Parametric-Sensitive Transaction Weighting for Multi-Tenant DoS Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, multi-tenant shared infrastructures face challenges in tracking usage and preventing application-level denial-of-service attacks, which can lead to unintentional degradation of service and impact legitimate users.

Innovation Solution

A method that involves creating and applying usage profiles with parametric-sensitive transaction weightings to determine access permissions, using a weighting function to adjust transaction weights based on parameters, thereby preventing excessive resource utilization and denial-of-service attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple entities share the infrastructure in a multi-tenant cloud environment, then resource utilization and cost efficiency are improved, but tracking usage and preventing denial-of-service attacks becomes more difficult

Engineering Contradiction:
Improveresource utilizationVSAvoidusage tracking complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments usage tracking by creating separate usage profiles for different tenants and accessors. Each profile contains specific usage constraints and weights that apply only to that tenant's accessors, allowing independent tracking and control without interference from other tenants. This segmentation resolves the complexity of tracking usage in a shared multi-tenant environment.

Inventive Principle:
Principle #1Segmentation

2Reliability

If usage constraints are applied to prevent denial-of-service attacks, then service reliability is improved, but access flexibility and user experience may deteriorate

Engineering Contradiction:
Improveservice reliabilityVSAvoidaccess flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic usage constraints through parametric-sensitive transaction weighting. Instead of static limits, the system dynamically adjusts transaction weights based on parameters such as transaction type, accessor identity, and current system state. This allows the system to maintain reliability by preventing abuse while preserving access flexibility for legitimate users through adaptive, context-aware decision-making.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If transaction weights are adjusted based on parameters to differentiate legitimate usage from attacks, then detection precision is improved, but computational overhead increases

Engineering Contradiction:
Improveusage detection precisionVSAvoidcomputational overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent changes parameters by introducing parametric-sensitive transaction weights that vary based on specific transaction characteristics. Instead of complex analysis of entire transaction patterns, the system uses simplified parametric adjustments to weights based on easily extractable features like transaction type and accessor identity. This achieves high detection precision with minimal computational overhead by focusing on key discriminating parameters.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9548991B1Preventing application-level denial-of-service in a multi-tenant system using parametric-sensitive transaction weighting
Publication Date: 2017.01.17 MAPLEBEAR INC
  • US9548991B1 patent drawing
  • US9548991B1 patent drawing
  • US9548991B1 patent drawing

AI summary

Denial-of-service attacks are prevented or mitigated in a cloud compute environment, such as a multi-tenant, collaborative SaaS system. This is achieved by providing a mechanism by which characterization of “legitimate” behavior is defined for accessor classes, preferably along with actions to be taken in the event an accessor exceeds those limits. A set of accessor “usage profiles” are generated. Typically, a profile comprises information, such as one or more “constraints,” and one or more “actions.” At least one constraint is generated by applying one or more parameters of a transaction weighting function such that the resulting constraint represents an actual or estimated cost of executing the transaction. An action defines how the system will respond if a particular constraint is triggered. By applying the constraints to accessor requests, the approach prevents over-utilization of compute resources.