Runtime Security Graph for Cloud-Native Attack Path Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security engineering tools struggle to provide real-time, comprehensive security management across all layers of cloud-native applications, including applications, APIs, containers, virtual machines, and external services, due to the complexity of modern cloud environments and the need for better identity-based access policies.

Innovation Solution

A computer-implemented method generates a dynamic application security graph in real-time using telemetry data from microservices, incorporating identity-aware analytics to visualize and manage potential attack vectors across multiple layers, including APIs, data stores, and user identities, without manual log-based processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If log-based approaches are used to assess runtime behavior, then security analysis can be performed, but real-time capability is lost and manual processing is required

Engineering Contradiction:
Improvesecurity analysis capabilityVSAvoidreal-time capability
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The patent replaces manual log-based analysis with automated machine learning models that process telemetry data. The ML system automatically analyzes runtime behavior patterns, substitutes human analysts, and provides real-time security assessments without manual intervention.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system implements self-service through automated telemetry collection and ML-based analysis. The security platform autonomously collects data from distributed systems, processes it through trained models, and generates security insights without requiring manual log processing or human intervention at each analysis step.

Inventive Principle:
Principle #25Self-service

2Quantity of substance

If log-based approaches with instrumentation are used, then data collection can be performed, but heavy manual work and coding instrumentation are required

Engineering Contradiction:
Improvedata collection capabilityVSAvoidmanual instrumentation work
Core Design Contradiction:
Quantity of substanceVSEase of manufacture

Solution Approach 1:

The patent replaces manual instrumentation coding with automated telemetry agents deployed across the distributed system. These agents automatically collect runtime behavior data without requiring developers to write instrumentation code, substituting manual programming work with automated software agents.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The telemetry collection system is designed as a universal platform that can automatically instrument any service in the distributed system. A single telemetry agent implementation can collect data from multiple services without custom instrumentation for each, providing multi-functional data collection capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If log-based approaches are used, then security analysis can be performed, but scalability to high network traffic volume is lost

Engineering Contradiction:
Improvesecurity analysis capabilityVSAvoidscalability to high traffic volume
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent replaces manual log processing with automated machine learning systems that can process high-volume telemetry data in real-time. The ML infrastructure scales to handle large traffic volumes by distributing computation across multiple processors and utilizing efficient data streaming architectures.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system implements dynamic scaling capabilities where the telemetry collection and analysis infrastructure can automatically adjust processing capacity based on traffic volume. The ML models process data streams dynamically, adapting to varying loads without fixed processing limits.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12495063B2Multi-layer application security graph for cloud-native applications using runtime application telemetry collected in real-time
Publication Date: 2025.12.09 OPERANT AI INC
  • US12495063B2 patent drawing
  • US12495063B2 patent drawing
  • US12495063B2 patent drawing

AI summary

A computer-implemented method generates and manages a dynamic security graph that visualizes runtime security and risk context across a cloud-native application. The graph displays real-time interactions among application components, such as API traffic flows across public-facing endpoints, internal microservices, third-party APIs, and data stores. It maps user and service identities, roles, and access patterns to API and data resources, and tracks data flows that egress to external destinations. The graph highlights security vulnerabilities at each layer. Graph analytics can identify potential attack vectors by correlating risks across identities, APIs, and data layers. Embodiments include a computer system, method, and program product as recited in the claims.