Messaging Service Data Streams for Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed application environments, existing messaging systems lack efficient mechanisms for generating data streams from message requests, analytics, and synchronization across multiple geographic regions, leading to potential unauthorized access and data inconsistencies.

Innovation Solution

A messaging service that generates data streams from message requests, including attribute information, to enable analytics and synchronization across multiple geographic regions, using an agent to detect and process message requests, and a server to generate data streams accessible for intrusion detection and replication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If message requests are monitored and data streams are generated for analytics, then security through intrusion detection is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

An agent is introduced as an intermediary component that intercepts message requests between application components and the message queue. The agent generates data streams from these requests without disrupting the existing messaging flow, enabling intrusion detection analytics while maintaining system encapsulation and minimizing complexity intrusion into core messaging functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The agent creates a copy of message request data to generate analytics data streams, rather than modifying the original message flow. This copying approach allows security monitoring and analytics to be performed on duplicate data, preventing interference with the primary messaging function while still enabling comprehensive security analysis.

Inventive Principle:
Principle #26Copying

2Reliability

If message queues are replicated across multiple geographic regions, then reliability for disaster recovery is improved, but loss of time for data synchronization increases

Engineering Contradiction:
Improvedisaster recoveryVSAvoidsynchronization time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-establishes replicated message queues across multiple geographic regions before disasters occur. The replication infrastructure, including data streams and synchronization mechanisms, is configured in advance so that when a disaster strikes, the failover can occur rapidly without requiring time-consuming setup or configuration of the replicated systems.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Data stream generation and message replication continue uninterrupted across geographic regions, maintaining continuous synchronization of message requests and analytics data. This continuous operation ensures that replicated queues remain current with minimal lag, enabling rapid failover while maintaining data consistency across regions.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10701145B1Data output using message requests to a messaging service
Publication Date: 2020.06.30 AMAZON TECH INC
  • US10701145B1 patent drawing
  • US10701145B1 patent drawing
  • US10701145B1 patent drawing

AI summary

Technology is described for generating data output using message requests to a message queue. A plurality of message requests that are sent to the message queue may be detected. The message queue may be operated by a messaging service executing in a service provider environment. Message attribute information for the plurality of message requests may be identified. The plurality of message requests and corresponding message attribute information may be published as a data output. The data output may be processed by the service provider environment. Access to the data output may be provided for consumption of the message attribute information in the data output.