Hybrid Cloud Security Architecture for Traffic Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As cloud service providers scale up their operations, traditional centralized network security approaches become difficult to manage and scale, leading to performance slowdowns and challenges in detecting offending traffic effectively.

Innovation Solution

A hybrid architecture is introduced, combining centralized security monitoring with distributed security enforcement, utilizing hardware-based security components for scalable and high-throughput inspection, and localized security enforcement modules to enforce security policies and detect malicious traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a fully centralized monitoring and control mechanism is used to inspect all network traffic, then security coverage is improved, but system performance and scalability deteriorate

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent divides the centralized security system into distributed security modules deployed across multiple cloud service accounts. Each module independently inspects traffic within its designated account, eliminating the single-point bottleneck of fully centralized inspection while maintaining comprehensive security coverage across all accounts.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a single-dimensional centralized inspection model to a multi-dimensional distributed architecture where security modules operate at different levels (individual service account level and collective level). This dimensional expansion allows parallel processing of traffic across multiple accounts simultaneously, improving overall system performance.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If a fully centralized monitoring and control mechanism is used to inspect all network traffic, then security coverage is improved, but scalability deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the security monitoring function into independent modules that can be individually deployed to each cloud service account. This segmentation enables the system to scale horizontally by simply adding new security modules as new accounts are created, without requiring changes to a centralizing infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each distributed security module autonomously inspects and controls traffic for its assigned service account without requiring centralized coordination for every decision. This self-service capability allows the system to automatically adapt to new accounts and traffic patterns, enhancing scalability.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If traditional centralized security approach is used, then security policy enforcement is simplified, but latency increases

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidinspection latency
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent divides traffic inspection into localized segments handled by distributed security modules positioned close to the traffic sources. This segmentation reduces the physical and logical distance traffic must traverse, minimizing inspection latency while maintaining centralized policy coordination.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces distributed security modules as intermediaries between the centralized policy authority and the actual traffic flow. These intermediaries cache and enforce policies locally, reducing the need for constant centralized communication and thereby reducing latency while maintaining policy consistency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240372880A1Monitoring and control of network traffic in a cloud server environment
Publication Date: 2024.11.07 SALESFORCE INC
  • US20240372880A1 patent drawing
  • US20240372880A1 patent drawing
  • US20240372880A1 patent drawing

AI summary

A computer-implemented method for monitoring and control of a network traffic in a cloud server environment is disclosed. The method includes receiving network traffic at a cloud service account that includes a corresponding local security enforcement module configured to enforce security policies for data processed by the cloud service account and forwarding a part of the network traffic from the cloud service account to a centralized security monitoring hub that includes a hardware-based security component. The method also includes detecting, by the hardware-based security component, offending traffic that includes traffic from an unwanted source or with malicious content. The method further includes sending a notification of the offending traffic to the localized security enforcement module, by the centralized security monitoring hub, and responsive to the notification, implementing a security enforcement strategy in the cloud service account based on the security policy, by the corresponding localized security enforcement module.