Multi-Cloud FQDN Traffic Filtering With Centralized Policy Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-based software instances with unrestricted Internet access are vulnerable to attacks due to inadequate filtering mechanisms, particularly in multi-cloud environments, where native IP address-based filtering is easily circumvented and lacks centralized policy control.
Innovation Solution
Implementing a multi-cloud network traffic filtering service with Fully Qualified Domain Name (FQDN) filtering logic across virtual private cloud networks, providing centralized control and visibility through gateways that enforce whitelist, blacklist, or combined filtering policies, and allowing subnet bypasses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If IP address-based filtering is used, then filtering speed is fast, but security reliability is low because it is easily circumvented and lacks centralized policy control
Solution Approach 1:
The patent changes the filtering parameter from IP address to FQDN (Fully Qualified Domain_name). This parameter change maintains the speed advantage of IP-based filtering while achieving more reliable security through domain-level control, centralized policy management, and bypass condition support that IP filtering cannot provide.
2Reliability
If FQDN filtering is deployed, then security reliability is improved, but device complexity increases due to lack of centralized control and difficulty in managing filtering policies
Solution Approach 1:
The patent introduces a centralized controller as an intermediary between the FQDN filtering service and multiple cloud environments. This controller manages filtering policies centrally, providing visibility and control across all cloud providers while simplifying the complexity of deploying and maintaining FQDN filtering in multi-cloud environments.
Solution Approach 2:
The patent creates a universal FQDN filtering service that operates across multiple cloud environments (AWS, Azure, Google Cloud, Oracle Cloud) through a standardized approach. The service provides consistent filtering functionality across different cloud providers, eliminating the need for separate filtering implementations in each cloud environment.
3Object-affected harmful factors
If whitelist filtering is implemented, then attack mitigation is improved, but ease of operation decreases due to frequent failures and circumvention without centralized control
Solution Approach 1:
The patent implements feedback mechanisms through centralized policy management and monitoring. The system provides visibility into filtering effectiveness, allows for policy adjustments based on observed behavior, and enables bypass condition configurations that respond to specific scenarios, making the filtering system more operationally manageable while maintaining strong attack mitigation.
Data Source
AI summary
In one embodiment, a computing platform featuring a controller and a first virtual private cloud network, which is communicatively coupled to the controller. The first virtual private cloud network includes at least a first gateway including egress filtering logic. The egress filtering logic is configured to (i) filter messages routed from the first gateway in accordance with a first set of filtering rules maintained by the first gateway and (ii) bypass the filtering of messages directed to or originating from one or more subnetworks in accordance with the first set of filtering rules.


