Fabric Controller for Multi-Cloud Security and Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Implementing a unified security perimeter and managing access to applications hosted on multiple cloud computing platforms is complex, especially when users access these applications from diverse locations globally, due to the difficulty in authenticating users coherently across diverse environments.

Innovation Solution

The solution involves creating edge clusters that operate as a cooperative fabric for providing authenticated access, using Kubernetes clusters managed by a Kubernetes master, and implementing a dashboard for configuring and monitoring these clusters across multiple cloud platforms, with a multi-cloud backbone for routing access requests and enforcing a unified security policy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a unified security perimeter is implemented across multiple cloud computing platforms, then enterprise security is improved, but system complexity increases

Engineering Contradiction:
Improveenterprise securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a fabric controller as an intermediary component that manages security policies across multiple cloud platforms. The fabric controller receives authentication requests, coordinates with authentication services, and enforces security policies without requiring direct integration between all cloud platforms, thereby simplifying the overall system architecture while maintaining unified security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The fabric controller serves multiple functions including authentication request handling, security policy enforcement, and coordination with authentication services. This multi-functional approach consolidates security management capabilities into a single component, reducing the need for separate security mechanisms on each cloud platform and thereby reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If users access applications from diverse locations globally, then accessibility is improved, but authentication management becomes more difficult

Engineering Contradiction:
Improveglobal accessibilityVSAvoidauthentication management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The fabric controller acts as a central intermediary that handles authentication requests from users regardless of their geographic location. It coordinates with authentication services to verify user credentials and enforce security policies, providing a single point of management that simplifies authentication across diverse global locations without requiring location-specific authentication mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If edge clusters are deployed across multiple cloud platforms, then access management efficiency is improved, but deployment complexity increases

Engineering Contradiction:
Improveaccess management efficiencyVSAvoiddeployment complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The fabric controller serves as a central intermediary that manages Kubernetes clusters deployed across multiple cloud platforms. It provides a unified interface for deploying, configuring, and managing edge clusters, abstracting away the underlying cloud platform differences and thereby reducing deployment complexity while maintaining efficient access management across diverse cloud environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If a fabric controller coordinates authentication requests across multiple platforms, then authentication coherence is improved, but communication overhead increases

Engineering Contradiction:
Improveauthentication coherenceVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The fabric controller maintains continuous coordination with authentication services, establishing persistent communication channels and caching authentication states. This approach reduces the need for repeated full authentication cycles and minimizes communication overhead while maintaining authentication coherence across multiple cloud platforms throughout the session duration.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS20230362178A1Detecting and Performing Root Cause Analysis for Anomalous Events
Publication Date: 2023.11.09 PALO ALTO NETWORKS INC
  • US20230362178A1 patent drawing
  • US20230362178A1 patent drawing
  • US20230362178A1 patent drawing

AI summary

Segments of a network having connectivity issues are detected in a network environment that may include one or more cloud computing platforms. A mutual information algorithm is used to determine relevance of network element factors, a subset of factors are selected based on relevance, and clustered according to values for the subset of factors, and quality of the clusters evaluated. Various thresholds for selecting the subset of factors may be used to determine which provides improved cluster quality. An approach for performing root cause analysis of events in a network environment selects bad events for logging alerts based on whether a factor is found to distinguish bad events according to a mutual information algorithm. Events for alerts maybe aggregated based on temporal proximity or similarity. Visualization may be performed using Sankey diagrams with each column representing a factor.