Correlating Threat Information Across Distributed Computing Levels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In large distributed computing systems, identifying and securing vulnerabilities is challenging due to complexity and distribution, making it difficult to collect and analyze log information, and conventional systems rely on manual mitigation methods.
Innovation Solution
A security service that collects and correlates operational information from various sources, including customer-operated and service provider-operated resources, to generate a unified security model, using methods like clustering, statistical analysis, and machine learning to detect and mitigate threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual mitigation methods are used for security vulnerabilities, then system security can be maintained through human analysis, but the complexity and distribution of computing resources make it difficult to collect and analyze log information efficiently
Solution Approach 1:
The patent segments the distributed computing system into multiple hierarchical levels (infrastructure level, virtualization level, guest operating system level, and application level). Each level has dedicated security monitoring components that collect and analyze logs locally, then aggregate findings upward. This segmentation allows manual security analysis to remain effective at each manageable level while the system as a whole handles distributed complexity through structured division of monitoring responsibilities across levels.
2Loss of information
If conventional log collection methods are used, then some security information can be gathered, but it is difficult to collect and analyze log information generated by computing resources across multiple sources and levels
Solution Approach 1:
The patent introduces a hierarchical dimension to log collection and analysis, organizing security monitoring across four distinct levels: infrastructure level (physical hardware), virtualization level (hypervisor), guest operating system level, and application level. This hierarchical dimension transforms the flat, distributed log collection problem into a structured multi-level framework where logs are collected, correlated, and analyzed at appropriate levels before aggregation, making the complexity of distributed resources manageable through vertical stratification.
3Productivity
If automated security management is implemented across multiple levels, then threat detection and mitigation efficiency is improved, but the complexity of correlating information across sources increases
Solution Approach 1:
The patent segments automated security management into level-specific correlation processes. Each hierarchical level (infrastructure, virtualization, guest OS, application) performs correlation and analysis of logs generated at that level, then passes aggregated findings to the level above. This segmentation of correlation tasks prevents the need to correlate all logs from all levels simultaneously, reducing the complexity of information correlation while maintaining comprehensive automated security management across the entire distributed system.
4Extent of automation
If centralized security management is implemented, then automated threat mitigation across multiple sources is achieved, but the complexity of managing distributed computing resources increases
Solution Approach 1:
The patent implements centralized security management through a hierarchical dimension rather than a flat centralized structure. Each hierarchical level has automated security management capabilities that operate independently within that level, then aggregate findings upward through the hierarchy. This hierarchical dimension allows automated security management to function at multiple levels simultaneously, achieving comprehensive coverage while distributing management complexity across levels rather than concentrating all management functions in a single centralized point.
Data Source
AI summary
Customers of a computing resource service provider may operate one or more computing resource provided by the computing resource service provider. In addition, the customers may implement security applications and/or devices using the one or more computing resources provided by the computing resource service provider. Operational information from customer operated computing resources may be correlated with operational information from computing resources operated by the computing resource service provider or other entities and correlated threat information may be generated. Anomalous activity may be detected based at least in part on the correlated threat information.


