Grouping Compute Resources for Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In service provider environments, detecting and addressing anomalies in computing resources is challenging due to the complexity and size of configurations, which can lead to security issues such as malware and advanced persistent threats, making it difficult to ensure authorized access and security of computing devices and data.

Innovation Solution

An anomaly service is implemented that identifies groups of similar compute resources by collecting and comparing attributes, determining differences in attribute values, and reporting anomalies to enable remediation or automatic correction, thereby enhancing security and reducing the impact of potential intrusions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtualization technologies are used to share computing resources among multiple users, then resource utilization efficiency and scalability are improved, but system complexity and security management difficulty increase

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the complex virtualized environment into groups of compute resources based on shared attributes (hypervisor, machine image, configuration). This segmentation simplifies monitoring and anomaly detection by breaking down the large-scale complex system into manageable groups that can be analyzed independently while maintaining overall system efficiency.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If the size and complexity of computing configurations grow to manage diverse customer needs, then service scalability and versatility are improved, but security management and anomaly detection become more difficult

Engineering Contradiction:
Improveservice scalabilityVSAvoidanomaly detection difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent performs preliminary grouping of compute resources based on shared attributes before anomaly detection. By pre-organizing resources into groups with similar characteristics, the system establishes a baseline structure that simplifies subsequent anomaly detection, making it easier to identify deviations without being overwhelmed by system complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter of resource organization from individual isolated monitoring to group-based monitoring with shared attributes. This parameter change enables the system to handle scalability while reducing detection difficulty by comparing resources within groups rather than analyzing each resource independently across the entire complex system.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive monitoring of all compute resources is implemented to detect security threats, then security reliability is improved, but computational overhead and processing time increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the monitoring task by grouping compute resources that share common attributes. Instead of monitoring each resource individually, the system monitors groups collectively, reducing the total number of comparisons needed while maintaining comprehensive security coverage across all resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges the monitoring of multiple compute resources by identifying and analyzing shared attributes across groups. This combining approach allows the system to detect anomalies that affect multiple resources simultaneously while reducing redundant processing, thereby improving security reliability without proportionally increasing processing time.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11050768B1Detecting compute resource anomalies in a group of computing resources
Publication Date: 2021.06.29 AMAZON TECH INC
  • US11050768B1 patent drawing
  • US11050768B1 patent drawing
  • US11050768B1 patent drawing

AI summary

A computing anomaly detection technique includes identifying a plurality of compute resources that are susceptible to compute resource anomalies. A group of similar compute resources from the plurality of compute resources may be determined. A difference in one or more of a plurality of attributes of the compute resources of the group may be determined. An anomaly detection notification, containing a compute resource anomaly, may be output.