Patent No. US11582252 (titled "Efficient monitoring of network activity in a cloud computing environment") on Sep 11, 2020. The application was issued on Feb 14, 2023.
’252 is related to the field of network security monitoring within public cloud computing environments. Specifically, it addresses the technical challenges of performing forensic analysis on massive volumes of traffic data in multi-tenant architectures, where traditional methods of full packet capture are often too resource-intensive or costly to scale effectively.
The underlying idea behind ’252 is to bridge the gap between lightweight metadata logging and heavy-duty packet inspection by creating a direct, referential link between the two. Instead of treating flow logs and full packet captures as isolated silos, the system embeds specific pointers within the metadata that allow for the surgical retrieval of raw packet data only when a potential threat is detected.
The claims of ’252 focus on a method and system that generates flow log records containing metadata identifiers, uses those identifiers to flag suspicious activity, and then leverages a referential mapping to pull the corresponding captured data packet (PCAP) record from a repository. A critical limitation of the independent claims is that the volume of PCAP data transmitted for analysis must represent less than 1% of the total stored packet data.
In practice, the invention functions by modifying standard VPC flow logs to include custom fields, such as a pcap_location storage address and security-specific fingerprints like JA3 SSL hashes. When a query identifies a malicious IP or a suspicious handshake fingerprint in the flow logs, the system uses the embedded location link to perform an on-demand targeted retrieval of the relevant binary files from cloud storage, such as an S3 bucket.
This approach differs from prior solutions that required exhaustive, terabyte-scale searches across entire PCAP repositories or the deployment of expensive, high-compute search clusters like Elasticsearch. By utilizing the flow log as a searchable index for the raw traffic data, the invention significantly reduces the cost-to-serve and accelerates incident response times by avoiding the need to download and index the vast majority of benign network traffic.
In the early 2020s when ’252 was filed, network security monitoring in multi-tenant cloud environments was typically implemented using two mutually exclusive methodologies: metadata-based header analysis or full packet capture (PCAP) analysis. At a time when systems commonly relied on resource-intensive search clusters to index and query terabytes of archived packet data, hardware and software constraints made the real-time correlation of high-level flow logs with deep-packet archives non-trivial. In these environments, forensic investigation often required exhaustive, full-text searches across massive binary large object stores, creating significant computational overhead and latency when attempting to isolate specific malicious traffic patterns within high-volume network streams.
The disclosed invention represents a technical advancement in network forensics through the architectural integration of referential metadata links directly within network flow log records. By generating flow logs that include specific pointers or locations for corresponding captured data packet files, the system enables an architectural shift from exhaustive repository-wide searches to on-demand, targeted retrieval of forensic data. This integration overcomes the technical constraint of high cost-to-serve and scaling challenges in public cloud environments by utilizing metadata-level triggers—such as SSL fingerprints or malicious IP identifiers—to facilitate immediate access to associated deep-packet records without the need for large-scale indexing of the entire packet payload volume.
This patent contains 18 total claims, with claims 1, 7, and 13 serving as the independent claims. The independent claims focus on a method, a database system, and a computer-readable medium for monitoring security risks in a public cloud environment by generating flow log records with metadata, identifying risky data packets, and retrieving specific captured data packet (PCAP) records that constitute a small fraction of the total stored data for analysis. The dependent claims serve to further define the metadata identifiers to include specific addresses or fingerprint identifiers like JA3 SSL, detail the aggregation of records from virtual machine instances, and specify the retrieval of multiple records associated with suspected IP addresses.
Definitions of key terms used in the patent claims.
US Latest litigation cases involving this patent.

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.
Get instant alerts for new documents