Virtual Asset Assisted Intrusion Detection in Cloud Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Detecting malware intrusion and extrusion in cloud computing environments is challenging due to the large number of virtual assets and resources involved, making it a difficult and resource-intensive task.

Innovation Solution

Implementing an analysis trigger monitoring system on virtual assets within the cloud computing environment to monitor message traffic for predefined parameters, identifying suspect messages, and transferring them to analysis systems for further examination.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional intrusion detection methods are used in cloud computing environments with hundreds or millions of virtual machines, then detection coverage can be maintained, but the task becomes extremely difficult and resource intensive

Engineering Contradiction:
Improvedetection capabilityVSAvoiddetection efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies self-service by enabling virtual assets to monitor their own message traffic for intrusion and extrusion indicators. Each virtual asset runs local monitoring code that autonomously detects suspicious patterns without requiring external detection infrastructure, transforming the detection task from resource-intensive centralized processing to lightweight distributed self-monitoring across the cloud environment

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The detection system is segmented into distributed components where each virtual asset independently monitors its own traffic. This segmentation eliminates the need for a single centralized detection system to handle all virtual machines, dividing the complex detection task into many simple local monitoring units that operate independently

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If comprehensive monitoring of all virtual assets is implemented, then detection accuracy improves, but resource consumption increases significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent implements local quality by having each virtual asset perform detection operations locally on its own message traffic rather than centralizing all monitoring. This allows detection accuracy to be maintained through comprehensive local monitoring while significantly reducing overall resource consumption, as each virtual asset only processes its own traffic data rather than all traffic in the environment

Inventive Principle:
Principle #3Local quality

3Device complexity

If existing cloud infrastructure is utilized for detection, then system complexity is reduced, but detection capability must be enhanced within existing constraints

Engineering Contradiction:
Improvesystem complexityVSAvoiddetection capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies universality by designing the monitoring system to function within existing cloud infrastructure while performing multiple detection tasks. The same cloud computing resources used for running virtual assets also host the detection monitoring code, allowing the system to maintain simplicity through existing infrastructure while enhancing detection capability through multi-functional use of these resources

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2951714B1Method and system for virtual asset assisted extrusion and intrusion detection in a cloud computing environment
Publication Date: 2019.04.10 INTUIT INC
  • EP2951714B1 patent drawingFigure 1
  • EP2951714B1 patent drawingFigure 2A
  • EP2951714B1 patent drawingFigure 2B

AI summary

An analysis trigger monitoring system is provided in one or more virtual assets. One or more analysis trigger parameters are defined and analysis trigger data is generated. The analysis trigger monitoring systems are used to monitor at least a portion of the message traffic sent to, or sent from, the one or more virtual assets to detect any message including one or more of the one or more analysis trigger parameters. A copy of at least a portion of any detected message including one or more of the one or more analysis trigger parameters is then transferred to one or more analysis systems for further analysis using a second communication channel.