Containerized Security Server for Network Traffic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data security solutions face challenges in effectively managing information security in complex, multi-subsystem networks, especially in untrusted or remote environments, due to the rapid evolution of computing environments and limited visibility into network traffic.

Innovation Solution

A secure information security architecture is deployed using a data security server that can be instantiated in any network, either on standalone hardware or within existing hardware through virtualization, equipped with software container engines like Docker, allowing for isolated execution of security applications and efficient updating, with a control agent for remote management and monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data security solutions are rapidly changing to adapt to different computing environments, then adaptability is improved, but device complexity increases and makes it difficult to build solutions that can effectively manage security

Engineering Contradiction:
Improveadaptability to computing environmentsVSAvoidsolution complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the data security solution into separate software containers, each handling specific security functions (network traffic analysis, threat detection, security policy enforcement). This modular architecture allows independent deployment and management of security components, reducing overall system complexity while maintaining adaptability to different computing environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal data security server that can function across multiple computing environments (cloud, on-premises, hybrid) and support various security applications. The server uses standardized interfaces and can dynamically load different security modules, providing multi-functional capability without increasing complexity for each specific environment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of manufacture

If security applications are deployed in virtualized environments with container engines, then ease of deployment and updating is improved, but reliability may be compromised due to shared host resources

Engineering Contradiction:
Improvedeployment easeVSAvoidsecurity execution reliability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent implements strong isolation boundaries between software containers using Linux kernel features (cgroups, namespaces). Each container has dedicated resource allocations and isolated execution environments, ensuring that security-critical applications maintain reliability even when running on shared host infrastructure. The host operating system is configured with specific security properties that guarantee container isolation.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If remote networks and untrusted environments are accessed to provide security services, then adaptability is improved, but visibility into network traffic decreases making security management difficult

Engineering Contradiction:
Improvenetwork environment accessibilityVSAvoidnetwork traffic visibility
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent positions the data security server as an intermediary component that receives and analyzes network traffic copies through dedicated interfaces. The server can access network traffic data from remote and untrusted environments while maintaining secure isolation from those environments. This intermediary position enables comprehensive traffic visibility and security analysis without direct exposure to untrusted networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11416587B1Security deployment and management mechanism for software container
Publication Date: 2022.08.16 AMAZON TECH INC
  • US11416587B1 patent drawing
  • US11416587B1 patent drawing
  • US11416587B1 patent drawing

AI summary

A data security server or system may be installed or placed into network to perform data security and network monitoring and analysis functions. The data security server may operate an isolated computing instance or engine, such as a software container engine. A computing resource service provider may send commands to the data security server to provision a variety of data security and monitoring applications in isolated software containers of the data security server. The data security server, via the data security and monitoring applications, may obtain copies of traffic going into and out of the network, and analyze the traffic to produce security data. The security data may be uploaded to the service provider for storage and retrieval.