Agent Verification for Trusted Threat Detection Telemetry
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-based threat detection services face challenges in collecting active telemetry data from customer-controlled environments due to the susceptibility of agents to manipulation and the need for cumbersome customer configuration changes, especially in short-lived container executions.
Innovation Solution
An agent verification system verifies agents using instance IDs, tokens, and connection IDs to authenticate and enable telemetry data transmission to cloud-based threat detection services, allowing automatic enrollment for multiple accounts within a shared isolated virtual network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If agents are installed in customer-controlled environments for active telemetry data collection, then telemetry data can be collected, but the agents may be altered or manipulated beyond the control of the threat detection service
Solution Approach 1:
The patent applies preliminary action by pre-provisioning unique identifiers (instance IDs, connection IDs) and cryptographic key pairs in the customer environment before agent deployment. The threat detection service pre-generates instance IDs and connection IDs, and cryptographic keys are embedded in the agent binary before installation. This preliminary setup ensures that when the agent is deployed, it carries inherent authentication credentials that enable verification without requiring post-deployment configuration changes, thus maintaining agent authenticity while enabling telemetry collection.
Solution Approach 2:
The patent implements feedback through a verification mechanism where the threat detection service receives telemetry data from agents and validates it using the pre-provisioned instance IDs, connection IDs, and cryptographic keys. The service verifies the agent's authenticity by checking digital signatures and matching identifiers, providing feedback on whether the agent is legitimate. This feedback loop ensures that only authenticated agents can successfully transmit telemetry data, maintaining reliability while enabling productive data collection.
2Productivity
If agents require customer configuration changes for telemetry data collection, then telemetry data can be collected, but the configuration process becomes cumbersome
Solution Approach 1:
The patent eliminates cumbersome customer configuration by performing all necessary setup actions preliminarily. Instance IDs, connection IDs, and cryptographic key pairs are generated and provisioned in advance by the threat detection service. The agent binary is pre-configured with these identifiers and keys during the build process. When the agent is deployed to the customer environment, it automatically uses these pre-provisioned credentials to establish communication, requiring no customer configuration actions. This preliminary preparation resolves the contradiction by enabling productive telemetry collection without operational burden.
Solution Approach 2:
The patent enables self-service by designing the agent to autonomously use the pre-provisioned instance IDs, connection IDs, and cryptographic keys without requiring customer configuration. The agent automatically establishes secure communication channels with the threat detection service using its embedded credentials. This self-service capability allows the agent to perform telemetry data collection independently, eliminating the need for customer configuration actions while maintaining productive data collection.
3Reliability
If manual verification processes are used for agent authentication, then agent security can be ensured, but the enrollment process becomes time-consuming
Solution Approach 1:
The patent resolves the time-loss contradiction by performing authentication setup preliminarily. Instance IDs, connection IDs, and cryptographic key pairs are generated and distributed before agent deployment. The verification rules and authentication mechanisms are pre-configured in the threat detection service. When the agent is deployed, authentication occurs automatically through cryptographic verification of pre-provisioned credentials, eliminating time-consuming manual verification steps while ensuring reliable agent authentication.
Solution Approach 2:
The patent replaces manual mechanical verification processes with automated cryptographic verification. Instead of human operators manually checking agent credentials, the system uses cryptographic key pairs, digital signatures, and automated validation of instance IDs and connection IDs. This substitution of mechanical verification with automated cryptographic mechanisms ensures reliable agent authentication while dramatically reducing the time required for enrollment, as the verification occurs automatically through mathematical proofs rather than manual inspection.
Data Source
AI summary
Systems and methods for performing agent verification for a threat detection service are disclosed. A request to send telemetry data from an agent on an instance with a customer-controlled container is by an agent verification system. The request may include an instance ID, token, and/or a connection ID. A confirmation is performed that the instance ID of the request matches an instance ID of an instance known to support the customer-controlled container. Also, the token included in the request may be authenticated to verify that the agent is an authentic agent. The connection ID from the request may also be confirmed to match a connection ID for a connection provided to the instance of the instance ID. The request may be accepted, and the threat detection service may be enabled to receive the telemetry data.


