Cloud Agent Data Collection Triggered by Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data collection systems in cloud environments lack efficient and secure mechanisms for anomaly detection and management of compute assets, leading to potential security breaches and compliance issues.

Innovation Solution

A data platform with agents deployed on compute assets that monitor and report activities, using polygraphs to analyze behaviors and detect anomalies, integrated with data ingestion, processing, and user interface resources for real-time anomaly detection and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If continuous data collection is performed to monitor all compute asset activities, then anomaly detection capability is improved, but data processing load and system complexity increase

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoiddata processing load
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by collecting and storing baseline data representing normal compute asset behavior patterns. This baseline data is used to train anomaly detection models that can identify deviations from normal behavior, enabling effective anomaly detection without requiring continuous processing of all data in real-time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system extracts only the relevant features and patterns from the collected data that are necessary for anomaly detection. By extracting key behavioral characteristics and normal patterns, the system reduces the processing load while maintaining the ability to detect anomalies effectively.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If comprehensive monitoring of compute assets is implemented, then security and compliance are improved, but operational overhead and resource consumption increase

Engineering Contradiction:
Improvesecurity and compliance monitoringVSAvoidoperational overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The compute assets themselves perform self-monitoring and self-reporting of their activities to the central system. The agents deployed on compute assets automatically collect, process, and transmit only relevant security and compliance data, reducing the operational overhead compared to centralized manual monitoring while maintaining comprehensive security monitoring.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements localized monitoring at each compute asset level with agents that independently collect and filter data based on local security and compliance requirements. This distributed approach reduces the operational overhead at the central system while maintaining comprehensive monitoring coverage.

Inventive Principle:
Principle #3Local quality

3Speed

If real-time data processing is performed for immediate anomaly detection, then response time to breaches is improved, but system resources and processing power are consumed

Engineering Contradiction:
Improveresponse time to breachesVSAvoidprocessing power consumption
Core Design Contradiction:
SpeedVSPower

Solution Approach 1:

The system performs preliminary processing by collecting and storing baseline behavioral data in advance. Anomaly detection models are trained on this pre-processed data, enabling rapid identification of anomalies when they occur without requiring intensive real-time processing, thus reducing processing power consumption while maintaining fast response time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates simplified representations and models of compute asset behaviors from collected data. These behavioral models serve as copies that can be quickly compared against actual activities to detect anomalies, reducing the processing power required for real-time analysis while maintaining fast detection capability.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12513221B1Anomaly-based on-demand collection of data by an agent for a data platform
Publication Date: 2025.12.30 FORTINET INC
  • US12513221B1 patent drawing
  • US12513221B1 patent drawing
  • US12513221B1 patent drawing

AI summary

An illustrative data platform may receive, from an agent configuration deployed in a cloud environment and configured to monitor compute assets in the cloud environment, first data periodically collected by the agent configuration at a first collection frequency and second data periodically collected by the agent configuration at a second collection frequency, identify, based on the first data, an anomaly associated with one or more compute assets included in the compute assets, and direct, based on the identifying the anomaly, the agent configuration to perform an on-demand collection of the second data.