Block-Level Forensics Service for Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large distributed computing systems, identifying vulnerabilities, isolating issues, and securing the system is challenging due to complexity and distribution, making it difficult to collect and analyze log information effectively, and conventional systems rely on manual mitigation methods.

Innovation Solution

A block-level forensics service analyzes log events from log-structured storage volumes to detect anomalies, correlate data across multiple systems, and provide real-time monitoring and alerts for malicious activity, using stream processing and forensic analysis techniques to identify compromised resources and isolate threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual mitigation methods are used in distributed computing systems, then system security can be maintained with existing resources, but the complexity and distribution of computing resources make it difficult to collect and analyze log information effectively

Engineering Contradiction:
Improvesystem securityVSAvoidlog analysis complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a log analysis service as an intermediary component that automatically collects, aggregates, and analyzes log information from distributed computing resources. This service acts as a mediator between the complex distributed system and security personnel, transforming raw log data into actionable security insights without requiring manual analysis of each log source.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements automated log collection and analysis capabilities that operate independently without requiring manual intervention. The log analysis service automatically subscribes to log streams from multiple computing resources, processes the data in real-time, and generates security alerts, enabling the system to self-monitor and self-protect against threats.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If real-time monitoring and analysis of log information is implemented across distributed systems, then security threat detection capability is improved, but the complexity of collecting and analyzing log data increases

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidlog collection and analysis complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The log analysis service is designed as a universal system that can handle multiple types of log data from various computing resources simultaneously. It subscribes to log streams from different sources, processes diverse log formats, and applies unified analysis rules, enabling multi-functional threat detection across the entire distributed system through a single service.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines multiple log streams from distributed computing resources into a single analysis pipeline. The log analysis service aggregates logs from multiple sources, correlates events across different systems, and presents unified security findings, merging complex distributed log data into coherent security intelligence.

Inventive Principle:
Principle #5Merging (Combining)

3Loss of time

If conventional manual mitigation methods are used, then existing system resources can be maintained, but the latency in detecting and responding to security threats increases

Engineering Contradiction:
Improvethreat response latencyVSAvoidautomated detection and mitigation
Core Design Contradiction:
Loss of timeVSExtent of automation

Solution Approach 1:

The system implements real-time feedback loops where the log analysis service continuously monitors log streams, automatically detects security threats as they occur, and immediately generates alerts or triggers mitigation actions. This closed-loop feedback mechanism eliminates the delays associated with manual threat detection and response, enabling near-real-time security incident management.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The log analysis service performs preliminary analysis of log data in real-time, identifying potential security threats before they can cause significant damage. By continuously processing and analyzing logs as they are generated, the system takes preliminary protective actions rather than waiting for manual review, reducing the overall response time to security incidents.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10079842B1Transparent volume based intrusion detection
Publication Date: 2018.09.18 AMAZON TECH INC
  • US10079842B1 patent drawing
  • US10079842B1 patent drawing
  • US10079842B1 patent drawing

AI summary

A computing resource service provider may provide customers with a block-level forensics service. Logical volumes associated a customer may be used to instantiate computing resources provided by a computing resource service provide for use by the customer. The block-level forensics service or component thereof may monitor the logical volume based at least in part on a log generated as a result of the logical volume being implemented as a log-structured storage system. Operations to the log may be collected by the block-level forensics service and malicious activity may be detected based at least in part on operations to the log.