Privacy-Preserving Compromise Detection in Cloud Data Centers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data center virtual machines (VMs) are unprotected and existing monitoring agents pose privacy concerns and degrade system performance, making it challenging to detect compromised VMs effectively without violating user data privacy.

Innovation Solution

A compromise detection system that uses periodic flow pattern summaries to detect compromised VMs by analyzing network traffic characteristics without requiring access to private data, employing agent-based detection and machine learning models to identify suspicious behavior, and applying the learned model to all VMs in the data center, ensuring continuous protection and compliance with GDPR regulations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If monitoring agents are deployed to detect compromised VMs, then detection capability is improved, but privacy is violated and system performance degrades

Engineering Contradiction:
Improvecompromise detection capabilityVSAvoidprivacy violation
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the necessary network flow metadata from the network traffic, removing all sensitive private data while retaining the essential characteristics needed for compromise detection. This allows the system to detect compromised VMs without accessing or storing user data, thus resolving the privacy violation issue.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary processing layer that collects network flow data, extracts relevant metadata, and removes sensitive information before analysis. This intermediary mechanism enables compromise detection while acting as a barrier that protects user privacy, preventing direct access to private data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If monitoring agents are deployed to detect compromised VMs, then detection capability is improved, but system performance degrades

Engineering Contradiction:
Improvecompromise detection capabilityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts only essential metadata from network flows, excluding unnecessary data that would consume processing resources. This selective extraction reduces the computational overhead on VMs while maintaining effective compromise detection capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies monitoring only to the extent necessary for compromise detection by analyzing specific network flow characteristics rather than capturing and processing all network traffic. This partial monitoring approach achieves detection goals while minimizing performance impact.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If comprehensive data collection is performed to improve detection accuracy, then detection precision is improved, but privacy is violated and costs increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidprivacy protection
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent extracts and retains only the specific metadata fields necessary for accurate compromise detection (such as flow duration, packet counts, byte counts) while removing all personally identifiable information and sensitive data, achieving both detection accuracy and privacy protection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different quality levels to different data elements by preserving detailed information only where necessary for detection (network flow statistics) while completely anonymizing or removing other data, creating a differentiated data structure that optimizes both accuracy and privacy.

Inventive Principle:
Principle #3Local quality

4Reliability

If traditional monitoring agents are used, then compromise detection is achieved, but expensive data collection and intrusive techniques are required

Engineering Contradiction:
Improvecompromise detectionVSAvoiddata collection infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts only the essential network flow metadata needed for compromise detection, eliminating the need for expensive comprehensive data collection infrastructure. This streamlined approach uses readily available network flow information from standard networking equipment.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses inexpensive network flow metadata that is naturally generated by networking infrastructure rather than requiring expensive specialized monitoring equipment or data collection systems, making compromise detection economically viable.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS11233804B2Methods and systems for scalable privacy-preserving compromise detection in the cloud
Publication Date: 2022.01.25 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11233804B2 patent drawing
  • US11233804B2 patent drawing
  • US11233804B2 patent drawing

AI summary

A compromise detection system protects data centers (DCs) or other providers in the cloud. The compromise detection system can detect compromised virtual machines (VMs) through changes in network traffic characteristics while avoiding expensive data collection and preserving privacy. The compromise detection system obtains and uses periodically-obtained flow pattern summaries to detect compromised VMs. Agent-based detection on predetermined and compromised VMs can expose (using supervised learning) the network behavior of compromised VMs and then apply the learned model to all VMs in the DC. The compromise detection system can run continuously, protect the privacy of cloud customers, comply with Europe's General Data Protection Regulation (GDPR), and avoid various techniques that both erode privacy and degrade VM performance.