Pattern-Based Service Interaction Detection in Distributed Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As distributed systems grow in scale and complexity, managing and securing interactions between services in a service-oriented architecture becomes increasingly challenging, particularly in identifying and monitoring sensitive data processing and potential security breaches.

Innovation Solution

A pattern-based detection system that monitors interactions between services, compares data and metadata against predefined patterns, and reports matches to a central recording service for data flow analysis and visualization, enabling the identification of services processing sensitive data and potential security breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If distributed systems grow in scale and complexity to provide more computing resources and services, then the system's productivity and adaptability improve, but the difficulty of managing and securing interactions between services increases

Engineering Contradiction:
Improvecomputing resources provisionVSAvoidsystem management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the complex distributed system into individual service components, each independently monitored for pattern matching. This allows the system to scale while maintaining manageable complexity by treating each service as a discrete unit that can be analyzed separately rather than managing the entire system as a monolithic complex structure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary pattern-matching system that sits between services and monitors their interactions. This intermediary automatically analyzes service communications against predefined patterns, reducing the manual management burden and enabling secure scaling without proportionally increasing operational complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive monitoring of service interactions is implemented to identify sensitive data processing, then security detection capability improves, but system complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity breach detection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-defining patterns for sensitive data and security breaches before monitoring begins. This allows the system to achieve high detection accuracy without complex real-time analysis, as the pattern-matching rules are established in advance and automatically applied to service interactions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the monitoring approach from analyzing complex contextual relationships to matching specific parameter patterns in service communications. This parameter-based pattern matching achieves precise security detection while maintaining simpler system architecture compared to comprehensive behavioral analysis.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If pattern matching is performed on all service interactions to identify sensitive data, then security monitoring precision improves, but the processing time and computational resources increase

Engineering Contradiction:
Improvesensitive data identification accuracyVSAvoidpattern matching processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies partial action by focusing pattern matching only on relevant parameters and metadata in service interactions rather than analyzing entire communication streams. This selective approach maintains high precision for identifying sensitive data while reducing overall processing time and computational overhead.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10320632B1Pattern-based detection for services in distributed systems
Publication Date: 2019.06.11 AMAZON TECH INC
  • US10320632B1 patent drawing
  • US10320632B1 patent drawing
  • US10320632B1 patent drawing

AI summary

Methods, systems, and computer-readable media for implementing pattern-based detection are disclosed. A plurality of services monitor a plurality of service interactions comprising data or metadata. The services compare the data or metadata to a set of patterns and identify one or more matched patterns among the set of patterns. The services send data indicative of the matched patterns to a central recording service. The central recording service aggregates the data indicative of the matched patterns and generates one or more data flow visualizations indicating one or more data flows between individual ones of the services for the matched patterns.