Network Appliance for Intrusion Detection Visibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In provider networks, conventional intrusion detection systems (IDS) are limited by their host-based deployment model, which results in incomplete visibility of network traffic and potential undetected security threats due to the lack of access to underlying network infrastructure, increasing management complexity and reducing detection efficacy.

Innovation Solution

Implementing network traffic monitoring, such as intrusion detection, at the load balancer layer or through out-of-band replication, allowing the provider network to configure and route traffic for monitoring without requiring clients to manage separate IDS components, thereby providing comprehensive traffic monitoring and threat detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If host-based IDS deployment is used, then clients have control over their own security monitoring, but network traffic visibility is incomplete and management complexity increases

Engineering Contradiction:
Improveclient control over security monitoringVSAvoidnetwork traffic visibility
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent introduces a network appliance as an intermediary component that sits between the network traffic source and the client's host-based IDS. This appliance captures and forwards network traffic to the IDS, providing complete visibility while allowing the client to maintain control over their security monitoring configuration and policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If host-based IDS deployment is used, then clients can implement security monitoring on their systems, but management complexity increases due to separate IDS component management

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the network traffic capture functionality and the IDS management into a single integrated network appliance. This merging eliminates the need for clients to manage separate IDS components independently, reducing management complexity while maintaining reliable security monitoring capability through the unified system.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If conventional IDS deployment is used, then security monitoring is implemented at the host level, but detection efficacy is reduced due to incomplete traffic visibility

Engineering Contradiction:
Improvesecurity monitoring implementationVSAvoidthreat detection efficacy
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent shifts the IDS deployment from a single host-based dimension to a network-level dimension by introducing the network appliance that intercepts traffic at the network layer. This dimensional change allows the IDS to observe complete network traffic flow across multiple hosts, significantly improving threat detection efficacy while maintaining security monitoring implementation at the original host level through integrated reporting.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9166992B1Methods and apparatus for providing network traffic monitoring services
Publication Date: 2015.10.20 AMAZON TECH INC
  • US9166992B1 patent drawing
  • US9166992B1 patent drawing
  • US9166992B1 patent drawing

AI summary

Methods and apparatus for providing network traffic monitoring such as intrusion detection to clients of a provider network. An interface and methods are provided via which a client can select traffic monitoring as a functionality to be added to their configuration on the provider network, for example as part of a load balancer layer. Via the interface, the client can configure new or existing components and specify that traffic monitoring be added on or at the components. Traffic monitoring technology is automatically and transparently added to the client's configuration on or at the components. By adding traffic monitoring functionality to an existing layer, the client does not have to separately manage traffic monitoring on the client's configuration. Traffic monitoring technology may be added at a network substrate level rather than at an overlay network level to insure that all traffic is available to the traffic monitoring technology.