Cloud Resource Activity Log Vectors for Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The transition from on-premises networks to cloud-native environments has increased the complexity of cyber security, with massive amounts of log data requiring effective anomaly detection methods to identify anomalous resource behavior.

Innovation Solution

A cloud-based system that collects resource activity data, aggregates it into vector form, determines event probabilities, and calculates anomaly scores based on historical data to detect and alert on suspicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cloud environments are utilized to facilitate business operations, then productivity and business capability are improved, but cyber security complexity and risk increase due to massive log data and anomalous resource behavior

Engineering Contradiction:
Improvebusiness capabilityVSAvoidcyber security complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces an anomaly detection system as an intermediary layer between cloud resources and security monitoring. This system collects resource activity data, transforms it into vector representations, and applies machine learning models to detect anomalous behavior. The intermediary processing layer simplifies security monitoring by automatically analyzing patterns and flagging deviations, thereby reducing the complexity of cyber security management while maintaining productivity benefits of cloud environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If resource activity data is collected and analyzed for anomaly detection, then security detection accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-processing resource activity data into vector representations and establishing baseline behavioral patterns before actual security threats occur. The system continuously learns normal resource behavior patterns and stores them for comparison. When anomalies need to be detected, the system compares current activity against pre-established baselines, significantly reducing processing time while maintaining high detection accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional mechanical rule-based security systems with machine learning-based anomaly detection. Instead of manually configuring security rules, the system uses machine learning models to automatically learn resource behavior patterns and detect deviations. This substitution reduces processing time by enabling automated pattern recognition and eliminates the need for manual rule updates, thereby improving both accuracy and efficiency.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If behavioral baseline measurements are created for all resources, then anomaly detection capability is improved, but system complexity and data processing requirements increase

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by transforming resource activity data into vector representations with specific dimensional characteristics. The system converts complex, unstructured log data into standardized vector formats that capture essential behavioral parameters. This parameter transformation simplifies the creation of behavioral baselines by reducing data complexity while preserving meaningful patterns, thereby improving anomaly detection capability without proportionally increasing system complexity.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements segmentation by dividing resource activity monitoring into distinct components: data collection, vector transformation, baseline creation, and anomaly detection. Each component processes specific aspects of resource behavior independently. This segmentation allows the system to manage complexity by handling different aspects of anomaly detection separately, improving reliability through specialized processing while keeping overall system architecture manageable.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12353309B2Systems and methods for anomaly detection on resource activity logs
Publication Date: 2025.07.08 ZSCALER INC
  • US12353309B2 patent drawing
  • US12353309B2 patent drawing
  • US12353309B2 patent drawing

AI summary

The present disclosure includes systems and methods for anomaly detection on resource activity logs. Various embodiments include collecting resource activity data from a plurality of resources in a cloud environment, the resource activity data including information related to a plurality of events associated with the plurality of resources in the cloud environment; aggregating and performing one or more calculations on the resource activity data to represent the plurality of resources in vector form; determining a probability of a sequence of events to be executed by a resource of the plurality of resources based on the vector form of the resource; and determining an anomaly score for the sequence of events being executed by the resource based on the probability.