Grouping Compute Resources for Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In service provider environments, detecting and addressing anomalies in computing resources is challenging due to the complexity and size of configurations, which can lead to security issues such as malware and advanced persistent threats, making it difficult to ensure authorized access and security of computing devices and data.
Innovation Solution
An anomaly service is implemented that identifies groups of similar compute resources by collecting and comparing attributes, determining differences in attribute values, and reporting anomalies to enable remediation or automatic correction, thereby enhancing security and reducing the impact of potential intrusions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If virtualization technologies are used to share computing resources among multiple users, then resource utilization efficiency and scalability are improved, but system complexity and security management difficulty increase
Solution Approach 1:
The patent segments the complex virtualized environment into groups of compute resources based on shared attributes (hypervisor, machine image, configuration). This segmentation simplifies monitoring and anomaly detection by breaking down the large-scale complex system into manageable groups that can be analyzed independently while maintaining overall system efficiency.
2Adaptability or versatility
If the size and complexity of computing configurations grow to manage diverse customer needs, then service scalability and versatility are improved, but security management and anomaly detection become more difficult
Solution Approach 1:
The patent performs preliminary grouping of compute resources based on shared attributes before anomaly detection. By pre-organizing resources into groups with similar characteristics, the system establishes a baseline structure that simplifies subsequent anomaly detection, making it easier to identify deviations without being overwhelmed by system complexity.
Solution Approach 2:
The patent changes the parameter of resource organization from individual isolated monitoring to group-based monitoring with shared attributes. This parameter change enables the system to handle scalability while reducing detection difficulty by comparing resources within groups rather than analyzing each resource independently across the entire complex system.
3Reliability
If comprehensive monitoring of all compute resources is implemented to detect security threats, then security reliability is improved, but computational overhead and processing time increase
Solution Approach 1:
The patent segments the monitoring task by grouping compute resources that share common attributes. Instead of monitoring each resource individually, the system monitors groups collectively, reducing the total number of comparisons needed while maintaining comprehensive security coverage across all resources.
Solution Approach 2:
The patent merges the monitoring of multiple compute resources by identifying and analyzing shared attributes across groups. This combining approach allows the system to detect anomalies that affect multiple resources simultaneously while reducing redundant processing, thereby improving security reliability without proportionally increasing processing time.
Data Source
AI summary
A computing anomaly detection technique includes identifying a plurality of compute resources that are susceptible to compute resource anomalies. A group of similar compute resources from the plurality of compute resources may be determined. A difference in one or more of a plurality of attributes of the compute resources of the group may be determined. An anomaly detection notification, containing a compute resource anomaly, may be output.


