Virtual Compute Instance Isolation for Fraud Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Fraudulent use of virtual compute instances leads to over-subscription of resources, impacting the performance of other instances on a host system, and existing techniques struggle to isolate and mitigate such fraudulent use without violating service-level agreements.

Innovation Solution

Implementing techniques to identify potentially fraudulent virtual compute instances through resource utilization monitoring and account information, followed by modifying resource availability and potentially migrating these instances to isolate their impact, while ensuring non-fraudulent instances maintain guaranteed performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtual compute instances are over-subscribed on host systems to efficiently utilize resources, then resource utilization efficiency is improved, but fraudulent instances can consume excessive resources and degrade performance of legitimate instances

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidperformance guarantee for legitimate instances
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments host system resources into different pools: guaranteed resources reserved for legitimate instances and best-effort resources available for fraudulent instances. This segmentation allows over-subscription while protecting legitimate workloads by isolating fraudulent resource consumption to specific resource pools that do not impact service-level agreements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The fraud mitigation service acts as an intermediary between fraudulent instances and host system resources. It monitors resource utilization patterns, identifies fraudulent behavior, and dynamically adjusts resource availability by modifying virtual device configurations, thereby protecting legitimate instances without requiring complete isolation of fraudulent workloads.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If fraud mitigation techniques are applied to isolate potentially fraudulent instances, then the impact on legitimate instances is reduced, but service-level agreements may be violated due to resource restrictions

Engineering Contradiction:
Improveimpact of fraudulent instancesVSAvoidservice-level agreement compliance
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The system dynamically adjusts resource availability for potentially fraudulent instances based on real-time monitoring of resource utilization patterns. When fraudulent behavior is detected, resource constraints are applied adaptively rather than statically, allowing the system to mitigate harm while maintaining service-level agreements under normal conditions. The fraud mitigation service continuously evaluates whether service-level objectives are met and adjusts resource allocation accordingly.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes resource allocation parameters dynamically by modifying the availability of virtual devices to potentially fraudulent instances. Instead of fixed resource reservations, the fraud mitigation service adjusts virtual device parameters such as CPU quotas, memory limits, and I/O thresholds based on detected fraud patterns, thereby reducing harmful impact while preserving service-level agreement compliance.

Inventive Principle:
Principle #35Parameter changes

3Object-generated harmful factors

If resource availability is modified for potentially fraudulent instances to mitigate fraud, then fraudulent resource consumption is limited, but legitimate resource needs may be impacted

Engineering Contradiction:
Improveexcessive resource consumption by fraudulent instancesVSAvoidresource availability for legitimate instances
Core Design Contradiction:
Object-generated harmful factorsVSProductivity

Solution Approach 1:

The system applies different resource quality levels to different instances based on their fraud risk profile. Legitimate instances receive full resource availability with no constraints, while potentially fraudulent instances have selectively restricted access to specific virtual devices or resource types. This local quality differentiation ensures that resource modifications target only fraudulent behavior without impacting legitimate workloads.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The fraud mitigation service extracts and isolates potentially fraudulent instances from the general resource pool by selectively modifying their access to virtual devices. Instead of restricting all resources system-wide, the system extracts only the problematic resource consumption paths by adjusting virtual device availability for specific instances, thereby limiting fraudulent impact while preserving overall system productivity.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12407722B1Isolating resources for potentially fraudulent virtual compute instances
Publication Date: 2025.09.02 AMAZON TECH INC
  • US12407722B1 patent drawing
  • US12407722B1 patent drawing
  • US12407722B1 patent drawing

AI summary

Resources may be isolated for potentially fraudulent virtual compute instances. Resource utilization of virtual compute instances at a host system may be monitored. A virtual compute instance may be identified for fraud mitigation based on the monitored resource utilization. Availability of hardware resources to the identified virtual compute instance may be modified, whereas the availability of the hardware resources may remain for other virtual compute instances not identified for fraud mitigation.