AI-POWERED SECURITY AND ANOMALY DETECTION SYSTEM
Patent Information
- Application Number
- TR202507666
- Authority / Receiving Office
- TR · TR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-06-11
- Publication Date
- 2026-06-22
Smart Images

Figure 00000007_0000
Abstract
Description
1 TARIFF AI-POWERED SECURITY AND ANOMALY DETECTION SYSTEM TECHNICAL AREA 5 The invention relates generally to an artificial intelligence-powered security and anomaly detection system. The invention is particularly useful for ensuring security and detecting threats in Kubernetes infrastructures. and to protect the system by identifying abnormal behaviors at an early stage 10 Security in distributed, dynamically operating pods and services It is implemented for continuous and intelligent monitoring, not based on known attack patterns, but on the same The system also detects previously unidentified abnormal behaviors over time. AI-powered security and anomaly control system that dynamically provides security. It is related to the detection system. 15 STATE OF THE ART Today, Kubernetes frameworks are modern due to their scalability and flexibility. It plays a significant role in application deployment. However, Kubernetes infrastructures have security issues. Protecting it from this perspective is becoming increasingly complex. Here... Hundreds of pods, services, and resources are protected against external threats or anomalies in the internal structure. It needs constant monitoring for movements. Current security systems are generally signature-based and have previously been used for 25 years. It can recognize identified threats. However, it is variable and dynamic, like Kubernetes. These systems are insufficient in structures. Newly emerging behaviors or previously... Unidentified attack types can be overlooked. Also, most systems are manual. It requires intervention, which leads to delays and human errors. Based on a search conducted under the known state of the art, the number US11704413 An application has been encountered. This application concerns hidden Kubernetes clusters. It offers a system aimed at assessing security risks. The system provides in-depth analysis. Using learning algorithms, potential security risks in a Kubernetes environment can be identified. 2 identifying vulnerabilities and anticipating and addressing these risks in advance. It targets predefined types of vulnerabilities in the system. It aims to perform risk analysis by matching configurations and behaviors. However, unlike a system based on behavior-based learning, it deals with unknown threats. It cannot proactively detect. Because it does not perform real-time monitoring, it is vulnerable to rapidly evolving 5 It may respond slowly to attacks. While the application in question focuses on known vulnerabilities, unknown threats, dynamic threat behaviors, and real-time attacks It is insufficient to counteract this. In conclusion, there are 10 AI-powered security and anomaly detection systems. Improvements are being made, therefore the aforementioned disadvantages are being eliminated. There is a need for new structures that will remove existing systems and provide solutions. It is heard. THE PURPOSE OF THE INVENTION 15 The present invention meets the aforementioned requirements and overcomes all the disadvantages. AI-powered security that eliminates these problems and brings some additional advantages. It is related to the anomaly detection system. The main purpose of the invention is to ensure security in Kubernetes infrastructures and to mitigate threats. detection and early identification of abnormal behaviors to protect the system in distributed, dynamically operating pods and services used for this purpose known attack patterns applied for continuous and intelligent monitoring of security not only, but also detect previously unidentified abnormal behaviors. 25 an AI-powered security system that dynamically ensures system security. and to provide an anomaly detection system. One of the aims of the invention is to analyze not only known attack patterns, but also those previously unknown. By also detecting unidentified abnormal behavior, the system security is dynamically enhanced. 30 to provide it in this way. 3 Another aim of the invention is to create a structure that constantly learns and adapts, thus making classical Making Kubernetes systems smarter by going beyond security measures It is to bring. The structural and characteristic features and all the advantages of the invention are given in Figure 5 below. And thanks to the detailed explanation written with references to these figures, it becomes clearer. This will be understood as such. Therefore, the evaluation should also be based on these forms and details. This should be done taking the explanation into consideration. BRIEF DESCRIPTION OF THE FIGURES 10 The best way to utilize the advantages of the existing invention, together with its structure and additional elements. For understanding, it should be evaluated together with the figures explained