Security Threat Based Auto Scaling for Cloud Resources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtualized computing systems are vulnerable to cyber-attacks due to extensive network connectivity, leading to significant costs and productivity losses, necessitating effective protection mechanisms for shared computing resources.

Innovation Solution

Implementing an auto-scaling mechanism in a service provider environment that identifies and mitigates cyber-attacks by dynamically adjusting computing resources, such as adding or removing instances, and applying security scaling actions based on heuristic rules to prevent resource overload and capture attackers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If computing resources are increased to handle cyber-attacks, then system reliability is improved, but resource loss increases

Engineering Contradiction:
Improvesystem reliabilityVSAvoidresource loss
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

The patent implements dynamic auto-scaling of computing resources based on real-time detection of cyber-attacks. The system automatically increases resources when attacks are detected and decreases them when threats subside, making the resource allocation flexible and adaptive to changing security conditions rather than static

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of computing resource allocation dynamically in response to security threats. By monitoring attack patterns and adjusting resource levels accordingly, the system optimizes the balance between maintaining reliability during attacks and reducing resource loss during normal operation

Inventive Principle:
Principle #35Parameter changes

2Reliability

If computing resources are increased to mitigate cyber-attacks, then security is improved, but cost increases

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system dynamically adjusts computing resources based on the presence and intensity of cyber-attacks. During attack periods, resources are increased to maintain security; during normal periods, resources are reduced to minimize costs, creating a cost-effective security posture that adapts to real-time threats

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the resource allocation parameter dynamically in response to security conditions. This parameter adjustment ensures security is maintained when needed while minimizing unnecessary resource consumption and associated costs during normal operation

Inventive Principle:
Principle #35Parameter changes

3Productivity

If auto-scaling is implemented to respond to cyber-attacks, then productivity is improved, but device complexity increases

Engineering Contradiction:
ImproveproductivityVSAvoiddevice complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system implements self-service through automated detection and response to cyber-attacks. The auto-scaling mechanism operates autonomously without requiring manual intervention, detecting threats and adjusting resources automatically, which improves productivity while the automation manages the complexity internally

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10050999B1Security threat based auto scaling
Publication Date: 2018.08.14 AMAZON TECH INC
  • US10050999B1 patent drawing
  • US10050999B1 patent drawing
  • US10050999B1 patent drawing

AI summary

Technology is described for auto scaling computing resources in response to a cyber-attack in a service provider environment. The computing resources in the service provider environment may be detected as being exposed to the cyber-attack. A security scaling action may be performed in the service provider environment that mitigates the cyber-attack. The security scaling action to be performed may be determined by a security threat mitigation service that operates in the service provider environment. A performance of the security scaling action in the service provider environment may be initiated.