Computing Event Anomaly Detection for Cloud Access Breach Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Identifying cybersecurity events, particularly in large enterprises with shared cloud datacenters, is challenging due to sophisticated attacks that often go unnoticed when there are no login failures, and existing monitoring systems struggle to detect breaches when bad actors gain access to virtual servers.
Innovation Solution
Anomaly detection systems process time series data from system events to identify unusual access patterns by transforming event logs into a time series dataset, using machine learning models to detect anomalies and generate alerts for potential security breaches.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional monitoring systems are used to detect security events, then login failures can be detected, but breaches without login failures cannot be identified
Solution Approach 1:
The patent replaces traditional rule-based monitoring systems with machine learning models that analyze time series data from system events. These models detect anomalies in user behavior patterns, file access sequences, and system operation timelines without relying on predefined login failure rules, thereby identifying breaches that traditional systems miss.
Solution Approach 2:
The system transforms security event detection from binary login success/failure parameters to continuous time series parameters including event timestamps, user behavior patterns, access frequencies, and sequence anomalies. This parameter transformation enables detection of subtle breach indicators that don't trigger traditional alerts.
2Productivity
If cloud datacenters share physical hardware among multiple enterprises, then resource utilization improves, but security breach vectors increase
Solution Approach 1:
The patent introduces an intermediary anomaly detection layer between the shared physical infrastructure and multiple enterprises. This layer collects and analyzes system events from virtual servers across different enterprises, identifying breaches that exploit shared hardware vulnerabilities without requiring direct access to physical server details.
Solution Approach 2:
The monitoring system is designed to universally collect and analyze system events from multiple virtual servers and enterprises sharing the same physical infrastructure. The machine learning models generalize breach detection patterns across different enterprise environments, providing comprehensive security coverage for cloud datacenter scenarios.
3Reliability
If sophisticated attacks are used by bad actors, then attack effectiveness increases, but detectability by traditional systems decreases
Solution Approach 1:
The system implements continuous feedback loops where machine learning models are trained on historical system events and anomaly patterns. The models continuously learn from new data, adapting to evolving attack techniques by identifying novel anomaly patterns in user behavior, access sequences, and system operations that deviate from established baselines.
Solution Approach 2:
The patent establishes baseline behavior patterns and normal operation profiles before attacks occur. By pre-training models on legitimate user behaviors and system operations, the system can detect subtle deviations caused by sophisticated attacks, identifying breaches before they cause significant damage even when attackers avoid traditional indicators.
Data Source
AI summary
Methods and systems are described herein for detecting anomalous access to system resources. An anomaly detection system may access system events from one or more computing devices and may generate entries from the system events. Each entry may include a corresponding timestamp indicating a time when a corresponding system event occurred, a corresponding user identifier indicating a user account within a computing environment associated with the corresponding system event, a corresponding location identifier indicating a location within the computing environment, and a corresponding action identifier indicating an action that the user account performed with respect to the location or an object within the computing environment. The generated entries may be aggregated and input into an anomaly detection model to obtain anomalous activity identified by the model.


