Cloud Deployment Configuration via Cross-Deployment Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data analytics platforms face challenges in efficiently monitoring and detecting anomalies within cloud environments, particularly in large-scale datacenter settings, where identifying malicious activities or misconfigurations among normal elastic resource use is difficult due to the complexity and dynamic nature of virtualized servers.
Innovation Solution
A data platform is configured to ingest data from cloud environments, process it for anomaly detection, and generate polygraphs to model normal behavior, allowing for real-time identification of deviations from established baselines, using agents deployed on compute assets to collect and report data, and microservices for data aggregation and analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional monitoring approaches are used in cloud environments, then infrastructure cost and complexity are reduced, but anomaly detection capability and false alarm rate deteriorate
Solution Approach 1:
The patent introduces a data platform as an intermediary layer between cloud compute assets and security analysis systems. This platform collects operational data from multiple cloud accounts, normalizes it into a unified schema, and makes it available for security analysis without requiring complex integration between individual cloud providers' monitoring systems. The intermediary handles the complexity of multi-cloud data aggregation while presenting simplified interfaces to consumers.
2Measurement precision
If comprehensive monitoring of all cloud resources is implemented, then anomaly detection accuracy is improved, but data volume and processing complexity increase
Solution Approach 1:
The patent extracts and isolates security-relevant operational data from the broader cloud infrastructure monitoring data. By focusing collection on specific data elements that are most indicative of security anomalies (such as user authentication events, resource creation patterns, and access control changes), the system achieves high detection accuracy without processing the entire volume of cloud operational data. This selective extraction approach maintains precision while managing data quantity.
Solution Approach 2:
The system segments the monitoring function into separate components: data collection from cloud accounts, data normalization and enrichment, security analysis, and alert generation. This segmentation allows each component to process and handle specific portions of data independently, improving overall efficiency and reducing the processing burden on any single system element while maintaining comprehensive monitoring capability.
3Speed
If real-time monitoring of dynamic cloud resources is performed, then threat detection speed is improved, but system stability and false alarms increase
Solution Approach 1:
The patent implements preliminary actions by establishing baseline behavior patterns for cloud resources during normal operation before security incidents occur. The system continuously learns and updates what constitutes normal behavior for each resource type and configuration, creating a reference framework that enables rapid and accurate anomaly detection. When deviations from these pre-established baselines are detected, the system can confidently identify true anomalies rather than generating false alarms, while maintaining real-time response capability.
Data Source
AI summary
Configuring cloud deployments based on learnings obtained by monitoring other cloud deployments, including: determining normal behavior for one or more components in a first cloud deployment; determining normal behavior for one or more components in one or more other cloud deployments; and recommending, based on the normal behavior for one or more components in one or more other cloud deployments, a change to the first cloud deployment.


