Anomaly Detection with Selective Telemetry Collection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing anomaly detection systems face challenges in determining the right amount of data to collect, leading to resource strain, inaccurate detection, and privacy concerns, while balancing sensitivity and avoiding false alarms in dynamic environments.

Innovation Solution

A 'detect and collect' approach that initially analyzes a carefully selected baseline subset of telemetry data to rapidly detect anomalies, selectively triggering the collection of additional data for further characterization, using advanced technologies like vectorized representations, multimodal ensemble inference, and multiresolution Random Cut Forest algorithms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If extensive telemetry data is collected for anomaly detection, then detection accuracy is improved, but storage and processing resources are strained

Engineering Contradiction:
Improvedetection accuracyVSAvoiddata volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent segments telemetry data collection into two phases: initial baseline data collection for model training and selective post-event data collection for anomaly investigation. This segmentation allows the system to collect only necessary data at appropriate times, reducing overall data volume while maintaining detection accuracy through targeted sampling and contextual filtering.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by establishing a baseline model from initial telemetry data before actual anomaly detection occurs. This baseline represents normal behavior patterns, allowing the system to detect anomalies without needing to collect and analyze all historical data, thus reducing storage requirements while maintaining detection precision.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If more data is collected for anomaly analysis, then detection reliability is improved, but processing time and real-time responsiveness are reduced

Engineering Contradiction:
Improvedetection reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary model training using baseline data in advance, creating anomaly detection models that can operate in real-time without requiring extensive data processing during actual detection events. This preliminary action enables fast, reliable anomaly detection by using pre-computed models rather than performing complex analysis in real-time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the data processing workflow into offline baseline analysis for model training and online real-time detection using the trained models. This segmentation separates computationally intensive tasks from real-time operations, maintaining detection reliability while enabling rapid response to anomalies.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If comprehensive telemetry collection is implemented, then detection coverage is improved, but system complexity and integration difficulty increase

Engineering Contradiction:
Improvedetection coverageVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by collecting and analyzing telemetry data selectively based on the specific anomaly type and context rather than uniformly across all data streams. This targeted approach maintains comprehensive detection coverage for relevant anomalies while reducing system complexity by avoiding unnecessary data collection and processing for irrelevant areas.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts data collection and analysis strategies based on detected anomaly types and contextual information. This dynamic adaptation allows the system to maintain broad detection coverage across different anomaly scenarios while managing complexity through context-aware filtering and selective processing rather than static comprehensive monitoring.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250379878A1Anomaly Detection via a Detect and Collect Approach
Publication Date: 2025.12.11 ZSCALER INC
  • US20250379878A1 patent drawing
  • US20250379878A1 patent drawing
  • US20250379878A1 patent drawing

AI summary

Systems and methods are disclosed for anomaly detection using a “detect and collect” cybersecurity monitoring approach. Initially, a cybersecurity monitoring system obtains and analyzes a baseline subset of telemetry data from computing resources to detect potential anomalies indicative of cybersecurity threats. Responsive to identifying such anomalies, the system selectively determines additional, contextually relevant telemetry data for targeted collection. This selective data collection significantly reduces telemetry volumes, enhancing efficiency and scalability. An intelligent data fabric and dynamic security knowledge graph are employed to enrich telemetry data in real-time, enabling comprehensive anomaly characterization, risk scoring, and automated security responses. The disclosed techniques support multimodal and multiresolution anomaly detection, adaptive learning, and rapid threat response within diverse distributed computing environments.