Multi-Cloud FQDN Traffic Filtering With Centralized Policy Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based software instances with unrestricted Internet access are vulnerable to attacks due to inadequate filtering mechanisms, particularly in multi-cloud environments, where native IP address-based filtering is easily circumvented and lacks centralized policy control.

Innovation Solution

Implementing a multi-cloud network traffic filtering service with Fully Qualified Domain Name (FQDN) filtering logic across virtual private cloud networks, providing centralized control and visibility through gateways that enforce whitelist, blacklist, or combined filtering policies, and allowing subnet bypasses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If IP address-based filtering is used, then filtering speed is fast, but security reliability is low because it is easily circumvented and lacks centralized policy control

Engineering Contradiction:
Improvefiltering speedVSAvoidsecurity reliability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent changes the filtering parameter from IP address to FQDN (Fully Qualified Domain_name). This parameter change maintains the speed advantage of IP-based filtering while achieving more reliable security through domain-level control, centralized policy management, and bypass condition support that IP filtering cannot provide.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If FQDN filtering is deployed, then security reliability is improved, but device complexity increases due to lack of centralized control and difficulty in managing filtering policies

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized controller as an intermediary between the FQDN filtering service and multiple cloud environments. This controller manages filtering policies centrally, providing visibility and control across all cloud providers while simplifying the complexity of deploying and maintaining FQDN filtering in multi-cloud environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal FQDN filtering service that operates across multiple cloud environments (AWS, Azure, Google Cloud, Oracle Cloud) through a standardized approach. The service provides consistent filtering functionality across different cloud providers, eliminating the need for separate filtering implementations in each cloud environment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If whitelist filtering is implemented, then attack mitigation is improved, but ease of operation decreases due to frequent failures and circumvention without centralized control

Engineering Contradiction:
Improveattack mitigationVSAvoidfiltering policy management
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements feedback mechanisms through centralized policy management and monitoring. The system provides visibility into filtering effectiveness, allows for policy adjustments based on observed behavior, and enables bypass condition configurations that respond to specific scenarios, making the filtering system more operationally manageable while maintaining strong attack mitigation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12556601B1Multi-cloud network traffic filtering service
Publication Date: 2026.02.17 AVIATRIX SYSTEMS INC
  • US12556601B1 patent drawing
  • US12556601B1 patent drawing
  • US12556601B1 patent drawing

AI summary

In one embodiment, a computing platform featuring a controller and a first virtual private cloud network, which is communicatively coupled to the controller. The first virtual private cloud network includes at least a first gateway including egress filtering logic. The egress filtering logic is configured to (i) filter messages routed from the first gateway in accordance with a first set of filtering rules maintained by the first gateway and (ii) bypass the filtering of messages directed to or originating from one or more subnetworks in accordance with the first set of filtering rules.