Sovereign Cloud Incident Investigation Workspace
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Compliance boundaries complicate incident investigations across different sovereign clouds, making it difficult to access production servers and move data for troubleshooting, especially in cases of security breaches, due to varying compliance rules and regulations.
Innovation Solution
A secure investigations platform is deployed within each sovereign cloud, featuring a request processing system, control message processing system, data/tool ingestion system, secure log generation system, and machine learning investigation system, which creates an ad-hoc workspace for investigation, ingests necessary data and tools, logs operations, and generates models for future incident analysis, all while adhering to compliance boundaries.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If compliance rules restrict access to production servers and data movement across sovereign clouds, then data security and compliance are improved, but incident investigation capability deteriorates
Solution Approach 1:
The system segments the investigation environment by creating isolated workspaces within each sovereign cloud boundary. Each workspace is a self-contained environment that prevents data from crossing compliance boundaries while still enabling investigation activities. This segmentation allows investigators to work within compliance constraints without compromising investigation effectiveness.
Solution Approach 2:
The patent introduces an intermediary investigation environment (workspace) that mediates between the restricted production servers and the investigation needs. This intermediary layer captures event data from production systems through compliant interfaces, allowing investigation without direct access to production servers or cross-boundary data movement.
2Productivity
If investigators are granted access to production servers for troubleshooting, then investigation effectiveness is improved, but security risk and compliance violation potential worsen
Solution Approach 1:
The system performs preliminary actions by pre-configuring secure workspaces with necessary investigation tools and event capture capabilities before investigations begin. Event capture mechanisms are pre-established to collect relevant data from production systems through compliant interfaces, eliminating the need for investigators to access production servers directly during investigations.
Solution Approach 2:
The patent creates a copy of the investigation environment within the sovereign cloud boundary, including replicated tools and pre-captured event data. This copy enables investigators to perform analysis and troubleshooting activities without accessing the actual production servers, thus maintaining security while preserving investigation effectiveness.
3Productivity
If data is moved across compliance boundaries for centralized analysis, then investigation efficiency is improved, but compliance rule violations worsen
Solution Approach 1:
The system applies local quality by tailoring the investigation environment to each sovereign cloud's specific compliance requirements. Each workspace is configured with local event capture capabilities and investigation tools appropriate to that jurisdiction's regulations, enabling efficient investigations without requiring data movement across boundaries. The workspace adapts to local compliance qualities rather than imposing a uniform approach.
Data Source
AI summary
A secure investigation platform in a sovereign cloud includes a request processing system that receives requests to investigate an incident. A control message processing system creates a workspace, within the sovereign cloud, so that an investigation can be conducted within that workspace. The control message processing system performs investigation tasks within the workspace. A secure log generation system captures information corresponding to the tasks and generates an event record based on the captured information.


