Cloned Computing Resource Environments for Intrusion Detection Testing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion detection systems face challenges in effectively detecting complex attacks across distributed computer systems, especially as attackers develop new patterns and zero-day vulnerabilities, making it difficult to measure their effectiveness and improve security measures.

Innovation Solution

A threat analysis service that uses simulated attack payloads to test the detection capabilities of intrusion detection systems by directing them to cloned computing resource environments, allowing for the evaluation of security measures without affecting actual customer systems, and providing insights into the effectiveness of threat analysis and intrusion detection systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If intrusion detection systems are deployed to protect distributed computing systems, then security detection capability is improved, but the ability to measure effectiveness and detect new attack patterns deteriorates

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoideffectiveness measurement difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent creates cloned computing resource environments that replicate production systems. These clones include copied configurations, services, and network arrangements, allowing security testing without affecting actual customer systems. The cloning enables effectiveness measurement by providing a safe testbed for evaluating intrusion detection capabilities against known attack patterns.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs preliminary security testing by directing simulated attack payloads to cloned environments before evaluating detection effectiveness. This preliminary action allows security teams to assess detection capabilities, tune parameters, and validate security measures in advance, improving the reliability of effectiveness measurements without compromising production systems.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If simulated attack payloads are directed to actual customer computing resource environments, then detection effectiveness can be measured, but system security and stability deteriorate

Engineering Contradiction:
Improvedetection effectiveness measurementVSAvoidsystem security risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent introduces cloned computing resource environments as an intermediary between simulated attacks and actual customer systems. These clones act as a buffer, receiving attack payloads and allowing effectiveness measurement while isolating production systems from harmful effects. The intermediary preserves measurement precision by maintaining realistic system configurations without exposing actual customer resources to security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If cloned computing resource environments are created for security testing, then effectiveness measurement capability is improved, but system complexity and resource requirements worsen

Engineering Contradiction:
Improveeffectiveness measurement capabilityVSAvoidtesting infrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates universal cloned environments that can serve multiple testing purposes and evaluate various attack patterns across different service types. These multi-functional clones support diverse security testing scenarios, improving adaptability and versatility while consolidating testing infrastructure. The universal clones can be reused for different measurement objectives, reducing overall system complexity compared to creating specialized test environments for each scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10769045B1Measuring effectiveness of intrusion detection systems using cloned computing resources
Publication Date: 2020.09.08 AMAZON TECH INC
  • US10769045B1 patent drawing
  • US10769045B1 patent drawing
  • US10769045B1 patent drawing

AI summary

A simulated attack service of a computing resource service provider generates a cloned computing resource environment on which a simulated attack is executed. The cloned computing resource environment may be based at least in part on a computing resource environment including a set of computing resources. The simulated attack service may execute the simulated attack by at least directing a simulated attack payload to the cloned computing resource environment based at least in part on a signature included in the simulated attack payload. A measure of the effectiveness of an intrusion detection system may then be generated based at least in part on threat analysis information generated by the intrusion detection system and the simulated attack payloads of the simulated attack.