Data Centric Cloud Security Portal for Inline Service Offload

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing techniques for detecting and mitigating malware are hindered by sophisticated obfuscation methods, leading to inefficiencies in identifying and preventing malware damage, particularly in cloud-based security service providers.

Innovation Solution

A data-centric approach is implemented, where a security platform uses a single upload connection to a cloud service portal, which then distributes the data to multiple cloud detection services via distinct GRPC connections, optimizing data processing and reducing complexity and costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple separate upload connections are maintained for different cloud detection services, then each service can be accessed independently, but the complexity of connection management increases and computational costs rise

Engineering Contradiction:
ImproveAbility to access multiple cloud detection servicesVSAvoidComplexity of maintaining multiple upload connections
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines multiple upload connections into a single shared upload connection that serves multiple cloud detection services. The security platform establishes one upload connection to the cloud service portal, which then distributes data to multiple detection services (malware, phishing, spam detection) through this single connection, eliminating the need to manage multiple separate connections.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The cloud service portal acts as an intermediary between the security platform and multiple cloud detection services. The portal receives data through a single upload connection from the security platform and then distributes it to various detection services, mediating the communication and simplifying connection management for the security platform.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data is sent to multiple cloud detection services through separate connections, then comprehensive security analysis is achieved, but bandwidth consumption and computational costs increase

Engineering Contradiction:
ImproveComprehensive security analysis capabilityVSAvoidComputational and bandwidth costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent merges multiple data transmission operations into a single upload connection. Instead of establishing separate connections for malware detection, phishing detection, and spam detection services, the system uses one shared upload connection that carries data to the cloud service portal, which then distributes it to all necessary detection services, reducing redundant bandwidth consumption.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The single upload connection is designed to serve multiple functions and multiple cloud detection services simultaneously. The cloud service portal receives data through this universal connection and routes it to various detection services (malware, phishing, spam), making the connection multi-functional and reducing overall resource consumption.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Device complexity

If a single shared upload connection is used for multiple cloud detection services, then complexity and costs are reduced, but data distribution to multiple services must be efficiently managed

Engineering Contradiction:
ImproveSimplification of connection managementVSAvoidEfficiency of data distribution to multiple services
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The cloud service portal serves as an intermediary that handles the complexity of data distribution. It receives data through the single upload connection from the security platform and automatically distributes it to multiple cloud detection services, managing the complexity internally while presenting a simplified interface to the security platform.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cloud service portal autonomously manages data distribution to multiple detection services without requiring explicit instructions from the security platform. The portal self-services by receiving data through the shared connection and automatically routing it to the appropriate detection services based on its internal logic and service requirements.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250141886A1Data centric approach for supporting multiple inline cloud services
Publication Date: 2025.05.01 PALO ALTO NETWORKS INC
  • US20250141886A1 patent drawing
  • US20250141886A1 patent drawing
  • US20250141886A1 patent drawing

AI summary

Techniques for a data centric approach for supporting multiple inline cloud services are disclosed. In some embodiments, a system, a process, and/or a computer program product for a data centric approach for supporting multiple inline cloud services includes processing a set of data for network security analysis; determining whether to offload the set of data to a cloud security entity for security processing; and in response to determining to offload the set of data to the cloud security entity, sending the set of data from the inline security entity to a cloud service portal, wherein: the cloud service portal receives a data upload from the inline security entity and processes the data upload to determine content to send to one or more of a plurality of cloud security services for offload processing based on a data type associated with the content; and the cloud service portal receives a result from the one or more of the plurality of cloud security services and forwards the result to the inline security entity, wherein the inline security entity performs an action based on a security policy associated with the inline security entity.