below. is necessary. Figure 1 Block of the artificial intelligence-powered security and anomaly detection system, which is the subject of the invention. This is a diagram view. 15 REFERENCE NUMBERS 1. Anomaly detection module 2. Analysis module 20 3. Intervention Module DETAILED EXPLANATION OF THE INVENTION This detailed explanation describes the invention as an AI-powered security and anomaly detection system. The preferred structures of the system contribute not only to a better understanding of the subject. This is explained in a way that is geared towards and does not create any limiting effects. The invention, shown in the block diagram in Figure 1, is used in Kubernetes infrastructures. Ensuring security, identifying threats and detecting abnormal behavior at an early stage 30 distributed, dynamic structures used to protect the system by identifying and implementing them. For continuous and intelligent security monitoring in pods and services that operate as such. The attacks employed involved not only known attack patterns, but also previously unidentified ones. 4 Dynamically ensuring system security by also detecting abnormal behavior. It is an artificial intelligence-powered security and anomaly detection system. This artificial intelligence... Intelligence-assisted security and anomaly detection system. Nodes, which are physical or virtual machines on which applications run Network traffic, API calls, and services within clusters, which are a combination of 5 by collecting and analyzing communication data between them in real time an analysis module (2), Based on the data obtained by the mentioned analysis module (2) Behavioral patterns of components running in a Kubernetes environment After the learner classified daily activities as normal, 10 detecting unexpected, suspicious, or incomplete activities an AI-powered anomaly detection module (1), The threat level detected by the aforementioned anomaly detection module (1) It gives a warning if it exceeds a predetermined threshold value. 15 that isolates the threatened pod and disables network connectivity. and an intervention module that activates safe mode (3) It includes. The invention is a prototype of an artificial intelligence-powered security and anomaly detection system. In the first stage of the application, network traffic within the Kubernetes cluster, system 20 calls, pod behaviors and user interactions are analyzed by an analytics module (2) It is constantly monitored and analyzed. The anomaly detection module (1) analyzes It identifies unusual behaviors based on the analysis performed by module (2). For example, Excessive resource consumption, unusual port accesses, or unexpected events. Potential threats are classified using data such as transactions that occurred over time. Anomaly 25 Anomalies detected by the detection module (1) are reported to the system operators. While timely notification is given; the intervention module (3) automatically responds in critical situations preventive measures such as restricting network access or isolating pods Actions are put into effect. In the system that is the subject of the invention, the artificial intelligence-based anomaly detection module (1) system It identifies unusual movements by learning. Real-time analysis module (2), It analyzes the system's communication traffic and makes these anomalies clearer. Threat When detected, the intervention module (3) disconnects the connections or suspects if necessary. It protects the overall security of the system by isolating the pods. This configuration is suitable for a Kubernetes environment. It provides uninterrupted and adaptive security.
Claims
6 REQUESTS 1. Ensuring security and detecting threats in Kubernetes infrastructures, and Protecting the system by identifying abnormal behaviors at an early stage. Used for this purpose, a distributed, dynamically operating pod and 5 implemented for continuous and intelligent monitoring of safety in services, not only known attack patterns, but also previously unidentified ones. By also detecting abnormal behavior, the system security is dynamically improved. It is an AI-powered security and anomaly detection system that provides, Feature; 10 Nodes, which are physical or virtual machines on which applications run Network traffic, API calls, and services within clusters, which are a combination of by collecting and analyzing communication data between them in real time an analysis module (2), Based on the data obtained by the mentioned analysis module (2), 15 Behavioral patterns of components running in a Kubernetes environment After the learner categorizes daily activities as normal, detecting unexpected, suspicious, or incomplete activities an AI-powered anomaly detection module (1), The threat level detected by the aforementioned anomaly detection module (1) is 20 It gives a warning if it exceeds a predetermined threshold value. isolating the threatened pod and disabling network connectivity. and an intervention module that activates safe mode (3) It includes. 25