Security Agent for Distributed Computing Threat Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large distributed computing systems, it is challenging to identify and isolate vulnerabilities, troubleshoot issues, and secure the system effectively due to complexity and distribution, with conventional methods relying on manual mitigation and struggling to collect and analyze log information efficiently.

Innovation Solution

An agent is executed on customer-operated computing resources to monitor processes, detect security threats, and collect operational information, which is then analyzed by a security service to generate security information and perform remedial operations based on customer-defined rule sets, allowing for automated mitigation of threats without manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual mitigation methods are used to secure the system, then system security can be maintained, but the complexity and distribution of computing resources make it difficult to collect and analyze log information efficiently

Engineering Contradiction:
Improvesystem securityVSAvoidlog collection and analysis complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security agent as an intermediary component deployed on each computing resource. This agent collects log information locally and transmits it to a central security service, mediating between the distributed log sources and the central analysis system. This resolves the contradiction by simplifying log collection at each node while maintaining comprehensive security monitoring across the distributed system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent merges log collection, security monitoring, and threat detection functions into a unified security service architecture. By combining these previously separate functions into an integrated system, the patent reduces the overall complexity of managing security across distributed computing resources while improving reliability through centralized coordination.

Inventive Principle:
Principle #5Merging (Combining)

2Productivity

If the system complexity and distribution increase, then more computing resources are available, but it becomes more challenging to identify and isolate vulnerabilities

Engineering Contradiction:
Improvecomputing resource availabilityVSAvoidvulnerability identification difficulty
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the security monitoring function by deploying individual security agents on each computing resource. This segmentation allows vulnerabilities to be identified and isolated at the specific resource level where they occur, making it easier to detect and measure security issues in distributed systems while maintaining high computing resource availability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements feedback mechanisms where security agents continuously monitor and report security events back to the central security service. This real-time feedback enables rapid identification and isolation of vulnerabilities in distributed systems, resolving the difficulty of detecting security issues as system complexity increases.

Inventive Principle:
Principle #23Feedback

3Loss of time

If automated remedial operations are implemented, then response time to security threats is reduced, but the extent of automation increases system complexity

Engineering Contradiction:
Improveresponse time to security threatsVSAvoidautomated remediation complexity
Core Design Contradiction:
Loss of timeVSExtent of automation

Solution Approach 1:

The patent implements preliminary action by pre-configuring remedial operations and security rules before security threats occur. The security service maintains a repository of predefined remediation actions that can be automatically executed when specific security events are detected, reducing response time while managing automation complexity through pre-planned responses.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service automation where the security system automatically performs remedial operations without requiring manual intervention. The security agent and service work together to automatically detect, analyze, and remediate security threats, reducing response time while the modular architecture manages the complexity of automation through clear separation of monitoring and remediation functions.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10362046B1Runtime behavior of computing resources of a distributed environment
Publication Date: 2019.07.23 AMAZON TECH INC
  • US10362046B1 patent drawing
  • US10362046B1 patent drawing
  • US10362046B1 patent drawing

AI summary

Customers of a computing resource service provider may operate one or more computing resource provided by the computing resource service provider. In addition, the customers may execute agent using the one or more computing resources provided by the computing resource service provider. Operational information from customer-operated computing resources may be obtained by the agents and evaluated for security threats. The operational information may be evaluated based at least in part on a set of security rules. The security rules may be generated at least in part on customer input to generate customer defined security rules.