Cloud Deployment Configuration via Cross-Deployment Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data analytics platforms face challenges in efficiently monitoring and detecting anomalies within cloud environments, particularly in large-scale datacenter settings, where identifying malicious activities or misconfigurations among normal elastic resource use is difficult due to the complexity and dynamic nature of virtualized servers.

Innovation Solution

A data platform is configured to ingest data from cloud environments, process it for anomaly detection, and generate polygraphs to model normal behavior, allowing for real-time identification of deviations from established baselines, using agents deployed on compute assets to collect and report data, and microservices for data aggregation and analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional monitoring approaches are used in cloud environments, then infrastructure cost and complexity are reduced, but anomaly detection capability and false alarm rate deteriorate

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a data platform as an intermediary layer between cloud compute assets and security analysis systems. This platform collects operational data from multiple cloud accounts, normalizes it into a unified schema, and makes it available for security analysis without requiring complex integration between individual cloud providers' monitoring systems. The intermediary handles the complexity of multi-cloud data aggregation while presenting simplified interfaces to consumers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive monitoring of all cloud resources is implemented, then anomaly detection accuracy is improved, but data volume and processing complexity increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoiddata volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts and isolates security-relevant operational data from the broader cloud infrastructure monitoring data. By focusing collection on specific data elements that are most indicative of security anomalies (such as user authentication events, resource creation patterns, and access control changes), the system achieves high detection accuracy without processing the entire volume of cloud operational data. This selective extraction approach maintains precision while managing data quantity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system segments the monitoring function into separate components: data collection from cloud accounts, data normalization and enrichment, security analysis, and alert generation. This segmentation allows each component to process and handle specific portions of data independently, improving overall efficiency and reducing the processing burden on any single system element while maintaining comprehensive monitoring capability.

Inventive Principle:
Principle #1Segmentation

3Speed

If real-time monitoring of dynamic cloud resources is performed, then threat detection speed is improved, but system stability and false alarms increase

Engineering Contradiction:
Improvethreat detection speedVSAvoidfalse alarm rate
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent implements preliminary actions by establishing baseline behavior patterns for cloud resources during normal operation before security incidents occur. The system continuously learns and updates what constitutes normal behavior for each resource type and configuration, creating a reference framework that enables rapid and accurate anomaly detection. When deviations from these pre-established baselines are detected, the system can confidently identify true anomalies rather than generating false alarms, while maintaining real-time response capability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11894984B2Configuring cloud deployments based on learnings obtained by monitoring other cloud deployments
Publication Date: 2024.02.06 FORTINET INC
  • US11894984B2 patent drawing
  • US11894984B2 patent drawing
  • US11894984B2 patent drawing

AI summary

Configuring cloud deployments based on learnings obtained by monitoring other cloud deployments, including: determining normal behavior for one or more components in a first cloud deployment; determining normal behavior for one or more components in one or more other cloud deployments; and recommending, based on the normal behavior for one or more components in one or more other cloud deployments, a change to the first cloud deployment.