Monitoring Cloud Files for Changes Without Installing Software
This patent describes a method for checking if files stored in a cloud environment have been changed, by looking at logs from the cloud service instead of installing special software on the cloud servers.
Patent Number
US 12739266
Status
Active
Filing Date
July 28, 2023
Grant Date
September 15, 2026
Expiration
~July 2043 (estimated)
Claims
0
Assignee
—
Inventors
—
Citations
0 forward · 0 backward
What it covers
The patent outlines a system that performs security monitoring in cloud computing environments, especially those without installed monitoring software, known as agentless environments. It works by first identifying a specific file in the cloud that needs monitoring. This file is managed by a cloud-based filesystem service. The system then accesses log data generated by that cloud-based filesystem service, which records any changes to the designated file. Based on this log data, the system performs a file integrity monitoring operation to detect unauthorized modifications. The results of this monitoring are then used to enhance the overall security monitoring of the cloud environment.
What it doesn't cover
- —Does not cover monitoring files stored on traditional, on-premise servers that are not part of a cloud-based filesystem service.
- —Does not cover file integrity monitoring systems that require installing a software agent directly onto the compute environment being monitored.
- —Does not cover monitoring changes to data that is not managed by a cloud-based filesystem service, such as data directly within a cloud database service.
- —Does not cover file integrity monitoring methods that do not rely on accessing log data produced by the cloud-based filesystem service.
- —Does not cover detecting file changes if the cloud-based filesystem service itself does not produce relevant log data.
The clever bit
The novelty lies in achieving file integrity monitoring without deploying any additional software agents on the cloud compute environment. Instead, it cleverly reuses the existing log data already produced by the cloud's own filesystem service, turning passive system records into an active security monitoring tool.
Why it matters
File integrity monitoring is crucial for detecting unauthorized changes to important files, which can indicate a security breach or compliance violation. This patent offers a way to do this in cloud environments without the overhead of installing and managing agents, simplifying security operations and improving coverage for cloud-native applications. It helps organizations meet regulatory compliance requirements by providing an audit trail of file modifications in the cloud.
Real-world examples
- 1.Cloud security posture management (CSPM) platforms
- 2.Cloud workload protection platforms (CWPP)
- 3.Compliance monitoring tools for AWS S3 or Azure Blob Storage
- 4.Security information and event management (SIEM) systems integrating cloud logs
Generated by PatentBrief · Not legal advice · patentbrief.org
US 12739266 · 2026