Cloud Connection Direction Inference for Real-Time Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems lack effective methods for monitoring and managing network activities within cloud environments to detect anomalies and ensure data security, compliance, and asset management efficiently.
Innovation Solution
A data platform that integrates data ingestion, processing, and user interface resources to monitor and analyze network activities across cloud environments, utilizing agents to collect and report data, and generate polygraphs to identify anomalies and deviations from baseline activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If agents collect and report detailed network activity data from cloud environments, then anomaly detection capability is improved, but data volume and processing complexity increase
Solution Approach 1:
The patent extracts only the necessary connection direction information (source IP, destination IP, direction) from the full network activity data collected by agents. This selective extraction reduces the data volume to be processed while maintaining the ability to detect anomalies in cloud environment connectivity patterns.
Solution Approach 2:
The patent introduces a data processing layer that acts as an intermediary between agent data collection and anomaly detection. This intermediate processing layer filters, aggregates, and prepares connection data in a standardized format, reducing complexity before the data reaches the detection algorithms.
2Reliability
If the system monitors all network connections in cloud environments, then security coverage is improved, but system complexity and resource consumption increase
Solution Approach 1:
The patent segments the monitoring function into distributed agents deployed across individual cloud environments. Each agent independently collects connection data locally, then transmits only relevant information to the central processing system. This segmentation maintains comprehensive security coverage while reducing the complexity burden on any single component.
Solution Approach 2:
The patent implements partial monitoring by focusing on connection direction data rather than all possible network parameters. This selective monitoring approach provides sufficient security coverage for anomaly detection while consuming fewer system resources and maintaining lower complexity levels.
3Speed
If connection data is processed in real-time, then anomaly detection speed is improved, but processing resources and computational load increase
Solution Approach 1:
The patent performs preliminary processing actions at the agent level by immediately filtering and formatting connection data upon collection. This preliminary action reduces the volume of data that requires processing at the central system, enabling faster anomaly detection while reducing overall computational load requirements.
Solution Approach 2:
The patent implements periodic processing cycles where connection data is collected, processed, and analyzed in regular intervals rather than continuously. This periodic approach maintains real-time detection capability for critical anomalies while significantly reducing peak processing resource consumption compared to continuous monitoring and analysis.
Data Source
AI summary
An example method includes obtaining, by an agent deployed on a resource in a cloud environment, a data packet indicating a source port and a destination port and for which a direction of a connection between the source port and the destination port is unknown; searching, by the agent, a cache for at least one of the source port or the destination port; and assigning, by the agent and based on information associated with at least one of the source port or the destination port in the cache, the direction of the connection between the source port and the destination port.


