Fabric Controller for Multi-Cloud Security and Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Implementing a unified security perimeter and managing access to applications hosted on multiple cloud computing platforms is complex, especially when users access these applications from diverse locations globally, due to the difficulty in authenticating users coherently across diverse environments.
Innovation Solution
The solution involves creating edge clusters that operate as a cooperative fabric for providing authenticated access, using Kubernetes clusters managed by a Kubernetes master, and implementing a dashboard for configuring and monitoring these clusters across multiple cloud platforms, with a multi-cloud backbone for routing access requests and enforcing a unified security policy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a unified security perimeter is implemented across multiple cloud computing platforms, then enterprise security is improved, but system complexity increases
Solution Approach 1:
The patent introduces a fabric controller as an intermediary component that manages security policies across multiple cloud platforms. The fabric controller receives authentication requests, coordinates with authentication services, and enforces security policies without requiring direct integration between all cloud platforms, thereby simplifying the overall system architecture while maintaining unified security.
Solution Approach 2:
The fabric controller serves multiple functions including authentication request handling, security policy enforcement, and coordination with authentication services. This multi-functional approach consolidates security management capabilities into a single component, reducing the need for separate security mechanisms on each cloud platform and thereby reducing overall system complexity.
2Adaptability or versatility
If users access applications from diverse locations globally, then accessibility is improved, but authentication management becomes more difficult
Solution Approach 1:
The fabric controller acts as a central intermediary that handles authentication requests from users regardless of their geographic location. It coordinates with authentication services to verify user credentials and enforce security policies, providing a single point of management that simplifies authentication across diverse global locations without requiring location-specific authentication mechanisms.
3Productivity
If edge clusters are deployed across multiple cloud platforms, then access management efficiency is improved, but deployment complexity increases
Solution Approach 1:
The fabric controller serves as a central intermediary that manages Kubernetes clusters deployed across multiple cloud platforms. It provides a unified interface for deploying, configuring, and managing edge clusters, abstracting away the underlying cloud platform differences and thereby reducing deployment complexity while maintaining efficient access management across diverse cloud environments.
4Reliability
If a fabric controller coordinates authentication requests across multiple platforms, then authentication coherence is improved, but communication overhead increases
Solution Approach 1:
The fabric controller maintains continuous coordination with authentication services, establishing persistent communication channels and caching authentication states. This approach reduces the need for repeated full authentication cycles and minimizes communication overhead while maintaining authentication coherence across multiple cloud platforms throughout the session duration.
Data Source
AI summary
Segments of a network having connectivity issues are detected in a network environment that may include one or more cloud computing platforms. A mutual information algorithm is used to determine relevance of network element factors, a subset of factors are selected based on relevance, and clustered according to values for the subset of factors, and quality of the clusters evaluated. Various thresholds for selecting the subset of factors may be used to determine which provides improved cluster quality. An approach for performing root cause analysis of events in a network environment selects bad events for logging alerts based on whether a factor is found to distinguish bad events according to a mutual information algorithm. Events for alerts maybe aggregated based on temporal proximity or similarity. Visualization may be performed using Sankey diagrams with each column representing a factor.


