Data Platform Community Policy Generation for Cloud Anomaly Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security and analytics systems struggle to efficiently monitor and manage large-scale cloud environments, lacking effective tools for real-time anomaly detection and compliance monitoring across diverse compute assets.

Innovation Solution

A data platform that integrates data ingestion, processing, and user interface resources to monitor and manage cloud environments, utilizing agents to collect data from compute assets and generate polygraphs for anomaly detection and compliance monitoring, with community-based policy generation for customized analytics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing data security and analytics systems are used to monitor cloud environments, then basic monitoring capabilities are provided, but real-time anomaly detection and compliance monitoring across diverse compute assets cannot be effectively achieved

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidmonitoring efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments the monitoring function by deploying agents on individual compute assets to collect local data, then aggregates this data at centralized processing components. This segmentation enables distributed real-time monitoring across diverse compute assets while maintaining centralized control for anomaly detection and compliance monitoring, resolving the contradiction between reliability and productivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces polygraphs as intermediary data structures that normalize and represent computed asset data in a unified format. These polygraphs serve as mediators between diverse compute assets and the analysis system, enabling effective real-time anomaly detection and compliance monitoring across heterogeneous environments without requiring system redesign.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If centralized monitoring systems are used, then compliance monitoring is simplified, but real-time anomaly detection across diverse compute assets becomes inefficient

Engineering Contradiction:
Improvecompliance monitoringVSAvoidanomaly detection speed
Core Design Contradiction:
Ease of operationVSSpeed

Solution Approach 1:

The system divides monitoring into two segments: local agents on compute assets that perform real-time data collection and preliminary processing, and centralized components that handle compliance monitoring. This segmentation enables fast local anomaly detection while maintaining simplified centralized compliance oversight, resolving the contradiction between ease of operation and speed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Agents perform preliminary actions by collecting and pre-processing data locally at compute assets before transmitting to centralized systems. This preliminary action reduces the volume of data requiring centralized processing, enabling both fast local anomaly detection and simplified compliance monitoring through aggregated, pre-processed information.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If customized analytics policies are implemented for each compute asset, then adaptability to diverse environments improves, but system complexity increases

Engineering Contradiction:
Improvepolicy customizationVSAvoidsystem configuration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal policy framework where compute asset owners can define customized analytics policies using a standardized polygraph-based language. This universal interface allows diverse compute assets to have asset-specific policies while using the same underlying processing mechanisms, improving adaptability without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses template-based policy definitions where common monitoring patterns can be copied and reused across different compute assets. This copying mechanism enables rapid customization for diverse environments while avoiding the complexity of creating unique policies from scratch, as templates can be instantiated and adapted as needed.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12407701B1Community-based generation of policies for a data platform
Publication Date: 2025.09.02 FORTINET INC
  • US12407701B1 patent drawing
  • US12407701B1 patent drawing
  • US12407701B1 patent drawing

AI summary

A disclosed data platform may be configured to access a custom policy developed by a particular client entity that uses the data platform. The custom policy may invoke a query that targets a target dataset ingested from a cloud environment and stored in a data store. The data platform may determine that the custom policy is likely to be of value to one or more other client entities, besides the particular client entity, that also use the data platform. In response to the determining that the custom policy is likely to be of value to the one or more other client entities, the data platform may generate a community policy based on the custom policy. The community policy may be available for use by the one or more other client entities. Corresponding methods, systems, and products are also disclosed.