Confidential Malicious Behavior Analysis for Virtual Resources
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Identifying and mitigating malicious software in virtual computing resources within provider networks is challenging due to the need for intrusive and costly detection methods, which can violate confidentiality guarantees and exceed the capacity of control systems, especially in large multi-tenant networks.
Innovation Solution
Implementing a confidential malicious behavior analysis system that uses raw metering data analysis to identify suspect instances, followed by high-cost analysis only on selected instances, without violating security and privacy, and utilizing machine learning to improve detection efficiency and scalability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If intrusive and costly detection methods are used to identify malicious software, then detection precision is improved, but device complexity and loss of information increase due to confidentiality violations
Solution Approach 1:
The patent segments the detection process into two distinct phases: (1) an initial screening phase using lightweight analysis of network traffic metering data to identify suspect virtual compute instances, and (2) a secondary deep analysis phase using confidential data analysis only on the suspect instances identified in phase 1. This segmentation allows the system to maintain detection precision while minimizing confidentiality violations by limiting deep analysis to a small subset of suspect instances rather than applying it universally.
Solution Approach 2:
The patent introduces confidential data analysis service as an intermediary component that receives requests from the network traffic monitoring service. This intermediary handles the confidential data analysis in a controlled manner, ensuring that confidential data is accessed only when necessary and under proper authorization, thereby maintaining confidentiality guarantees while enabling detection when needed.
2Measurement precision
If high-cost analysis is performed on all virtual compute instances, then detection precision is improved, but productivity and loss of time decrease due to excessive resource consumption
Solution Approach 1:
The patent applies partial action by performing comprehensive confidential data analysis only on a partial set of virtual compute instances that are identified as suspects through initial lightweight screening. Instead of applying high-cost analysis to all instances, the system performs it only where necessary, thereby maintaining detection precision for the suspect instances while preserving overall system productivity by avoiding unnecessary resource consumption on non-suspect instances.
Solution Approach 2:
The patent implements preliminary action through the initial screening phase that analyzes network traffic metering data before committing to resource-intensive confidential data analysis. This preliminary step identifies suspect instances in advance, allowing the system to prepare and focus resources only where needed, thereby improving overall detection efficiency and preventing waste of computational resources.
3Reliability
If comprehensive monitoring of all virtual computing resources is implemented, then reliability is improved, but device complexity and loss of time increase
Solution Approach 1:
The patent segments the monitoring system into multiple specialized components with distinct responsibilities: network traffic monitoring service for initial screening, confidential data analysis service for deep analysis, and malicious behavior mitigation service for response actions. This segmentation reduces control system complexity by distributing functions across specialized services rather than requiring a single monolithic system, while maintaining comprehensive monitoring coverage for reliability.
Data Source
AI summary
A multi-tenant provider network may implement confidential data capture and analysis for virtual computing resources. Network traffic for virtual compute instances may be evaluated to identify possible malicious behavior of the virtual compute instances. In some embodiments, a stream of raw metering data for individual network communications to the virtual compute instances may be evaluated. A confidential analysis may be performed for identified virtual compute instances, evaluating confidential data utilized by the virtual compute instances for malicious software. Results of the confidential analysis may be generated according to an access policy that restricts access to the confidential data. The results may be provided to a client that is restricted from accessing the confidential data according to the access policy.


