Tenant Packet Tagging for Malicious Source Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In shared computing environments, such as cloud or multi-tenant platforms, outgoing network packets often do not identify the specific user or application as the sender, making it difficult for recipients to pinpoint the source of malicious communications, leading to unnecessary blocking of all traffic from the environment.

Innovation Solution

A computer-security system intercepts outgoing network packets and adds a tag that identifies the specific tenant or user, allowing external recipients to determine the true source of the packet, thereby enabling selective blocking of malicious communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If outgoing network packets do not identify the specific user or application as the sender in shared computing environments, then the security and privacy of individual users are protected, but the ability to pinpoint the source of malicious communications is lost

Engineering Contradiction:
ImprovesecurityVSAvoidsource identification precision
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent introduces an intermediary tagging system where a security appliance inserts identifiers into outgoing packets from shared computing environments. This intermediary mechanism allows external recipients to identify the true source of communications without requiring the shared environment to expose internal user identities directly, thus maintaining security while enabling source identification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security appliance performs preliminary action by tagging outgoing network packets with user or application identifiers before they leave the shared computing environment. This advance tagging ensures that when packets are later analyzed for security purposes, the source information is already embedded and available for precise identification without compromising the underlying privacy architecture.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If all traffic from a shared computing environment is blocked to prevent malicious communications, then the security of external recipients is improved, but legitimate traffic from innocent users is also blocked

Engineering Contradiction:
ImprovesecurityVSAvoidlegitimate communication flow
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies segmentation by enabling external recipients to identify and respond to threats at the individual user or application level rather than blocking entire shared environments. By tagging packets with specific user identifiers, the system allows selective blocking of only the malicious source while permitting legitimate traffic from other users to continue flowing uninterrupted.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent replaces the mechanical all-or-nothing blocking approach with a more sophisticated system that uses embedded identifiers and automated analysis to distinguish between malicious and legitimate traffic. This substitution allows for granular control over traffic blocking decisions, replacing crude blanket restrictions with precision-based security measures.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If a security system adds tags to outgoing network packets to identify the specific user, then the precision of source identification is improved, but the complexity of the network infrastructure increases

Engineering Contradiction:
Improvesource identification precisionVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces a security appliance as an intermediary component that handles the tagging of network packets. This dedicated intermediary device centralizes the complexity of tag insertion and management, allowing the rest of the network infrastructure to remain relatively simple while still achieving precise source identification through the tagging mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10673893B2Isolating a source of an attack that originates from a shared computing environment
Publication Date: 2020.06.02 KYNDRYL INC
  • US10673893B2 patent drawing
  • US10673893B2 patent drawing
  • US10673893B2 patent drawing

AI summary

A method and associated systems for isolating a source of an attack that originates from a shared computing environment. A computer-security system tags outgoing packets originating from within the shared computing environment in a tamper-proof manner in order to identify which tenant of the shared environment is the true source of each packet. If one of those tenants transmits malicious packets to an external recipient, either because the tenant has malicious intent or becomes infected with malware, the transmitted malicious packets' tags allow the recipient to determine which tenant is the source of the unwanted transmissions. The recipient may then block further communications from the problematic tenant without blocking communications from other tenants of the shared environment.