat or contextual trustworthiness, at near real time, of subjects and applications on the instrumented target platform. Systems and methods for threat identification and remediation for computing platforms based upon reconnaissance-based intelligence correlation and network/application monitoring are disclosed. In an embodiment, a method provides runtime operational integrity of a system by receiving: a dynamic context including endpoint events; and network endpoint assessments. The method generates temporal events based on the network endpoint assessments and correlates the endpoint events and temporal events before generating an integrity profile for the system. In another embodiment, flow level remediation is provided to isolate infected or compromised systems from a computing network fabric using a network trust agent, an endpoint trust agent, and a trust orchestrator.


