Correlating Threat Information Across Distributed Computing Sources
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In large distributed computing systems, it is challenging to identify vulnerabilities, isolate and troubleshoot issues, and secure the system effectively due to complexity and distribution of resources, which complicates the collection and analysis of log information.
Innovation Solution
A security service correlates operational information from various sources, including customer-operated and service provider-operated resources, to generate a unified security model, using methods such as clustering events, statistical analysis, and machine learning to detect and mitigate threats across different levels and locations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual mitigation methods are used to secure the system, then security measures can be implemented, but the complexity and distribution of computing resources make it difficult to collect and analyze log information effectively
Solution Approach 1:
The patent combines log collection, analysis, and threat detection functions into a unified automated security service that operates across the distributed computing system. This service aggregates log information from multiple sources and performs centralized analysis, transforming the complex distributed security management into a coordinated system-wide approach.
Solution Approach 2:
The security service implements continuous monitoring and analysis of log information with automated feedback loops that detect threats, generate alerts, and trigger mitigation actions. This feedback mechanism enables the system to automatically respond to security events based on analyzed log data, reducing the need for manual intervention.
2Productivity
If the system operates with high complexity and distribution, then computing resources can be efficiently utilized, but it becomes difficult to identify vulnerabilities and isolate issues
Solution Approach 1:
The patent introduces a security service as an intermediary layer between the distributed computing resources and the security analysis function. This intermediary collects and standardizes log information from diverse sources, enabling unified vulnerability detection and issue isolation without disrupting the underlying distributed system architecture.
Solution Approach 2:
The security service segments the vulnerability detection and analysis function into distinct modular components that can independently process different types of log information from various computing resources. This segmentation allows the system to maintain high productivity while systematically identifying vulnerabilities across the distributed environment.
3Productivity
If automated threat detection is implemented across distributed sources, then security efficiency is improved, but the system must process and correlate large volumes of operational information from multiple sources
Solution Approach 1:
The security service extracts only the relevant and critical log information from the large volume of operational data generated by distributed computing resources. By filtering and selecting only the essential security-relevant events for correlation and analysis, the system achieves efficient threat detection without being overwhelmed by the total quantity of operational information.
Solution Approach 2:
The patent transforms operational log information into standardized security parameters and metrics that facilitate efficient correlation and analysis. By changing the representation format of log data into unified security events with standardized attributes, the system can process large volumes of information more effectively.
Data Source
AI summary
Customers of a computing resource service provider may operate computing resources provided by the computing resource service provider. Operational information from customer operated computing resources may be correlated with operational information from computing resources operated by the computing resource service provider or other entities, and correlated threat information may be generated.


