Edge Event Scoring for Real-Time Cloud Anomaly Alerts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack an efficient and comprehensive method for monitoring and analyzing data from cloud environments to detect anomalies and ensure data security, compliance, and asset management in real-time.

Innovation Solution

An edge-based data platform that integrates data ingestion, processing, and user interface resources to monitor and analyze data from cloud environments, utilizing agents to collect data and generate polygraphs for anomaly detection and security monitoring, with data processing resources performing real-time analytics and user interface resources providing insights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If agents continuously collect and transmit all data from cloud environments to the data platform, then comprehensive monitoring and anomaly detection capability is improved, but network bandwidth consumption and data processing load increase

Engineering Contradiction:
Improvemonitoring capabilityVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts only the essential event information (polygraph data) from the continuous data stream collected by agents. Instead of transmitting all raw data, the system extracts and transmits only the scored event information that meets detection criteria, reducing network bandwidth consumption while maintaining monitoring effectiveness

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The data platform performs preliminary scoring and filtering of events using machine learning models before full analysis. Events are pre-sorted by severity and relevance, allowing the system to prioritize transmission and processing of only the most critical events, thereby reducing overall data transfer requirements

Inventive Principle:
Principle #10Preliminary action

2Speed

If the data platform processes and analyzes all collected data in real-time, then anomaly detection speed is improved, but computational resources and processing time increase

Engineering Contradiction:
Improveanomaly detection speedVSAvoidcomputational resources
Core Design Contradiction:
SpeedVSPower

Solution Approach 1:

The patent segments the data processing workflow into distinct stages: data collection by agents, preliminary scoring at the edge, and detailed analysis at the central platform. This segmentation allows real-time processing of only critical events while deferring less urgent analysis to appropriate time windows, reducing peak computational demands

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts processing parameters based on event severity and detected anomalies. High-severity events trigger immediate full-processing, while low-severity events are processed asynchronously or batched, optimizing computational resource allocation while maintaining rapid response to critical issues

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If the system transmits and stores all raw event data for comprehensive analysis, then data completeness is improved, but data management complexity and storage requirements increase

Engineering Contradiction:
Improvedata completenessVSAvoiddata management complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent extracts only the necessary event attributes and scored information for storage and analysis, discarding redundant raw data. The system stores condensed polygraph representations and event summaries rather than complete event streams, reducing storage requirements while preserving essential information for anomaly detection

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary data transformation and structuring at the edge before transmission to the central platform. Events are pre-formatted into standardized polygraph structures with scored priorities, simplifying downstream data management and reducing the complexity of processing and storing raw event data

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12580935B1Scoring of events in an edge-based data platform
Publication Date: 2026.03.17 FORTINET INC
  • US12580935B1 patent drawing
  • US12580935B1 patent drawing
  • US12580935B1 patent drawing

AI summary

Scoring of events in an edge-based data platform, including: detecting an event associated with a plurality of entities and an event type; calculating, based on a prevalence of each entity in events of the event type and a classification of each entity, a risk score for the event; and generating an alert based on the risk score for the event.