Monitoring Server Dynamic Kernel-Space Detection Under CPU Constraints

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing monitoring technologies struggle to perform dynamic monitoring at the kernel level in Operational Technology (OT) systems, particularly in older equipment with limited CPU processing power, due to high processing overhead and difficulty in maintaining steady operation.

Innovation Solution

A monitoring server apparatus that collects predetermined logs excluding kernel trace information, uses a model created in advance to monitor anomalies, and focuses on kernel space only when anomalies occur, reducing CPU load and ensuring stable operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If kernel trace information is collected continuously to monitor system state, then monitoring coverage of kernel-level issues is improved, but CPU processing overhead increases significantly

Engineering Contradiction:
Improvemonitoring coverageVSAvoidCPU processing overhead
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The patent segments the monitoring function into two distinct phases: a training phase where kernel trace information is collected and processed to build anomaly detection models, and an operation phase where only pre-processed log information is analyzed. This segmentation allows comprehensive kernel-level monitoring during training without imposing continuous high CPU overhead during operation, as the heavy kernel tracing is performed only when needed for model creation rather than continuous monitoring.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by collecting and processing kernel trace information in advance during a training phase to create anomaly detection models. Once the model is trained, the system can operate with reduced CPU overhead by using the pre-processed information and models for anomaly detection, rather than continuously performing heavy kernel tracing. This preliminary processing of kernel-level data enables future anomaly detection without real-time CPU burden.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If dynamic monitoring at kernel level is implemented, then detection of kernel failures and cyberattacks is improved, but system stability deteriorates due to high processing load

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidsystem stability
Core Design Contradiction:
Measurement precisionVSStability of the object's composition

Solution Approach 1:

The patent divides the monitoring operation into segmentation: a training mode where comprehensive kernel trace collection and anomaly model creation occur, and an operation mode where lightweight anomaly detection using pre-processed logs is performed. This segmentation enables strong anomaly detection capability during training without compromising system stability during operation, as the heavy processing is confined to the training phase rather than continuously impacting system performance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamics by making the monitoring approach adaptable based on system state. The system can switch between training mode (for comprehensive monitoring and model creation) and operation mode (for lightweight anomaly detection). This dynamic adjustment allows the system to provide strong anomaly detection when needed while maintaining stability during normal operation, avoiding the fixed high overhead of continuous kernel-level monitoring.

Inventive Principle:
Principle #15Dynamics

3Productivity

If continuous kernel trace collection is performed, then real-time monitoring of system anomalies is improved, but device complexity increases

Engineering Contradiction:
Improvereal-time monitoring capabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the monitoring system into a training component that handles complex kernel trace collection and model creation, and an operation component that performs simpler anomaly detection using pre-processed information. This segmentation reduces the complexity of the ongoing monitoring system by separating the heavy computational tasks into a one-time training phase, leaving the operational system with simpler, more manageable components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by performing complex kernel trace collection, feature extraction, and anomaly model creation in advance during training. This preliminary processing simplifies the operational monitoring system, as the heavy computational burden is completed beforehand, leaving only lightweight anomaly detection tasks for the operational phase. This reduces device complexity in the ongoing monitoring operation while maintaining real-time monitoring capability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250217482A1Monitoring server apparatus, system, method, and program
Publication Date: 2025.07.03 NEC CORP
  • US20250217482A1 patent drawing
  • US20250217482A1 patent drawing
  • US20250217482A1 patent drawing

AI summary

A monitoring server apparatus comprises an operation section configured to collect from monitored apparatuses predetermined logs excluding kernel trace information during operation, monitor an anomaly of the monitored apparatuses using a model created in advance, and perform dynamic monitoring by narrowing its focus to kernel space of a monitored apparatus having the anomaly when any anomaly has occurred.