Correlating Threat Information Across Distributed Computing Sources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large distributed computing systems, it is challenging to identify vulnerabilities, isolate and troubleshoot issues, and secure the system effectively due to complexity and distribution of resources, which complicates the collection and analysis of log information.

Innovation Solution

A security service correlates operational information from various sources, including customer-operated and service provider-operated resources, to generate a unified security model, using methods such as clustering events, statistical analysis, and machine learning to detect and mitigate threats across different levels and locations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual mitigation methods are used to secure the system, then security measures can be implemented, but the complexity and distribution of computing resources make it difficult to collect and analyze log information effectively

Engineering Contradiction:
Improvesystem securityVSAvoidlog collection and analysis complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines log collection, analysis, and threat detection functions into a unified automated security service that operates across the distributed computing system. This service aggregates log information from multiple sources and performs centralized analysis, transforming the complex distributed security management into a coordinated system-wide approach.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security service implements continuous monitoring and analysis of log information with automated feedback loops that detect threats, generate alerts, and trigger mitigation actions. This feedback mechanism enables the system to automatically respond to security events based on analyzed log data, reducing the need for manual intervention.

Inventive Principle:
Principle #23Feedback

2Productivity

If the system operates with high complexity and distribution, then computing resources can be efficiently utilized, but it becomes difficult to identify vulnerabilities and isolate issues

Engineering Contradiction:
Improvecomputing resource utilizationVSAvoidvulnerability identification difficulty
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a security service as an intermediary layer between the distributed computing resources and the security analysis function. This intermediary collects and standardizes log information from diverse sources, enabling unified vulnerability detection and issue isolation without disrupting the underlying distributed system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security service segments the vulnerability detection and analysis function into distinct modular components that can independently process different types of log information from various computing resources. This segmentation allows the system to maintain high productivity while systematically identifying vulnerabilities across the distributed environment.

Inventive Principle:
Principle #1Segmentation

3Productivity

If automated threat detection is implemented across distributed sources, then security efficiency is improved, but the system must process and correlate large volumes of operational information from multiple sources

Engineering Contradiction:
Improvethreat detection efficiencyVSAvoidoperational information volume
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The security service extracts only the relevant and critical log information from the large volume of operational data generated by distributed computing resources. By filtering and selecting only the essential security-relevant events for correlation and analysis, the system achieves efficient threat detection without being overwhelmed by the total quantity of operational information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms operational log information into standardized security parameters and metrics that facilitate efficient correlation and analysis. By changing the representation format of log data into unified security events with standardized attributes, the system can process large volumes of information more effectively.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11159554B2Correlating threat information across sources of distributed computing systems
Publication Date: 2021.10.26 AMAZON TECH INC
  • US11159554B2 patent drawing
  • US11159554B2 patent drawing
  • US11159554B2 patent drawing

AI summary

Customers of a computing resource service provider may operate computing resources provided by the computing resource service provider. Operational information from customer operated computing resources may be correlated with operational information from computing resources operated by the computing resource service provider or other entities, and correlated threat information may be generated.