Unmanaged Cloud Resource Detection and Enterprise Attribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large enterprises face challenges in identifying and attributing unmanaged cloud resources due to employees using cloud-hosted resources from multiple sources, complicating the differentiation of enterprise-owned assets and necessitating remediation, especially when monitoring applications lack visibility into all endpoints and network interactions.

Innovation Solution

Utilizing a network visibility module (NVM) and monitoring applications to map ground truth usernames and process information, constructing bipartite knowledge graphs from endpoint and network logs, and applying rules and machine learning algorithms to identify enterprise-owned cloud assets and business entities, with outputs in compact formats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If monitoring applications use official provisioning systems to identify cloud assets, then authorization and audit capabilities are improved, but visibility is lost when employees bypass the provisioning system or remove programmatic access

Engineering Contradiction:
Improveauthorization capabilityVSAvoidcloud asset visibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces network traffic analysis as an intermediary method to detect cloud asset access. Instead of relying solely on provisioning system data, the system monitors network traffic between endpoints and cloud resources, using this intermediate observation to identify unmanaged assets. This mediator approach allows the system to discover cloud assets that employees have accessed outside the official provisioning workflow.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical reliance on provisioning system integrations with a data-driven approach using machine learning models. The system collects network traffic data, endpoint data, and cloud metadata, then uses trained models to automatically identify and attribute cloud assets. This substitution transforms the asset identification process from a system-integration-dependent mechanism to an autonomous analytical system.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If employees access cloud resources from multiple sources for efficiency, then productivity is improved, but differentiation of enterprise-owned assets becomes complicated

Engineering Contradiction:
Improveemployee efficiencyVSAvoidasset differentiation
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent adds multiple dimensions to cloud asset identification by collecting data from diverse sources: network traffic patterns, endpoint characteristics, cloud metadata, and access timing. Instead of relying on a single dimension like provisioning system records, the system analyzes assets across multiple dimensions simultaneously, enabling differentiation even when employees access resources through various channels.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent changes the parameters used to identify cloud assets from static provisioning system attributes to dynamic multi-source characteristics. The system analyzes varying parameters such as network traffic patterns, endpoint IP addresses, access timestamps, and resource metadata to create a comprehensive profile of each cloud asset. These changing parameters enable the system to distinguish enterprise-owned assets regardless of access method.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If monitoring applications integrate additional frameworks to audit cloud configurations, then security posture is improved, but complexity of the provisioning system increases

Engineering Contradiction:
Improvesecurity postureVSAvoidprovisioning system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the cloud asset identification function into separate, independent components: data collection from multiple sources, data processing and feature extraction, machine learning model training, and asset identification/attribution. This segmentation allows each component to be developed and maintained independently, reducing the complexity burden on the core provisioning system while still providing comprehensive security monitoring.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary analysis layer that sits between the provisioning system and the monitoring function. This intermediate layer collects and processes data from multiple sources without requiring deep integration into the provisioning system itself. The intermediary approach maintains security monitoring capabilities while preserving the simplicity of the core provisioning infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250293992A1Identifying unmanaged cloud resources with endpoint and network logs
Publication Date: 2025.09.18 CISCO TECHNOLOGY INC
  • US20250293992A1 patent drawing
  • US20250293992A1 patent drawing
  • US20250293992A1 patent drawing

AI summary

Techniques and mechanisms for identifying unmanaged cloud resources with endpoint and network logs and attributing the identified cloud resources to an entity of an enterprise that owns the cloud resources. The process collects data from sources, e.g., endpoint and network logs, with respect to traffic in a computer network and based at least in part on the data, extracts relationships related to the traffic. The process applies rules to the relationships to extract destinations in the computer network that provide cloud resources in a cloud environment, wherein the cloud resources are owned by an enterprise. One or more users or business entities of the enterprise are identified as accessing the cloud resources.