Cloud Workload Protection Platform for DNS Reputation Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Protecting corporate cloud-based services and infrastructure from cyber threats is challenging due to dynamic network environments and expanded security perimeters, which introduce vulnerabilities from remote workers, cloud devices, and untrusted traffic sources.

Innovation Solution

Implementing a system that determines the approval status of data streams and transmits fetch requests to a renderer for network resources requested by protected clients, using a reputation-based global threat engine for real-time access controls, monitoring, and auditing, while preventing lateral attacks and unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network security perimeters are expanded to include remote workers, mobile devices, and cloud devices, then accessibility and flexibility are improved, but vulnerabilities and security risks increase

Engineering Contradiction:
ImproveaccessibilityVSAvoidvulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

A cloud-based security platform acts as an intermediary between protected clients and network resources. The platform intercepts DNS requests, performs reputation-based filtering, and controls access to network resources, thereby mediating security risks while maintaining expanded network accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security checks by evaluating the reputation of DNS requests before allowing access to network resources. By pre-assessing the trustworthiness of requested domains and IPs, the system prevents malicious traffic from reaching protected devices, addressing security vulnerabilities before they can cause harm.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If traditional network-based security approaches are used, then infrastructure control is maintained, but visibility and protection of remote traffic are lost

Engineering Contradiction:
Improveinfrastructure controlVSAvoidvisibility
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The security system transitions from traditional network-perimeter-based protection to a cloud-based, application-layer security model. By moving security controls to the cloud and implementing DNS-level filtering, the system extends visibility and control to remote traffic without requiring changes to local network infrastructure.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The cloud-based security platform provides universal protection across multiple devices, locations, and network environments through a single centralized system. It handles DNS requests from any protected client anywhere in the world, providing consistent security policies and visibility across the entire expanded network perimeter.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If zero-trust principles are implemented across all traffic, then security is improved, but system complexity and processing overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies differentiated security evaluation to different DNS requests based on their reputation scores and contextual factors. Rather than uniformly treating all traffic with the same level of scrutiny, it dynamically adjusts security measures based on the specific risk profile of each requested resource, optimizing both security and performance.

Inventive Principle:
Principle #3Local quality

4Measurement precision

If comprehensive threat intelligence is collected and analyzed, then detection accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system pre-evaluates and caches reputation information for DNS requests, performing security assessments before traffic needs to be routed. By maintaining updated reputation databases and pre-assessing domain trustworthiness, the system enables rapid real-time decisions without extensive processing delays during actual traffic flow.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240106862A1Virtual cloud workload protection platform and related application programming interfaces
Publication Date: 2024.03.28 INTRUSION
  • US20240106862A1 patent drawing
  • US20240106862A1 patent drawing
  • US20240106862A1 patent drawing

AI summary

Systems, methods, apparatuses, and computer program products for providing a virtual cloud workload protection platform. One method may include determining, by a device, whether a data stream is approved or unapproved; and transmitting, by the device, a fetch request to a renderer requesting a network resource requested by a protected client. Another method may include receiving, by a rendering device, a fetch request from a device requesting at least one network resource requested by a protected client; requesting, by the rendering device, the requested at least one requested resource; and rendering, by the rendering device, the at least one requested resource.