Virtual Asset Assisted Intrusion Detection in Cloud Computing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Detecting malware intrusion and extrusion in cloud computing environments is challenging due to the large number of virtual assets and resources involved, making it a difficult and resource-intensive task.
Innovation Solution
Implementing an analysis trigger monitoring system on virtual assets within the cloud computing environment to monitor message traffic for predefined parameters, identifying suspect messages, and transferring them to analysis systems for further examination.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional intrusion detection methods are used in cloud computing environments with hundreds or millions of virtual machines, then detection coverage can be maintained, but the task becomes extremely difficult and resource intensive
Solution Approach 1:
The patent applies self-service by enabling virtual assets to monitor their own message traffic for intrusion and extrusion indicators. Each virtual asset runs local monitoring code that autonomously detects suspicious patterns without requiring external detection infrastructure, transforming the detection task from resource-intensive centralized processing to lightweight distributed self-monitoring across the cloud environment
Solution Approach 2:
The detection system is segmented into distributed components where each virtual asset independently monitors its own traffic. This segmentation eliminates the need for a single centralized detection system to handle all virtual machines, dividing the complex detection task into many simple local monitoring units that operate independently
2Measurement precision
If comprehensive monitoring of all virtual assets is implemented, then detection accuracy improves, but resource consumption increases significantly
Solution Approach 1:
The patent implements local quality by having each virtual asset perform detection operations locally on its own message traffic rather than centralizing all monitoring. This allows detection accuracy to be maintained through comprehensive local monitoring while significantly reducing overall resource consumption, as each virtual asset only processes its own traffic data rather than all traffic in the environment
3Device complexity
If existing cloud infrastructure is utilized for detection, then system complexity is reduced, but detection capability must be enhanced within existing constraints
Solution Approach 1:
The patent applies universality by designing the monitoring system to function within existing cloud infrastructure while performing multiple detection tasks. The same cloud computing resources used for running virtual assets also host the detection monitoring code, allowing the system to maintain simplicity through existing infrastructure while enhancing detection capability through multi-functional use of these resources
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
An analysis trigger monitoring system is provided in one or more virtual assets. One or more analysis trigger parameters are defined and analysis trigger data is generated. The analysis trigger monitoring systems are used to monitor at least a portion of the message traffic sent to, or sent from, the one or more virtual assets to detect any message including one or more of the one or more analysis trigger parameters. A copy of at least a portion of any detected message including one or more of the one or more analysis trigger parameters is then transferred to one or more analysis systems for further analysis using a second communication channel.