-
1.
公开(公告)号:US09904587B1
公开(公告)日:2018-02-27
申请号:US14975295
申请日:2015-12-18
Applicant: Amazon Technologies, Inc.
Inventor: Nachiketh Rao Potlapally , Donald Lee Bailey, Jr. , Richard Weatherly
CPC classification number: G06F11/079 , G06F11/0709 , G06F11/0751 , G06F11/0757 , G06F11/0772 , G06F11/0793 , G06F11/3006 , G06F11/3419
Abstract: Anomalous behavior in a multi-tenant computing environment may be identified by analyzing hardware sensor value data associated with hardware events on a host machine. A privileged virtual machine instance executing on a host machine acquires hardware sensor values and causes the values to be compared to other hardware sensor value data that may be indicative of anomalous behavior; for example, various threshold values, patterns, and/or signatures of hardware counter values generated by analyzing and correlating hardware event counter data. In this manner, potential anomalous behavior on an instance may be determined without having to access customer data or workloads associated with the instance.
-
公开(公告)号:US09819727B2
公开(公告)日:2017-11-14
申请号:US13781289
申请日:2013-02-28
Applicant: Amazon Technologies, Inc.
Inventor: Nachiketh Rao Potlapally , Andrew Paul Mikulski , Donald Lee Bailey, Jr. , Robert Eric Fitzgerald
CPC classification number: H04L67/10 , H04L9/0662 , H04L9/0869 , H04L63/20 , H04L67/1023
Abstract: Methods and apparatus for a computing infrastructure for configurable-quality random data are disclosed. A storage medium stores program instructions that when executed on a processor designate some servers of a provider network as members of a pool of producers of random data usable by random data consumers. The instructions, when executed, determine a subset of the pool to be used to supply a collection of random data intended for a random data consumer, and one or more sources of random phenomena to be used to generate the collection of random data. The instructions, when executed, initiate a transmission of the collection of random data directed to the random data consumer.
-
公开(公告)号:US10348759B2
公开(公告)日:2019-07-09
申请号:US15874771
申请日:2018-01-18
Applicant: Amazon Technologies, Inc.
Inventor: Hassan Sultan , John Schweitzer , Donald Lee Bailey, Jr. , Gregory Branchek Roth , Nachiketh Rao Potlapally
Abstract: A graph of a plurality of resources in a computing environment is generated, with the graph associating a first resource of the plurality with a second resource of the plurality. Based at least in part on measurements obtained at a point in a test computing environment that corresponds to a point in the computing environment, a graph representing the relationship between the first resource and the second resource is generated. A threat model identifying potential risks to the computing environment is created from the graph.
-
公开(公告)号:US09425966B1
公开(公告)日:2016-08-23
申请号:US13826888
申请日:2013-03-14
Applicant: Amazon Technologies, Inc.
Inventor: Nachiketh Rao Potlapally , Eric Jason Brandwine , Gregory Alan Rubin , Patrick James Ward , James Leon Irving, Jr. , Andrew Paul Mikulski , Donald Lee Bailey, Jr.
CPC classification number: H04L9/3263 , H04L9/302 , H04L9/3268 , H04L63/0823 , H04L63/1433
Abstract: Methods and apparatus for a security mechanism evaluation service are disclosed. A storage medium stores program instructions that when executed on a processor define a programmatic interface enabling a client to submit an evaluation request for a security mechanism. On receiving an evaluation request from a client indicating a particular security mechanism using public-key encryption, the instructions when executed, identify resources of a provider network to be used to respond. The instructions, when executed, provide to the client, one or more of: (a) a trustworthiness indicator for a certificate authority that issued a public-key certificate in accordance with the particular security mechanism; (b) a result of a syntax analysis of the public-key certificate; or (c) a vulnerability indicator for a key pair.
Abstract translation: 公开了用于安全机制评估服务的方法和装置。 存储介质存储当在处理器上执行时定义编程接口的程序指令,使得客户端能够提交对安全机制的评估请求。 在从客户端接收到指示使用公钥加密的特定安全机制的评估请求时,执行指令时,识别要用于响应的提供商网络的资源。 指令在执行时向客户提供以下一个或多个:(a)根据特定安全机制发布公钥证书的认证机构的可信赖性指示符; (b)公钥证书的语法分析结果; 或(c)密钥对的漏洞指示符。
-
5.
公开(公告)号:US10705904B2
公开(公告)日:2020-07-07
申请号:US15900042
申请日:2018-02-20
Applicant: Amazon Technologies, Inc.
Inventor: Nachiketh Rao Potlapally , Donald Lee Bailey, Jr. , Richard Weatherly
Abstract: Anomalous behavior in a multi-tenant computing environment may be identified by analyzing hardware sensor value data associated with hardware events on a host machine. A privileged virtual machine instance executing on a host machine acquires hardware sensor values and causes the values to be compared to other hardware sensor value data that may be indicative of anomalous behavior; for example, various threshold values, patterns, and/or signatures of hardware counter values generated by analyzing and correlating hardware event counter data. In this manner, potential anomalous behavior on an instance may be determined without having to access customer data or workloads associated with the instance.
-
公开(公告)号:US09049232B2
公开(公告)日:2015-06-02
申请号:US13781298
申请日:2013-02-28
Applicant: Amazon Technologies, Inc.
