Security Verification via Message Interception and Modification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Ensuring the security of computing resources and data in large distributed systems is challenging due to complexities and the difficulty in detecting vulnerabilities, especially when different applications with varying roles and skills are involved, leading to potential insecurities that may go undetected.

Innovation Solution

Injecting insecurity into communications between computer systems to test their configurations and responses, using methods such as modifying messages or acting as a man-in-the-middle to simulate protocol failures, and monitoring reactions to identify potential security breaches, with mitigating operations like blacklisting or whitelisting to address vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If distributed systems use multiple different applications with varying roles and skills, then system functionality and versatility are improved, but security detection difficulty and vulnerability management worsen

Engineering Contradiction:
Improvesystem functionalityVSAvoidsecurity vulnerability detection
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a security verification system that acts as an intermediary between applications and the distributed system infrastructure. This intermediary automatically intercepts, monitors, and verifies security protocols across all applications regardless of their specific roles or implementations, centralizing security detection capabilities and eliminating the need for each application to have specialized security detection mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security verification system enables applications to self-verify their security configurations by automatically injecting test insecurity into their communications and analyzing their responses. This self-service mechanism allows each application to detect its own vulnerabilities without requiring external security experts or complex manual auditing processes.

Inventive Principle:
Principle #25Self-service

2Reliability

If security verification methods are applied to test computer systems, then security vulnerability detection is improved, but communication overhead and system complexity worsen

Engineering Contradiction:
Improvesecurity vulnerability detectionVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security verification system applies partial action by selectively injecting insecurity into specific test communications rather than all communications. The system monitors only the responses related to security protocol handling, leaving normal operational communications unaffected. This approach provides sufficient security verification while minimizing interference with system operations and reducing overall communication overhead.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10574686B2Security verification by message interception and modification
Publication Date: 2020.02.25 AMAZON TECH INC
  • US10574686B2 patent drawing
  • US10574686B2 patent drawing
  • US10574686B2 patent drawing

AI summary

A first computer is selected for testing. Information sent from a second computer system to the first computer is intercepted. The information is modified to be noncompliant with a communication protocol, thereby producing noncompliant information. A determination is made whether the first computer device has failed to provide a particular response to receipt of the noncompliant information, and an operation is performed based at least in part on the determination.