Generative AI Delegator for Cloud Security Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data security and anomaly detection systems face challenges in efficiently monitoring and analyzing vast amounts of data from cloud environments to detect insider threats and anomalies in real-time.

Innovation Solution

A data platform is configured to ingest, process, and analyze data from cloud environments using agents deployed on compute assets, generating polygraphs to model normal behavior and detect deviations, leveraging generative AI for enhanced security and anomaly detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anomaly detection systems process vast amounts of data from cloud environments, then the ability to detect insider threats and anomalies improves, but the system complexity and computational resources required increase significantly

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex data processing task by deploying agents on individual compute assets to collect and pre-process data locally, then transmitting only essential information to the central polygraph generation system. This divides the workload between distributed agents and centralized processing, reducing overall system complexity while maintaining detection accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates a simplified representation (polygraph) of cloud environment behavior patterns that captures essential anomaly detection capabilities without requiring processing of the entire raw data volume. The polygraph acts as a compressed model that enables efficient anomaly detection while reducing computational requirements.

Inventive Principle:
Principle #26Copying

2Speed

If real-time data processing is implemented to detect security incidents immediately, then response time improves, but computational resource consumption increases

Engineering Contradiction:
Improvedetection speedVSAvoidcomputational resource consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

Agents perform preliminary data collection, filtering, and local processing actions before transmitting data to the central system. This pre-processing reduces the volume of data requiring real-time analysis while maintaining the ability to detect anomalies immediately, thus lowering computational resource consumption during real-time processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system extracts only the most critical information and behavior patterns from the vast amount of cloud environment data, representing them in the polygraph structure. This extraction enables real-time anomaly detection by focusing computational resources on the essential features rather than processing all raw data continuously.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If comprehensive data collection from all cloud assets is implemented, then detection coverage improves, but data management complexity increases

Engineering Contradiction:
Improvedetection coverageVSAvoiddata management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments data collection by deploying independent agents on each compute asset that autonomously manage their own data gathering and local processing. This segmentation allows comprehensive coverage across all cloud assets while distributing data management responsibilities, reducing central化管理 complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system merges individual asset data into a unified polygraph representation that consolidates behavior patterns across the entire cloud environment. This merging approach maintains comprehensive detection coverage while simplifying data management by creating a single integrated model rather than managing separate data structures for each asset.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12309185B1Architecture for a generative artificial intelligence (AI)-enabled assistant
Publication Date: 2025.05.20 FORTINET INC
  • US12309185B1 patent drawing
  • US12309185B1 patent drawing
  • US12309185B1 patent drawing

AI summary

Architecture for a generative artificial intelligence (AI)-enabled assistant, including: receiving, via a natural language interface for a security framework monitoring a cloud deployment, a natural language input; selecting, by a delegator generative artificial intelligence (AI) model and based on the natural language input, a particular generative AI model from a plurality of selectable generative AI models; prompting the particular generative AI model based on the natural language input; and providing, via the natural language interface and in response to the natural language input, a response from the particular generative AI model.