Unified Identity Graph for Multi-Cloud Vulnerability Scanning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions for cloud workload vulnerability scanning are costly, time-consuming, and fail to provide comprehensive coverage of cloud environments, particularly for multi-tenant setups and hybrid cloud architectures.
Innovation Solution
A method and system for generating a security graph using a unified model across multiple cloud computing environments, which involves receiving data on resources, principals, and permissions, and creating nodes and connections in the graph based on this data to visualize and manage access permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If specialized scanning agents are deployed for each cloud environment, then vulnerability detection capability is improved, but device complexity and resource usage increase
Solution Approach 1:
The patent creates a unified identity model that serves multiple cloud environments (AWS, Azure, GCP) simultaneously. Instead of deploying separate scanning agents for each cloud platform, a single agentless system uses standardized identity graphs to represent principals, resources, and permissions across all environments, enabling universal vulnerability detection without increasing device complexity
Solution Approach 2:
The patent introduces an intermediary layer (the unified identity model and graph representation system) between the scanning system and diverse cloud environments. This intermediary translates various cloud platform-specific identities and permissions into a standardized graph format, allowing vulnerability scanning without direct integration with each cloud provider's proprietary systems
2Adaptability or versatility
If multiple separate cloud environments are used, then architectural flexibility is improved, but management complexity increases
Solution Approach 1:
The patent merges multiple cloud environment identity systems into a single unified graph representation. By combining principals, resources, and permissions from different cloud platforms into one standardized model, the system maintains architectural flexibility while reducing management complexity through consolidation
Solution Approach 2:
The patent applies homogeneity by standardizing the representation of identities and permissions across heterogeneous cloud environments. All cloud providers' principals and resources are represented using the same graph structure and permission models, creating uniform management interfaces despite underlying architectural differences
3Reliability
If comprehensive vulnerability scanning is implemented across all cloud workloads, then security coverage is improved, but loss of time and computational resources increase
Solution Approach 1:
The patent performs preliminary actions by pre-building and maintaining identity graphs that represent the cloud environment's principals, resources, and permissions. This pre-structuring of security context enables faster vulnerability scanning because the system already has an organized understanding of the attack surface before actual vulnerability detection begins
Solution Approach 2:
The patent replaces mechanical scanning agents with an agentless approach based on graph analysis. Instead of deploying physical or virtual scanning software on each workload, the system uses computational graph theory to model and analyze security relationships, substituting mechanical deployment with mathematical computation for faster, more efficient scanning
Data Source
AI summary
A system and method for generating a security graph utilizing a unified model based on multiple cloud environments are provided. The method includes receiving data from a first cloud environment pertaining to: resources, principals, and permissions; generating for each resource a corresponding resource node in the security graph, the corresponding resource node including an identifier of the resource, wherein the resource is a cloud entity deployed in the first cloud environment; generating for each principal a corresponding principal node in the security graph, the corresponding principal node including an identifier of the principal, wherein the principal is a cloud entity in the first cloud environment that generates an operation request in the first cloud environment; and generating a connection between at least a principal node and at least a resource node in the security graph, in response to detecting a permission indicating that a principal can access a resource.


