Secure data backup and recovery from cyberattacks
US-2023141909-A1 · May 11, 2023 · US
US12063166B1 · US · B1
| Field | Value |
|---|---|
| Publication number | US-12063166-B1 |
| Application number | US-202217709265-A |
| Country | US |
| Kind code | B1 |
| Filing date | Mar 30, 2022 |
| Priority date | Mar 30, 2022 |
| Publication date | Aug 13, 2024 |
| Grant date | Aug 13, 2024 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Systems and methods for resource management are disclosed. A search request may be received at a resource management service of a provider network. The search request may be received from a client device that does not have permission to access resources in a protected region of a provider network. The search request may specify a query associated with at least one operational health indicator in the protected region. It may be determined, using a secure query service, that the at least one operational health indicator does not exist in the protected region. The secure query service enables the client device to obtain information about the resources in the protected region without gaining access to the resources in the protected region. Sending of a notification indicating that the at least one operational health indicator does not exist in the protected region to the client device may be caused.
Opening claim text (preview).
What is claimed is: 1. A method for resource management, the method comprising: receiving, from a client device that does not have permission to access resources in a protected region of a provider network, a search request at a resource management service of the provider network, the search request specifying a query associated with at least one operational health indicator in the protected region, wherein the protected region has restricted connectivity with at least one other region in the provider network; determining, using a secure query service, that the at least one operational health indicator does not exist in the protected region, wherein the secure query service enables the client device to obtain information about the resources in the protected region without gaining access to the resources in the protected region by sending the query regarding the status of the operational health indicator and receiving filtered results without receiving information retrieved by the query; and causing, by the resource management service, sending to the client device of a notification indicating that the at least one operational health indicator does not exist in the protected region. 2. The method of claim 1 , wherein determining, using the secure query service, that the at least one operational health indicator does not exist in the protected region by sending the query regarding the status of the operational health indicator and filtering the results comprises forwarding the search request to the secure query service, wherein the secure query service: sends a filtered search request validated by one or more attributes of a first schema to a storage location in the protected region; executes the search request on the at least one operational health indicator in the protected region using the name of the at least one operational health indicator; generates a search result including metadata associated with the at least one operational health indicator; and returns a search response based on filtering the search result by validating one or more attributes with a second schema. 3. The method of claim 1 , further comprising: causing creation of the at least one operational health indicator in the protected region using a secure transfer service, wherein the at least one operational health indicator is developed in an unprotected region of the provider network and the secure transfer service is configured to transfer the developed at least one operational health indicator to the protected region of the provider network. 4. The method of claim 3 , wherein the secure transfer service is configured to: determine, in the unprotected region, whether the developed at least one operational health indicator is free of malicious components; package, in the unprotected region, the developed at least one operational health indicator for transfer to the protected region by generating a manifest file for the developed at least one operational health indicator; and transfer, via the secure transfer service, the packaged, developed at least one operational health indicator from the unprotected region to the protected region. 5. The method of claim 3 , wherein the developed at least one operational health indicator comprises an infrastructure as code (IaC) to create the at least one operational health indicator in the protected region. 6. A system for resource management, the system comprising: at least one processor in communication with at least one memory, the at least one processor configured at least to: receive in a first region of a provider network a request from a client, the request indicative of performing a query associated with at least one operational health indicator in a protected region of the provider network, wherein the protected region has restricted access and restricted connectivity with the first region in the provider network; determine, by a query service with access to the protected region, that the at least one operational health indicator does not exist in the protected region, wherein the query service performs the query on the at least one operational health indicator in the protected region and returns filtered information indicative of the presence without sending the information retrieved from the at least one operational health indicator; and sending to the client device of a notification indicating that the at least one operational health indicator does not exist in the protected region. 7. The system of claim 6 , wherein determining, by the query service, that the at least one operational health indicator does not exist in the protected region comprises executing the query on the at least one operational health indicator in the protected region. 8. The system of claim 7 , wherein the at least one processor is further configured to: cause creation of the at least one operational health indicator in the protected region using a secure transfer service, wherein the at least one operational health indicator is developed in an unprotected region of the provider network and the secure transfer service is configured to transfer the developed at least one operational health indicator to the protected region of the provider network. 9. The system of claim 8 , wherein the secure transfer service is configured to: determine, in the unprotected region, whether the developed at least one operational health indicator is free of malicious components; package, in the unprotected region, the developed at least one operational health indicator for transfer to the protected region by generating a manifest file for the developed at least one operational health indicator; and transfer, via the secure transfer service, the packaged, developed at least one operational health indicator from the unprotected region to the protected region. 10. The system of claim 9 , wherein the developed at least one operational health indicator comprises an infrastructure as code (IaC) to create the at least one operational health indicator in the protected region. 11. The system of claim 7 , wherein the at least one operational health indicator exists in at least one different region of the provider network. 12. The system of claim 7 , wherein the at least one operational health indicator comprises an alarm. 13. The system of claim 7 , wherein the at least one operational health indicator comprises a metric. 14. A non-transitory computer-readable medium storing instructions that, when executed, causes at least one computing node to perform the operations comprising: receiving in a first region of a provider network a request from a client, the request indicative of performing a query associated with at least one operational health indicator in a protected region of the provider network, wherein the protected region has restricted access and restricted connectivity with the first region in the provider network; determining, by a query service with access to the protected region, that the at least one operational health indicator does not exist in the protected region, wherein the query service performs the query on the at least one operational health indicator in the protected region and returns filtered information indicative of the presence of the at least one operational health indicator without sending the information retrieved from the at least one operational health indicator; and causing sending information to the client indicating that the at least one operational health indicator does not exist in the protected region. 15. The non-transitory computer-readable medium of claim 14 , wherein determining, by the query s
User-type aware · CPC title
Centralised allocation of resources · CPC title
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
Event detection, e.g. attack signature detection · CPC title
Entity profiles · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.