Inter-Cloud Attack Prevention via Coordinated Notification Protocol

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud management services lack a standardized protocol for communicating and coordinating with each other to detect and mitigate distributed denial-of-service (DDoS) and other cyber attacks that cross network boundaries, making it difficult to effectively manage and respond to inter-cloud attacks.

Innovation Solution

A shared intra-cloud communication protocol is introduced that allows cloud management services to monitor traffic, identify potential attacks, and request restrictions on egress traffic from other services using JSON files and REST-based services, enabling coordinated responses to cyber threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud management services use different attack detection and mitigation protocols, then each service can operate independently with its own security policies, but coordination between services during inter-cloud attacks becomes difficult and ineffective

Engineering Contradiction:
Improveattack mitigation effectivenessVSAvoidprotocol compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal notification protocol that enables cloud management services to communicate attack information across different security domains. The protocol defines standardized message formats including attack detection notifications, blocking requests, and confirmation responses that can be exchanged between any cloud management services regardless of their native security protocols, thereby achieving both reliability in attack mitigation and adaptability across diverse systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If cloud management services implement comprehensive attack detection and coordination mechanisms, then inter-cloud attack response capability improves, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improveinter-cloud attack response capabilityVSAvoidcommunication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the attack response process into distinct, manageable protocol messages: attack detection notifications containing attack parameters, blocking requests with specific blocking parameters, and confirmation responses. This segmentation allows each message type to have a focused, simple structure while the overall system achieves comprehensive attack response capability through the coordination of these discrete message exchanges

Inventive Principle:
Principle #1Segmentation

3Reliability

If cloud management services exchange detailed attack information across network boundaries, then coordinated attack mitigation improves, but information security and trust management become more challenging

Engineering Contradiction:
Improvecoordinated attack mitigationVSAvoidinformation security risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the receiving cloud management service sends confirmation responses back to the notifying service, indicating whether blocking actions were successfully implemented. This feedback loop enables coordinated attack mitigation by verifying that mitigation actions are effective while maintaining information security through authenticated, bidirectional communication that establishes trust between services

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11595432B1Inter-cloud attack prevention and notification
Publication Date: 2023.02.28 AMAZON TECH INC
  • US11595432B1 patent drawing
  • US11595432B1 patent drawing
  • US11595432B1 patent drawing

AI summary

Devices, systems, and methods are provided for detecting and preventing inter-cloud attacks. A method may include determining, by a first cloud management service, a cyber attack on a second cloud management service using the first cloud management service, and determining two or more source Internet protocol (IP) addresses associated with the cyber attack. The method may include determining a response to the cyber attack, the response associated with controlling egress traffic from the first cloud management service, the egress traffic associated with the two or more source IP addresses. The method may include sending a notification to the second cloud management service, the notification including an indication of the response.