Host-Based Firewall Adaptive Rule Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large distributed computing systems, it is challenging to identify vulnerabilities, isolate and troubleshoot issues, and secure the system effectively due to complexity and distribution, with conventional methods relying on manual mitigation and struggling to collect and analyze log information.

Innovation Solution

A host-based firewall that obtains process-level information, detects network connections, and allows or denies traffic based on customer decisions, using machine learning and adaptive rules generated from network traffic data, while aggregating information across multiple computing resources and providing visualization tools for remote diagnostic and troubleshooting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual mitigation methods are used to secure the system, then system security can be maintained with simple tools, but the complexity and distribution of computing resources make it difficult to effectively identify vulnerabilities, isolate issues, and secure the system

Engineering Contradiction:
Improvesystem securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security service as an intermediary component that mediates between the host-based firewall and the distributed computing resources. This security service aggregates information from multiple sources, correlates threat data across different levels of the distributed system, and provides centralized security management, thereby simplifying vulnerability identification and issue isolation in complex distributed environments

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments security management into multiple hierarchical levels: host-based firewalls at individual computing resources, security services at the data center level, and cloud-level security services. This segmentation allows security functions to be distributed appropriately while maintaining centralized coordination, making it easier to identify and isolate security issues in specific segments without affecting the entire system

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If conventional firewall systems are used, then basic network traffic filtering is provided, but they rely on manual mitigation and struggle to collect and analyze log information from distributed computing resources

Engineering Contradiction:
Improveautomated security managementVSAvoidlog information analysis capability
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent implements feedback mechanisms where the security service continuously collects log information from host-based firewalls and computing resources, analyzes threat patterns, and automatically updates security rules and policies. This closed-loop feedback system enables automated security management by using collected information to improve future security decisions without requiring manual intervention for each threat

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The security service is designed as a universal platform that performs multiple functions: collecting logs from diverse sources, analyzing threat information, generating security rules, and coordinating with host-based firewalls. This multi-functional approach eliminates the need for separate manual processes for log collection, analysis, and response, thereby improving ease of operation while preserving log information

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If host-based firewalls with automated rule generation are deployed, then adaptive security responses are achieved, but the system requires collection and processing of extensive network traffic data across distributed resources

Engineering Contradiction:
Improveadaptive security responseVSAvoiddata collection and processing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent adds a new dimension to security data processing by introducing a hierarchical architecture where host-based firewalls process local network traffic data and upload aggregated information to cloud-level security services. This dimensional change from flat to hierarchical processing reduces the complexity at each level by distributing data collection and processing tasks across multiple layers of the system

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10142290B1Host-based firewall for distributed computer systems
Publication Date: 2018.11.27 AMAZON TECH INC
  • US10142290B1 patent drawing
  • US10142290B1 patent drawing
  • US10142290B1 patent drawing

AI summary

Customers of a computing resource service provider may utilize computing resources of the computing resources service provided to implement one or more computer systems. Furthermore, the customer may cause a host-based firewall to be executed by the one or more computer systems. The host-based firewall may collect network traffic information. The customer may then be provided with the network traffic information and be prompted to provide decisions associated with the network traffic information. The decisions may be used to generate a set of rules which may be enforced by the host-based firewall.