Dynamic Network Attack Detection and Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data centers face challenges in providing network isolation for diverse customer systems while allowing desired communications while restricting undesired ones, and existing solutions are inadequate in detecting and responding to network attacks effectively.

Innovation Solution

A Data Transmission Management system that dynamically updates access policies for computing nodes by analyzing data transmissions, using Transmission Manager components to authorize communications based on defined policies and group membership, and employs a Network Diagnostic System to detect malicious activities and implement security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network isolation policies are strictly enforced for each customer system, then security and isolation are improved, but legitimate communications between authorized systems are restricted

Engineering Contradiction:
Improvenetwork securityVSAvoidauthorized communication
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system continuously monitors network traffic patterns and communication behaviors to detect anomalies that may indicate attacks. This feedback mechanism allows the system to dynamically adjust isolation policies, blocking only suspicious traffic while maintaining legitimate communications. The feedback loop enables the system to learn from observed patterns and improve its discrimination between authorized and unauthorized communications over time.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The network isolation system transitions from static, pre-configured access control lists to dynamic policy enforcement based on real-time analysis of communication patterns. The system adapts its isolation rules dynamically, allowing legitimate communications to proceed while automatically blocking detected attacks. This dynamic approach resolves the contradiction by making isolation policies flexible rather than rigid.

Inventive Principle:
Principle #15Dynamics

2Measurement precision

If comprehensive monitoring of all data transmissions is implemented to detect attacks, then detection capability is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improveattack detection capabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system extracts and analyzes only specific relevant features from network traffic data, such as communication patterns, frequency, and timing, rather than processing entire data streams. This selective extraction reduces the complexity of monitoring while maintaining effective attack detection capability. The system focuses on key indicators of potential attacks without requiring comprehensive analysis of all transmission details.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces intermediary components that sit between network traffic sources and the analysis engine, pre-processing and filtering data before detailed examination. These intermediaries aggregate traffic patterns and identify anomalies at intermediate stages, reducing the burden on the main detection system and lowering overall complexity while preserving detection precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If dynamic access policy updates are implemented in response to detected attacks, then security response effectiveness is improved, but risk of blocking legitimate communications increases

Engineering Contradiction:
Improvesecurity response effectivenessVSAvoidlegitimate communication reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements preliminary blocking of identified attack sources before legitimate communications from those sources can cause harm. When an attack pattern is detected, the system proactively updates access policies to block the offending source immediately. This preliminary action prioritizes security response while the system continues to monitor to ensure legitimate communications are not inadvertently blocked.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors the effects of dynamic policy updates by observing communication patterns after blocking decisions are made. If legitimate communications are accidentally blocked, the feedback mechanism detects this anomaly and triggers policy adjustments to restore those communications. This closed-loop feedback ensures that security response effectiveness is maintained while minimizing false positives that would block legitimate traffic.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9258319B1Detection of and responses to network attacks
Publication Date: 2016.02.09 AMAZON TECH INC
  • US9258319B1 patent drawing
  • US9258319B1 patent drawing
  • US9258319B1 patent drawing

AI summary

Disclosed are various embodiments for detecting and responding to attacks on a computer network. One embodiment of such a method describes monitoring data communications transmitted to a target class of first computing nodes; in response to detecting a non-legitimate data communication to a computing node in the target class, determining whether the non-legitimate data communication is a form of attack on a network to which the computing nodes are connected; and in response to determining that the network is under attack, implementing new security measures for second computing nodes that are not part of the target class to protect the second computing nodes against the attack on the network while the attack is ongoing.