Hardware Performance Counter Anomaly Detection in Cloud

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-tenant computing environments like cloud computing, existing security measures struggle to detect and address anomalous behavior without impacting performance or invading customer privacy, as they often require access to customer data and resources, which can be costly and resource-intensive.

Innovation Solution

The use of hardware performance counters and sensors to detect anomalous behavior by tracking events such as cache misses and thermal data, with a privileged instance analyzing these values to identify patterns indicative of malicious or performance-degrading activities, allowing for proactive remediation without accessing customer data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security measures are used to detect anomalous behavior, then security detection capability is improved, but computing resource overhead and cost increase significantly

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidcomputing resource overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces hardware performance counters as an intermediary mechanism that indirectly monitors system behavior without requiring direct access to customer data or substantial computing resources. These counters serve as mediators between the security monitoring system and the underlying hardware, providing actionable security insights while minimizing resource overhead and preserving customer privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces complex software-based security monitoring mechanisms with simpler hardware-based performance counters. By substituting the mechanical/software monitoring system with hardware-level counters that automatically track system events, the solution reduces computing resource overhead while maintaining effective security detection capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If customer data is accessed for security monitoring, then detection accuracy is improved, but customer privacy is violated

Engineering Contradiction:
Improvedetection accuracyVSAvoidcustomer privacy
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent extracts only the essential security-relevant information from the system through hardware performance counters, separating what is needed for security monitoring from customer proprietary information. By taking out only the necessary metrics (counter values) while leaving customer data intact and private, the system achieves detection accuracy without violating customer privacy rights.

Inventive Principle:
Principle #2Taking out (Extraction)

3Device complexity

If hardware performance counters are used for monitoring, then resource overhead is reduced, but detection capability may be limited

Engineering Contradiction:
Improveresource overheadVSAvoiddetection capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent changes the monitoring parameters from high-level software metrics to low-level hardware counter values. By monitoring fundamental hardware events such as cache misses, branch mispredictions, and memory access patterns at the hardware level, the system achieves effective security detection with minimal resource overhead, as these parameters provide deep insights into system behavior without requiring substantial processing power.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10705904B2Detecting anomalous behavior in an electronic environment using hardware-based information
Publication Date: 2020.07.07 AMAZON TECH INC
  • US10705904B2 patent drawing
  • US10705904B2 patent drawing
  • US10705904B2 patent drawing

AI summary

Anomalous behavior in a multi-tenant computing environment may be identified by analyzing hardware sensor value data associated with hardware events on a host machine. A privileged virtual machine instance executing on a host machine acquires hardware sensor values and causes the values to be compared to other hardware sensor value data that may be indicative of anomalous behavior; for example, various threshold values, patterns, and/or signatures of hardware counter values generated by analyzing and correlating hardware event counter data. In this manner, potential anomalous behavior on an instance may be determined without having to access customer data or workloads associated with the instance.