Cloud Activity Anomaly Detection Through Historical Behavior Baselines

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions lack the thoroughness and human resources needed to effectively detect suspicious cloud activity, posing a risk to enterprise data and user security in cloud-based systems.

Innovation Solution

A cloud-based system utilizing machine learning to analyze historical data, predict future activity patterns, and perform inline monitoring to detect anomalies, with a flexible anomaly score mechanism to rank activities based on risk, and provide real-time alerts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated tools are used to monitor cloud activities, then productivity is improved, but measurement precision deteriorates due to insufficient detection thoroughness

Engineering Contradiction:
Improveactivity monitoring efficiencyVSAvoidsuspicious activity detection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system implements feedback by continuously comparing monitored cloud activities against established baseline patterns and providing alerts when deviations are detected. This closed-loop approach allows automated monitoring to maintain high productivity while improving detection precision through continuous learning and adaptation to normal behavior patterns.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary anomaly detection system that sits between the cloud activities and the monitoring tools. This intermediary layer analyzes activities against learned patterns and only flags genuine anomalies, thereby maintaining high monitoring efficiency while significantly improving detection accuracy by filtering out false positives.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If more human resources are allocated to analyze cloud activity, then measurement precision is improved, but productivity deteriorates due to resource constraints

Engineering Contradiction:
Improveactivity analysis accuracyVSAvoidanalysis throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system segments the analysis task by automatically handling routine pattern recognition and anomaly detection, freeing human analysts to focus only on complex cases that require expert judgment. This segmentation maintains high analysis accuracy while improving overall throughput by parallelizing automated and human analysis capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The anomaly detection system performs self-service by automatically learning baseline patterns from historical data and autonomously detecting deviations without requiring continuous human intervention. This self-service capability maintains high detection precision while dramatically improving analysis throughput by eliminating manual review for routine cases.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If dedicated analysis tools are used, then measurement precision is improved, but device complexity increases

Engineering Contradiction:
Improvedetection thoroughnessVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a universal anomaly detection framework that can analyze multiple types of cloud activities across different services and platforms using the same core technology. This multi-functionality maintains high detection precision across diverse workloads while reducing overall system complexity by avoiding the need for separate specialized tools for each activity type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250301004A1Cloud Activity Anomaly Detection
Publication Date: 2025.09.25 ZSCALER INC
  • US20250301004A1 patent drawing
  • US20250301004A1 patent drawing
  • US20250301004A1 patent drawing

AI summary

Anomaly detection in cloud-based systems involves predicting identity behavior using historical activity data. Historical activities and their timestamps are analyzed to determine future intervals when activity is expected. Predictions are generated using weighted historical data emphasizing recent activity, and an anomaly score quantifying risk is calculated for each future interval based on deviation from expected behavior. Inline monitoring may detect and alert administrators or trigger automated responses to unexpected identity behavior. The method includes confidence scoring based on historical validation, visualization via graphical user interfaces, and lightweight, scalable computations suitable for monitoring extensive cloud deployments, enhancing both precision and efficiency in detecting suspicious cloud activity.