Cloud Agent Operations Adjustment for Real-Time Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems lack an efficient and scalable method for monitoring and detecting anomalies in cloud compute environments, particularly in datacenters, which are crucial for security, compliance, and operational efficiency, as they often rely on manual processes and lack real-time data analytics.
Innovation Solution
A data platform that integrates with cloud environments to collect and analyze data from agents deployed on compute assets, generating polygraphs to model behaviors and detect anomalies in real-time, using machine learning techniques to identify deviations from established baselines.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual monitoring processes are used in cloud environments, then device complexity is reduced, but productivity and real-time detection capability deteriorate
Solution Approach 1:
The system segments the monitoring function by deploying agents on individual compute assets to collect local data, separating the collection function from the centralized analysis function. This allows distributed real-time monitoring while keeping individual agent complexity low and enabling scalable deployment across the cloud environment.
Solution Approach 2:
The patent introduces an intermediary data collection and processing layer between compute assets and the central data platform. Agents act as intermediaries that locally collect, filter, and prepare data before transmission to the central platform, reducing network bandwidth requirements and enabling real-time local anomaly detection without requiring complex centralized processing for all data.
2Measurement precision
If comprehensive data collection is implemented, then measurement precision and anomaly detection accuracy improve, but loss of information and data management complexity worsen
Solution Approach 1:
The system implements partial data collection by focusing on specific data types and attributes relevant to anomaly detection rather than collecting all possible data. Agents collect only necessary metrics (CPU usage, memory, disk I/O, network connections) and filter data locally, avoiding unnecessary data transmission and storage while maintaining sufficient precision for detecting security anomalies and system failures.
Solution Approach 2:
The patent extracts and separates critical data collection functions from the central platform by placing intelligent agents on compute assets. These agents locally process and extract only the most relevant anomaly indicators, filtering out redundant information before transmission to the central data platform. This extraction approach reduces data volume while preserving detection accuracy by removing unnecessary data early in the pipeline.
3Reliability
If real-time monitoring is deployed, then reliability and security improvement worsen, but productivity and operational efficiency improve
Solution Approach 1:
The system implements periodic data collection and monitoring cycles rather than continuous real-time processing. Agents collect data at configured intervals and the central platform analyzes changes between periods, enabling reliable anomaly detection while reducing processing overhead. This periodic approach allows the system to maintain security monitoring without continuously consuming significant computational resources, thereby preserving operational efficiency.
Data Source
AI summary
An illustrative data platform is disclosed that may receive, from an agent deployed in a cloud compute environment monitored by the data platform, data the agent has collected within the cloud compute environment in accordance with an agent operations ruleset. The data platform may determine, based on the data the agent has collected, an operational adjustment to the agent operations ruleset. Accordingly, the data platform may then direct the agent to implement the operational adjustment to the agent operations ruleset for use as the agent continues collecting data within the cloud compute environment in accordance with the agent operations ruleset. Corresponding methods, systems, and products are also disclosed.


