Event-Based Compute Instance Security Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Web services providers face challenges in detecting and addressing security vulnerabilities in real-time due to the limitations of manual or scheduled security assessments, which can leave computing resources vulnerable for substantial periods.

Innovation Solution

Implementing a configurable event-based compute instance security assessment system that allows users to trigger security assessments in response to specific events, reducing the time resources remain vulnerable by enabling immediate detection and remediation of security issues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual or scheduled security assessments are used, then system complexity is reduced, but the window of vulnerability increases and security reliability deteriorates

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs security assessments in advance by pre-configuring event triggers and assessment rules. When security events occur (such as configuration changes or vulnerability detections), the system automatically initiates assessments before vulnerabilities can be exploited, reducing the window of vulnerability while maintaining manageable system complexity through event-driven automation.

Inventive Principle:
Principle #10Preliminary action

2Loss of time

If event-based security assessments are implemented, then the window of vulnerability is reduced, but system complexity and operational complexity increase

Engineering Contradiction:
Improvewindow of vulnerabilityVSAvoidsystem complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system implements continuous feedback loops where security events trigger automated assessments, and assessment results feed back into system configuration. This closed-loop approach minimizes the window of vulnerability by immediately responding to security events while managing complexity through automation and standardized feedback mechanisms.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system enables self-service security assessments by automatically detecting security events, triggering appropriate assessments without manual intervention, and implementing remediation based on assessment results. This reduces the window of vulnerability while keeping operational complexity manageable through automated self-service capabilities.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If continuous security monitoring is performed, then security detection capability is improved, but resource consumption and operational complexity increase

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system performs security assessments periodically based on triggered events rather than continuously. Security events (such as configuration changes, new vulnerabilities, or suspicious activities) trigger discrete assessment cycles, providing high security detection capability when needed while conserving computational resources during normal operation.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11394739B2Configurable event-based compute instance security assessments
Publication Date: 2022.07.19 AMAZON TECH INC
  • US11394739B2 patent drawing
  • US11394739B2 patent drawing
  • US11394739B2 patent drawing

AI summary

Techniques for configurable event-based compute instance security assessments are described. A security assessment service receives one or more configuration messages, sent on behalf of a user, indicating a request to perform a security assessment of one or more computing resources managed by a service provider system responsive to any of one or more events being determined to have occurred. The security assessment is to include attempting to identify security vulnerabilities of the one or more computing resources. The security assessment service determines that an event of the one or more events has occurred subsequent to event data being reported that is indicative of the event, and performs the security assessment of the one or more computing resources responsive to the determining that the event has occurred.