Confidential Malicious Behavior Analysis for Virtual Resources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Identifying and mitigating malicious software in virtual computing resources within provider networks is challenging due to the need for intrusive and costly detection methods, which can violate confidentiality guarantees and exceed the capacity of control systems, especially in large multi-tenant networks.

Innovation Solution

Implementing a confidential malicious behavior analysis system that uses raw metering data analysis to identify suspect instances, followed by high-cost analysis only on selected instances, without violating security and privacy, and utilizing machine learning to improve detection efficiency and scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If intrusive and costly detection methods are used to identify malicious software, then detection precision is improved, but device complexity and loss of information increase due to confidentiality violations

Engineering Contradiction:
Improvemalicious software detection precisionVSAvoidconfidentiality guarantee
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent segments the detection process into two distinct phases: (1) an initial screening phase using lightweight analysis of network traffic metering data to identify suspect virtual compute instances, and (2) a secondary deep analysis phase using confidential data analysis only on the suspect instances identified in phase 1. This segmentation allows the system to maintain detection precision while minimizing confidentiality violations by limiting deep analysis to a small subset of suspect instances rather than applying it universally.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces confidential data analysis service as an intermediary component that receives requests from the network traffic monitoring service. This intermediary handles the confidential data analysis in a controlled manner, ensuring that confidential data is accessed only when necessary and under proper authorization, thereby maintaining confidentiality guarantees while enabling detection when needed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If high-cost analysis is performed on all virtual compute instances, then detection precision is improved, but productivity and loss of time decrease due to excessive resource consumption

Engineering Contradiction:
Improvemalicious software detection precisionVSAvoiddetection system capacity
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent applies partial action by performing comprehensive confidential data analysis only on a partial set of virtual compute instances that are identified as suspects through initial lightweight screening. Instead of applying high-cost analysis to all instances, the system performs it only where necessary, thereby maintaining detection precision for the suspect instances while preserving overall system productivity by avoiding unnecessary resource consumption on non-suspect instances.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements preliminary action through the initial screening phase that analyzes network traffic metering data before committing to resource-intensive confidential data analysis. This preliminary step identifies suspect instances in advance, allowing the system to prepare and focus resources only where needed, thereby improving overall detection efficiency and preventing waste of computational resources.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive monitoring of all virtual computing resources is implemented, then reliability is improved, but device complexity and loss of time increase

Engineering Contradiction:
Improveprovider network securityVSAvoidcontrol system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the monitoring system into multiple specialized components with distinct responsibilities: network traffic monitoring service for initial screening, confidential data analysis service for deep analysis, and malicious behavior mitigation service for response actions. This segmentation reduces control system complexity by distributing functions across specialized services rather than requiring a single monolithic system, while maintaining comprehensive monitoring coverage for reliability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10341355B1Confidential malicious behavior analysis for virtual computing resources
Publication Date: 2019.07.02 AMAZON TECH INC
  • US10341355B1 patent drawing
  • US10341355B1 patent drawing
  • US10341355B1 patent drawing

AI summary

A multi-tenant provider network may implement confidential data capture and analysis for virtual computing resources. Network traffic for virtual compute instances may be evaluated to identify possible malicious behavior of the virtual compute instances. In some embodiments, a stream of raw metering data for individual network communications to the virtual compute instances may be evaluated. A confidential analysis may be performed for identified virtual compute instances, evaluating confidential data utilized by the virtual compute instances for malicious software. Results of the confidential analysis may be generated according to an access policy that restricts access to the confidential data. The results may be provided to a client that is restricted from accessing the confidential data according to the access policy.