Security Graph Modeling for Cloud Network Vulnerability Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network analysis solutions struggle to provide efficient and comprehensive insights into large, multi-layered network systems, especially in managing access and vulnerabilities across distributed environments.

Innovation Solution

A system and method for modeling a cloud environment as a security graph, identifying security objects, collecting object data, constructing a security graph, determining relationships among objects using static analysis, and storing the graph in a database for enhanced network security analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual review of devices and connections is performed, then thorough and specific analysis of individual network elements is achieved, but prohibitive time and effort requirements prevent analysis of large multi-layer networks

Engineering Contradiction:
Improveanalysis thoroughnessVSAvoidreview time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent creates a virtual model (security graph) that copies and represents the actual network structure, allowing analysis of the model instead of the physical network. This enables comprehensive analysis without the time penalties of manual review, as the virtual model can be processed automatically and queried efficiently.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The security graph acts as an intermediary between the physical network and the analysis process. It captures network relationships in a structured format that enables automated analysis tools to efficiently query and analyze network properties without requiring direct manual inspection of each device and connection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If protocol-specific analysis solutions are used, then monitoring of specific device types and protocols is improved, but streamlined monitoring of all network components across multiple protocols is lost

Engineering Contradiction:
Improveprotocol-specific monitoring accuracyVSAvoidmulti-protocol monitoring capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The security graph provides a universal framework that can represent and analyze multiple protocol types and device categories within a single unified model. The graph structure accommodates heterogeneous network elements and their relationships without requiring separate analysis solutions for each protocol, enabling both specific and comprehensive monitoring simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If protocol-agnostic solutions are deployed, then overall traffic management is simplified, but device-specific insights are lost and connection monitoring efficacy is reduced

Engineering Contradiction:
Improveoverall traffic management simplicityVSAvoiddevice-specific insight accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The security graph enables different levels of analysis granularity within the same system. While providing simplified overall network visibility through the unified graph model, it simultaneously preserves detailed device-specific properties and relationships in the graph data structures, allowing queries to retrieve both high-level overview information and specific device details as needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250202951A1Static analysis techniques for determining reachability properties of network and computing objects
Publication Date: 2025.06.19 WIZ INC
  • US20250202951A1 patent drawing
  • US20250202951A1 patent drawing
  • US20250202951A1 patent drawing

AI summary

A method and system for modeling a cloud environment as a security graph are provided. The method includes identifying security objects in the cloud environment; collecting object data of the identified security objects; constructing security graph based on collected object data of the identified security objects; determining relationships among the identified security objects, wherein the relationships are determined based on the collected object data of the identified security objects and using a static analysis process; updating the constructed security graph with the determined relationships among the identified security objects; and storing the constructed security graph in a graph database.