Computing Event Anomaly Detection for Cloud Access Breach Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Identifying cybersecurity events, particularly in large enterprises with shared cloud datacenters, is challenging due to sophisticated attacks that often go unnoticed when there are no login failures, and existing monitoring systems struggle to detect breaches when bad actors gain access to virtual servers.

Innovation Solution

Anomaly detection systems process time series data from system events to identify unusual access patterns by transforming event logs into a time series dataset, using machine learning models to detect anomalies and generate alerts for potential security breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional monitoring systems are used to detect security events, then login failures can be detected, but breaches without login failures cannot be identified

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces traditional rule-based monitoring systems with machine learning models that analyze time series data from system events. These models detect anomalies in user behavior patterns, file access sequences, and system operation timelines without relying on predefined login failure rules, thereby identifying breaches that traditional systems miss.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system transforms security event detection from binary login success/failure parameters to continuous time series parameters including event timestamps, user behavior patterns, access frequencies, and sequence anomalies. This parameter transformation enables detection of subtle breach indicators that don't trigger traditional alerts.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If cloud datacenters share physical hardware among multiple enterprises, then resource utilization improves, but security breach vectors increase

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity breach vectors
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary anomaly detection layer between the shared physical infrastructure and multiple enterprises. This layer collects and analyzes system events from virtual servers across different enterprises, identifying breaches that exploit shared hardware vulnerabilities without requiring direct access to physical server details.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The monitoring system is designed to universally collect and analyze system events from multiple virtual servers and enterprises sharing the same physical infrastructure. The machine learning models generalize breach detection patterns across different enterprise environments, providing comprehensive security coverage for cloud datacenter scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If sophisticated attacks are used by bad actors, then attack effectiveness increases, but detectability by traditional systems decreases

Engineering Contradiction:
Improveattack success rateVSAvoidbreach detectability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system implements continuous feedback loops where machine learning models are trained on historical system events and anomaly patterns. The models continuously learn from new data, adapting to evolving attack techniques by identifying novel anomaly patterns in user behavior, access sequences, and system operations that deviate from established baselines.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent establishes baseline behavior patterns and normal operation profiles before attacks occur. By pre-training models on legitimate user behaviors and system operations, the system can detect subtle deviations caused by sophisticated attacks, identifying breaches before they cause significant damage even when attackers avoid traditional indicators.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12476991B2Anomaly detection in computing system events
Publication Date: 2025.11.18 CAPITAL ONE SERVICES LLC
  • US12476991B2 patent drawing
  • US12476991B2 patent drawing
  • US12476991B2 patent drawing

AI summary

Methods and systems are described herein for detecting anomalous access to system resources. An anomaly detection system may access system events from one or more computing devices and may generate entries from the system events. Each entry may include a corresponding timestamp indicating a time when a corresponding system event occurred, a corresponding user identifier indicating a user account within a computing environment associated with the corresponding system event, a corresponding location identifier indicating a location within the computing environment, and a corresponding action identifier indicating an action that the user account performed with respect to the location or an object within the computing environment. The generated entries may be aggregated and input into an anomaly detection model to obtain anomalous activity identified by the model.