Risk-Based Data Routing and Sampling for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity and throughput of network computing and storage resources make it difficult to effectively detect and mitigate malicious data without affecting legitimate data, as existing detection and mitigation regimes often overzealously impact customer experiences.

Innovation Solution

Implementing a risk analyzer that uses risk classifiers to determine risk levels and profiles for transiting data, routing malicious data to quarantined hosts with additional mitigation measures while allowing legitimate data to be routed normally, and using a sandbox to analyze sampled data for improved risk assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If overzealous detection and mitigation regimes are implemented to handle malicious data, then security is improved, but customer experience deteriorates due to disruption of legitimate data

Engineering Contradiction:
ImprovesecurityVSAvoidcustomer experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies partial action by implementing data sampling where only a subset of transiting data is analyzed by the sandbox rather than all data. This reduces the burden on detection systems while still maintaining security effectiveness. The risk classifier processes data at a higher level to identify suspicious patterns without requiring exhaustive analysis of every data packet, thus balancing security with customer experience.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The detection system is segmented into multiple components: a risk classifier that performs initial assessment, a sandbox that performs detailed analysis on sampled data, and a routing mechanism that directs data based on risk levels. This segmentation allows different parts of the system to operate at different levels of scrutiny, reducing overall disruption while maintaining security.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If comprehensive detection regimes are implemented to identify malicious data, then detection accuracy is improved, but system complexity increases making implementation difficult

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The detection system is divided into modular components: a risk classifier that performs initial filtering and a sandbox that performs detailed analysis only on suspicious samples. This segmentation reduces overall system complexity by avoiding the need for comprehensive complex analysis on all data while maintaining high detection accuracy through focused scrutiny of suspicious cases.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses partial action by analyzing only a sample of transiting data through the sandbox rather than performing comprehensive analysis on all data. This approach maintains high detection accuracy for malicious data while significantly reducing the computational complexity and resource requirements of the overall system.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If all transiting data is analyzed to ensure security, then security coverage is improved, but processing time increases affecting data throughput

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements partial analysis by using the risk classifier to quickly assess all data and then subjecting only suspicious samples to detailed sandbox analysis. This maintains comprehensive security coverage for identifying malicious data while minimizing processing time by avoiding exhaustive analysis of legitimate data.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The analysis process is segmented into two stages: rapid initial classification of all data by the risk classifier, followed by detailed analysis only of suspicious samples by the sandbox. This segmentation enables the system to maintain high security coverage while processing data at near-line speed for the majority of legitimate traffic.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11711390B1Techniques for data routing and management using risk classification and data sampling
Publication Date: 2023.07.25 AMAZON TECH INC
  • US11711390B1 patent drawing
  • US11711390B1 patent drawing
  • US11711390B1 patent drawing

AI summary

Techniques described and suggested herein include various systems and methods for determining risk levels associated with transiting data, and routing portions of the data in accordance with the determined risk levels. For example, a risk analyzer may apply risk classifiers to transiting data to determine overall risk levels of some or all of the transiting data. A traffic router may route transiting data according to determined risk profiles for the data. A sandbox may be implemented to compare, for a given input, expected and observed outputs for a subset of transiting data, so as to determine risk profiles associated with at least the subset.