Cloud Agent Operations Adjustment for Real-Time Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack an efficient and scalable method for monitoring and detecting anomalies in cloud compute environments, particularly in datacenters, which are crucial for security, compliance, and operational efficiency, as they often rely on manual processes and lack real-time data analytics.

Innovation Solution

A data platform that integrates with cloud environments to collect and analyze data from agents deployed on compute assets, generating polygraphs to model behaviors and detect anomalies in real-time, using machine learning techniques to identify deviations from established baselines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual monitoring processes are used in cloud environments, then device complexity is reduced, but productivity and real-time detection capability deteriorate

Engineering Contradiction:
Improvereal-time anomaly detection capabilityVSAvoiddata collection and analysis system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments the monitoring function by deploying agents on individual compute assets to collect local data, separating the collection function from the centralized analysis function. This allows distributed real-time monitoring while keeping individual agent complexity low and enabling scalable deployment across the cloud environment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary data collection and processing layer between compute assets and the central data platform. Agents act as intermediaries that locally collect, filter, and prepare data before transmission to the central platform, reducing network bandwidth requirements and enabling real-time local anomaly detection without requiring complex centralized processing for all data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive data collection is implemented, then measurement precision and anomaly detection accuracy improve, but loss of information and data management complexity worsen

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoiddata management overhead and redundancy
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The system implements partial data collection by focusing on specific data types and attributes relevant to anomaly detection rather than collecting all possible data. Agents collect only necessary metrics (CPU usage, memory, disk I/O, network connections) and filter data locally, avoiding unnecessary data transmission and storage while maintaining sufficient precision for detecting security anomalies and system failures.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent extracts and separates critical data collection functions from the central platform by placing intelligent agents on compute assets. These agents locally process and extract only the most relevant anomaly indicators, filtering out redundant information before transmission to the central data platform. This extraction approach reduces data volume while preserving detection accuracy by removing unnecessary data early in the pipeline.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If real-time monitoring is deployed, then reliability and security improvement worsen, but productivity and operational efficiency improve

Engineering Contradiction:
Improvesecurity and compliance assuranceVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements periodic data collection and monitoring cycles rather than continuous real-time processing. Agents collect data at configured intervals and the central platform analyzes changes between periods, enabling reliable anomaly detection while reducing processing overhead. This periodic approach allows the system to maintain security monitoring without continuously consuming significant computational resources, thereby preserving operational efficiency.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS12363148B1Operational adjustment for an agent collecting data from a cloud compute environment monitored by a data platform
Publication Date: 2025.07.15 FORTINET INC
  • US12363148B1 patent drawing
  • US12363148B1 patent drawing
  • US12363148B1 patent drawing

AI summary

An illustrative data platform is disclosed that may receive, from an agent deployed in a cloud compute environment monitored by the data platform, data the agent has collected within the cloud compute environment in accordance with an agent operations ruleset. The data platform may determine, based on the data the agent has collected, an operational adjustment to the agent operations ruleset. Accordingly, the data platform may then direct the agent to implement the operational adjustment to the agent operations ruleset for use as the agent continues collecting data within the cloud compute environment in accordance with the agent operations ruleset. Corresponding methods, systems, and products are also disclosed.