Inventor: Nachiketh Rao Potlapally , Donald Lee Bailey, Jr. , Andrew Paul Mikulski , Robert Eric Fitzgerald
CPC classification number: H04L63/164 , H04L9/0869 , H04L63/04 , H04L63/16
Abstract: Methods and apparatus for a configurable-quality random data service are disclosed. A method includes implementing programmatic interfaces enabling a determination of respective characteristics of random data to be delivered to one or more clients of a random data service of a provider network. The method includes implementing security protocols for transmission of random data to the clients, including a protocol for transmission of random data to trusted clients at devices within the provider network. The method further includes obtaining, on behalf of a particular client and in accordance with the determined characteristics, random data from one or more servers of the provider network, and initiating a transmission of the random data directed to a destination associated with the particular client.
Abstract translation: 公开了可配置质量随机数据服务的方法和装置。 一种方法包括实现程序化接口,使得能够将随机数据的相应特性确定为递送给提供者网络的随机数据服务的一个或多个客户端。 该方法包括实现用于向客户端发送随机数据的安全协议,包括用于在提供商网络内的设备处将随机数据传输到可信客户端的协议。 该方法还包括代表特定客户端并根据确定的特征获得来自提供商网络的一个或多个服务器的随机数据,以及发起指向与特定客户端相关联的目的地的随机数据的传输。
-
公开(公告)号:US09576155B2
公开(公告)日:2017-02-21
申请号:US14868006
申请日:2015-09-28
Applicant: Amazon Technologies, Inc.
Inventor: Nachiketh Rao Potlapally , Michael David Marr , Eric Jason Brandwine , Donald Lee Bailey, Jr.
CPC classification number: G06F21/55 , G06F21/57 , G06F21/602 , G06F21/64 , H04L9/0861 , H04L9/30
Abstract: A trusted computing host is described that provides various security computations and other functions in a distributed multitenant and/or virtualized computing environment. The trusted host computing device can communicate with one or more host computing devices that host virtual machines to provide a number of security-related functions, including but not limited to boot firmware measurement, cryptographic key management, remote attestation, as well as security and forensics management. The trusted computing host maintains an isolated partition for each host computing device in the environment and communicates with peripheral cards on host computing devices in order to provide one or more security functions.
Abstract translation: 描述了在分布式多租户和/或虚拟化计算环境中提供各种安全计算和其他功能的可信计算主机。 可信主机计算设备可以与主机虚拟机的一个或多个主机计算设备进行通信,以提供许多与安全相关的功能,包括但不限于启动固件测量,密码密钥管理,远程验证以及安全和取证 管理。 可信计算主机为环境中的每个主机计算设备维护隔离的分区,并与主机计算设备上的外围卡进行通信,以便提供一个或多个安全功能。
-
公开(公告)号:US09147086B1
公开(公告)日:2015-09-29
申请号:US13912948
申请日:2013-06-07
Applicant: Amazon Technologies, Inc.
Inventor: Nachiketh Rao Potlapally , Michael David Marr , Eric Jason Brandwine , Donald Lee Bailey, Jr.
CPC classification number: G06F21/55 , G06F21/57 , G06F21/602 , G06F21/64 , H04L9/0861 , H04L9/30
Abstract: A trusted computing host is described that provides various security computations and other functions in a distributed multitenant and/or virtualized computing environment. The trusted host computing device can communicate with one or more host computing devices that host virtual machines to provide a number of security-related functions, including but not limited to boot firmware measurement, cryptographic key management, remote attestation, as well as security and forensics management. The trusted computing host maintains an isolated partition for each host computing device in the environment and communicates with peripheral cards on host computing devices in order to provide one or more security functions.
Abstract translation: 描述了在分布式多租户和/或虚拟化计算环境中提供各种安全计算和其他功能的可信计算主机。 可信主机计算设备可以与主机虚拟机的一个或多个主机计算设备进行通信,以提供许多与安全相关的功能,包括但不限于启动固件测量,密码密钥管理,远程验证以及安全和取证 管理。 可信计算主机为环境中的每个主机计算设备维护隔离的分区,并与主机计算设备上的外围卡进行通信,以便提供一个或多个安全功能。
-
公开(公告)号:US12028312B1
公开(公告)日:2024-07-02
申请号:US17809464
申请日:2022-06-28
Applicant: Amazon Technologies, Inc.
Inventor: Donald Lee Bailey, Jr. , Abigail Fuller , John Paul Torres , Giulian Dalton Luz
IPC: H04L61/3015 , H04L61/5007 , H04L61/5053
CPC classification number: H04L61/3025 , H04L61/5007 , H04L61/5053
Abstract: A namespace monitoring service may track released namespaces such as internet protocol (IP) addresses and manage namespace cooldown pools, available namespace pools, and a registry of released namespaces to detect and mitigate security vulnerabilities that arise from reassignment of namespaces. The namespace monitoring service provides access to the released namespace registry and/or sends a data stream of namespace registry updates. The namespace monitoring service may manage namespace reassignment process and extend the cooldown period of released namespaces or place a hold on available name spaces.
-
公开(公告)号:US11621996B2
公开(公告)日:2023-04-04
申请号:US15811592
申请日:2017-11-13
Applicant: Amazon Technologies, Inc.
Inventor: Nachiketh Rao Potlapally , Andrew Paul Mikulski , Donald Lee Bailey, Jr. , Robert Eric Fitzgerald
IPC: H04L67/10 , H04L9/08 , H04L67/1023 , H04L9/40 , H04L9/06
Abstract: Methods and apparatus for a computing infrastructure for configurable-quality random data are disclosed. A storage medium stores program instructions that when executed on a processor designate some servers of a provider network as members of a pool of producers of random data usable by random data consumers. The instructions, when executed, determine a subset of the pool to be used to supply a collection of random data intended for a random data consumer, and one or more sources of random phenomena to be used to generate the collection of random data. The instructions, when executed, initiate a transmission of the collection of random data directed to the random data consumer.
-
-
-
-
-
-
-
-
-