Efficient monitoring of network activity in a cloud computing environment

Patent No. US11582252 (titled "Efficient monitoring of network activity in a cloud computing environment") on Sep 11, 2020. The application was issued on Feb 14, 2023.

What is this patent about?

’252 is related to the field of network security monitoring within public cloud computing environments. Specifically, it addresses the technical challenges of performing forensic analysis on massive volumes of traffic data in multi-tenant architectures, where traditional methods of full packet capture are often too resource-intensive or costly to scale effectively.

The underlying idea behind ’252 is to bridge the gap between lightweight metadata logging and heavy-duty packet inspection by creating a direct, referential link between the two. Instead of treating flow logs and full packet captures as isolated silos, the system embeds specific pointers within the metadata that allow for the surgical retrieval of raw packet data only when a potential threat is detected.

The claims of ’252 focus on a method and system that generates flow log records containing metadata identifiers, uses those identifiers to flag suspicious activity, and then leverages a referential mapping to pull the corresponding captured data packet (PCAP) record from a repository. A critical limitation of the independent claims is that the volume of PCAP data transmitted for analysis must represent less than 1% of the total stored packet data.

In practice, the invention functions by modifying standard VPC flow logs to include custom fields, such as a pcap_location storage address and security-specific fingerprints like JA3 SSL hashes. When a query identifies a malicious IP or a suspicious handshake fingerprint in the flow logs, the system uses the embedded location link to perform an on-demand targeted retrieval of the relevant binary files from cloud storage, such as an S3 bucket.

This approach differs from prior solutions that required exhaustive, terabyte-scale searches across entire PCAP repositories or the deployment of expensive, high-compute search clusters like Elasticsearch. By utilizing the flow log as a searchable index for the raw traffic data, the invention significantly reduces the cost-to-serve and accelerates incident response times by avoiding the need to download and index the vast majority of benign network traffic.

How does this patent fit in bigger picture?

Technical Landscape

In the early 2020s when ’252 was filed, network security monitoring in multi-tenant cloud environments was typically implemented using two mutually exclusive methodologies: metadata-based header analysis or full packet capture (PCAP) analysis. At a time when systems commonly relied on resource-intensive search clusters to index and query terabytes of archived packet data, hardware and software constraints made the real-time correlation of high-level flow logs with deep-packet archives non-trivial. In these environments, forensic investigation often required exhaustive, full-text searches across massive binary large object stores, creating significant computational overhead and latency when attempting to isolate specific malicious traffic patterns within high-volume network streams.

Prosecution Position

The disclosed invention represents a technical advancement in network forensics through the architectural integration of referential metadata links directly within network flow log records. By generating flow logs that include specific pointers or locations for corresponding captured data packet files, the system enables an architectural shift from exhaustive repository-wide searches to on-demand, targeted retrieval of forensic data. This integration overcomes the technical constraint of high cost-to-serve and scaling challenges in public cloud environments by utilizing metadata-level triggers—such as SSL fingerprints or malicious IP identifiers—to facilitate immediate access to associated deep-packet records without the need for large-scale indexing of the entire packet payload volume.

Claims

This patent contains 18 total claims, with claims 1, 7, and 13 serving as the independent claims. The independent claims focus on a method, a database system, and a computer-readable medium for monitoring security risks in a public cloud environment by generating flow log records with metadata, identifying risky data packets, and retrieving specific captured data packet (PCAP) records that constitute a small fraction of the total stored data for analysis. The dependent claims serve to further define the metadata identifiers to include specific addresses or fingerprint identifiers like JA3 SSL, detail the aggregation of records from virtual machine instances, and specify the retrieval of multiple records associated with suspected IP addresses.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Captured data packet (PCAP) record
(Claim 1, Claim 7, Claim 13)
Also as used herein, a “captured data packet record” or “PCAP record” refers to data files for storing and archiving data packets received by a network. PCAP records are generally used for network traffic analysis, such as forensic analysis. In public cloud environments, most cloud service providers enable the capture of network packet data... and further provide capabilities to store the packet data in captured data packet (PCAP) records in their local binary large object (BLOB) storages.Data files used for storing and archiving the full payload and content of data packets received by a network, typically utilized for forensic network traffic analysis.
Flow log records
(Claim 1, Claim 7, Claim 13)
As used herein, a “flow log record” refers to a record of network events that includes data fields descriptive of network traffic flow into or out of a network. Flow log records may include identifiers such as, but not limited to, IP addresses indicative of sources and or destinations of data, network traffic protocols, data packet sizes, or other suitable information. Each record generated may contain data descriptive of a particular data packet at a metadata level without storing the contents of the data packet.Records of network events containing metadata-level data fields descriptive of network traffic flow (such as IP addresses, protocols, and packet sizes) into or out of a network, without storing the actual contents of the data packets.
Metadata identifiers
(Claim 1, Claim 7, Claim 13)
The system identifies information in data packet headers that is indicative of potential security risks such as, for example, a malicious IP address, and utilizes associated metadata within the data packet header to perform a targeted lookup of records in which the data packet has been stored or archived. In some implementations, a flow log record may be modified to include a JA3 hash to facilitate hunting SSL/TLS clients in the public cloud environment. Advantages... include... generating flow log records for incoming data packets that include referential links to corresponding PCAP data files.Information contained in or derived from data packet headers—such as IP addresses, SSL fingerprints (e.g., JA3 hashes), or referential links—used to identify potential security risks and facilitate targeted lookups of stored packet data.
PCAP record repository
(Claim 1, Claim 7, Claim 13)
In public cloud environments, most cloud service providers... provide capabilities to store the packet data in captured data packet (PCAP) records in their local binary large object (BLOB) storages. This approach avoids the need to perform full text searches of all captured data packet records, thus minimizing the amount of data to be downloaded and indexed. When the Presto query completes, the responder will now have access to a distinct list of PCAP records in S3.A storage location, such as a local binary large object (BLOB) storage or an AWS S3 bucket, where captured data packet records are archived for later retrieval and analysis.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
2:22-cv-00385Oct 3, 2022Bishop Display Tech LLC v. Innolux Corporation

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US11582252

Application Number
US17018355A
Filing Date
Sep 11, 2020
Publication Date
Feb 14, 2023
External Links
Slate, USPTO , Google Patents