Edge Event Scoring for Real-Time Cloud Anomaly Alerts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems lack an efficient and comprehensive method for monitoring and analyzing data from cloud environments to detect anomalies and ensure data security, compliance, and asset management in real-time.
Innovation Solution
An edge-based data platform that integrates data ingestion, processing, and user interface resources to monitor and analyze data from cloud environments, utilizing agents to collect data and generate polygraphs for anomaly detection and security monitoring, with data processing resources performing real-time analytics and user interface resources providing insights.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If agents continuously collect and transmit all data from cloud environments to the data platform, then comprehensive monitoring and anomaly detection capability is improved, but network bandwidth consumption and data processing load increase
Solution Approach 1:
The patent extracts only the essential event information (polygraph data) from the continuous data stream collected by agents. Instead of transmitting all raw data, the system extracts and transmits only the scored event information that meets detection criteria, reducing network bandwidth consumption while maintaining monitoring effectiveness
Solution Approach 2:
The data platform performs preliminary scoring and filtering of events using machine learning models before full analysis. Events are pre-sorted by severity and relevance, allowing the system to prioritize transmission and processing of only the most critical events, thereby reducing overall data transfer requirements
2Speed
If the data platform processes and analyzes all collected data in real-time, then anomaly detection speed is improved, but computational resources and processing time increase
Solution Approach 1:
The patent segments the data processing workflow into distinct stages: data collection by agents, preliminary scoring at the edge, and detailed analysis at the central platform. This segmentation allows real-time processing of only critical events while deferring less urgent analysis to appropriate time windows, reducing peak computational demands
Solution Approach 2:
The system dynamically adjusts processing parameters based on event severity and detected anomalies. High-severity events trigger immediate full-processing, while low-severity events are processed asynchronously or batched, optimizing computational resource allocation while maintaining rapid response to critical issues
3Loss of information
If the system transmits and stores all raw event data for comprehensive analysis, then data completeness is improved, but data management complexity and storage requirements increase
Solution Approach 1:
The patent extracts only the necessary event attributes and scored information for storage and analysis, discarding redundant raw data. The system stores condensed polygraph representations and event summaries rather than complete event streams, reducing storage requirements while preserving essential information for anomaly detection
Solution Approach 2:
The system performs preliminary data transformation and structuring at the edge before transmission to the central platform. Events are pre-formatted into standardized polygraph structures with scored priorities, simplifying downstream data management and reducing the complexity of processing and storing raw event data
Data Source
AI summary
Scoring of events in an edge-based data platform, including: detecting an event associated with a plurality of entities and an event type; calculating, based on a prevalence of each entity in events of the event type and a classification of each entity, a risk score for the event; and generating an alert based on the risk score for the event.


