Guided Anomaly Detection Framework for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data analytics platforms face challenges in efficiently monitoring and detecting anomalies in cloud environments, particularly in datacenters, due to the complexity of network activities and the need for real-time data processing and security monitoring.

Innovation Solution

A data platform is configured to ingest data from cloud environments, process it in real-time, and generate polygraphs to model normal behaviors, allowing for the detection of deviations and anomalies through a guided anomaly detection framework.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If real-time data processing is implemented to detect anomalies, then detection speed is improved, but system complexity increases

Engineering Contradiction:
Improveanomaly detection speedVSAvoiddata processing system complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The system segments the anomaly detection process into distinct modules: data ingestion, polygraph generation, behavior modeling, and anomaly detection. Each module handles specific tasks independently, allowing real-time processing while maintaining manageable complexity through modular architecture

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces polygraphs as an intermediary data structure that simplifies the relationship between raw data and anomaly detection. Polygraphs serve as a mediator that transforms complex network data into manageable behavioral models, reducing the complexity of real-time analysis while maintaining detection speed

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive security monitoring is implemented, then detection precision is improved, but processing time increases

Engineering Contradiction:
Improveanomaly detection precisionVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary action by continuously generating and updating polygraphs that model normal behavior patterns. These pre-computed behavioral models serve as reference frameworks that enable rapid anomaly detection without requiring time-consuming analysis during actual threat detection, thus maintaining both precision and speed

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If network activity complexity is increased to model detailed behaviors, then detection precision is improved, but device complexity increases

Engineering Contradiction:
Improvebehavior modeling precisionVSAvoiddata platform complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a universal polygraph data structure that serves multiple functions: it models normal behavior, detects anomalies, identifies patterns, and provides detection rules. This multi-functional approach allows detailed behavior modeling without proportionally increasing system complexity, as the same underlying structure supports multiple detection needs

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11770398B1Guided anomaly detection framework
Publication Date: 2023.09.26 FORTINET INC
  • US11770398B1 patent drawing
  • US11770398B1 patent drawing
  • US11770398B1 patent drawing

AI summary

A guided anomaly detection framework, including: gathering data describing activity associated with an anomaly detection framework monitoring a cloud deployment; generating, based on the data, a prompt describing one or more natural language inputs for a security workflow, wherein each of the one or more natural language inputs corresponds to a query for information related to the cloud deployment; and providing a selected natural language input to a natural language interface.