Scrubbed IP Domain for Cloud Probe Traffic Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud datacenters face inefficiencies and resource burdens due to unsolicited probe traffic from malicious sources, which can overwhelm computing resources and hinder legitimate network traffic, as traditional firewalls and security groups struggle to filter dynamic and nefarious probe traffic effectively.
Innovation Solution
A scrubbed Internet Protocol (IP) domain is established using a distributed, dynamic scrubbing scheme that identifies and drops probe traffic at designated points across the service provider network and datacenter, employing machine learning to categorize and filter out probe traffic before it reaches virtual machines, utilizing scrubbing points like cloud gateways and routers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewalls and security groups are used to filter probe traffic, then network security is maintained to some extent, but the filtering effectiveness is insufficient against dynamic and nefarious probe traffic
Solution Approach 1:
The patent introduces an intermediary scrubbing service positioned between the internet and the datacenter network. This scrubbing service acts as a mediator that receives incoming traffic, analyzes it for probe traffic characteristics, and filters out malicious traffic before it reaches the virtual machines. The scrubbing service includes components such as a scrubbing engine, traffic analyzer, and filter that work together to identify and remove probe traffic dynamically, thereby improving filtering effectiveness against traditional firewall limitations.
2Productivity
If probe traffic is allowed to reach virtual machines, then legitimate traffic can flow freely, but computing resources are overwhelmed by malicious traffic
Solution Approach 1:
The patent implements preliminary action by performing traffic scrubbing and probe traffic filtering before the traffic reaches the virtual machines and computing resources. The scrubbing service proactively analyzes incoming traffic flows, identifies probe traffic patterns, and removes malicious traffic in advance. This preliminary filtering prevents probe traffic from consuming computing resources, thereby maintaining high resource utilization efficiency for legitimate traffic while protecting against resource exhaustion attacks.
3Adaptability or versatility
If the datacenter is exposed to the service provider network, then applications can be accessed globally, but the datacenter becomes vulnerable to unsolicited probe traffic
Solution Approach 1:
The patent introduces a scrubbing service as an intermediary layer between the internet and the datacenter network. This mediator allows the datacenter to remain exposed to the service provider network for global accessibility while the scrubbing service filters out probe traffic. The scrubbing service includes a traffic analyzer that monitors incoming traffic and a filter that blocks probe traffic, thereby maintaining global access to applications while protecting against malicious exposure.
4Adaptability or versatility
If dynamic probe traffic is filtered using static firewall rules, then simple traffic filtering is achieved, but the filtering cannot adapt to changing probe traffic patterns
Solution Approach 1:
The patent implements dynamics by using a traffic analyzer that continuously monitors incoming traffic patterns and dynamically adjusts filtering criteria. The scrubbing engine adapts to changing probe traffic patterns by learning from observed traffic characteristics and updating its filtering rules in real-time. This dynamic approach allows the system to adapt to evolving attack patterns without requiring manual reconfiguration, while the modular architecture keeps the complexity manageable through automated analysis and adaptation mechanisms.
Data Source
AI summary
Concepts and technologies directed to scrubbed internet protocol domain for enhanced cloud security are disclosed herein. In various aspects, a system can include a processor and memory storing instructions that, upon execution, cause performance of operations. The operations can include exposing an application to a service provider network that provides an internet connection, where the application is provided by a datacenter that communicates with the service provider network. The operations can include monitoring traffic flows to the application during an observation time period, where the traffic flows include probe traffic that attempts to reach the application. The operations can include constructing a scrubbed internet protocol domain such that detected probe traffic is prevented from reaching a plurality of virtual machines provided by the datacenter.


