Monitoring Server Dynamic Kernel-Space Detection Under CPU Constraints
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing monitoring technologies struggle to perform dynamic monitoring at the kernel level in Operational Technology (OT) systems, particularly in older equipment with limited CPU processing power, due to high processing overhead and difficulty in maintaining steady operation.
Innovation Solution
A monitoring server apparatus that collects predetermined logs excluding kernel trace information, uses a model created in advance to monitor anomalies, and focuses on kernel space only when anomalies occur, reducing CPU load and ensuring stable operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If kernel trace information is collected continuously to monitor system state, then monitoring coverage of kernel-level issues is improved, but CPU processing overhead increases significantly
Solution Approach 1:
The patent segments the monitoring function into two distinct phases: a training phase where kernel trace information is collected and processed to build anomaly detection models, and an operation phase where only pre-processed log information is analyzed. This segmentation allows comprehensive kernel-level monitoring during training without imposing continuous high CPU overhead during operation, as the heavy kernel tracing is performed only when needed for model creation rather than continuous monitoring.
Solution Approach 2:
The patent applies preliminary action by collecting and processing kernel trace information in advance during a training phase to create anomaly detection models. Once the model is trained, the system can operate with reduced CPU overhead by using the pre-processed information and models for anomaly detection, rather than continuously performing heavy kernel tracing. This preliminary processing of kernel-level data enables future anomaly detection without real-time CPU burden.
2Measurement precision
If dynamic monitoring at kernel level is implemented, then detection of kernel failures and cyberattacks is improved, but system stability deteriorates due to high processing load
Solution Approach 1:
The patent divides the monitoring operation into segmentation: a training mode where comprehensive kernel trace collection and anomaly model creation occur, and an operation mode where lightweight anomaly detection using pre-processed logs is performed. This segmentation enables strong anomaly detection capability during training without compromising system stability during operation, as the heavy processing is confined to the training phase rather than continuously impacting system performance.
Solution Approach 2:
The patent implements dynamics by making the monitoring approach adaptable based on system state. The system can switch between training mode (for comprehensive monitoring and model creation) and operation mode (for lightweight anomaly detection). This dynamic adjustment allows the system to provide strong anomaly detection when needed while maintaining stability during normal operation, avoiding the fixed high overhead of continuous kernel-level monitoring.
3Productivity
If continuous kernel trace collection is performed, then real-time monitoring of system anomalies is improved, but device complexity increases
Solution Approach 1:
The patent segments the monitoring system into a training component that handles complex kernel trace collection and model creation, and an operation component that performs simpler anomaly detection using pre-processed information. This segmentation reduces the complexity of the ongoing monitoring system by separating the heavy computational tasks into a one-time training phase, leaving the operational system with simpler, more manageable components.
Solution Approach 2:
The patent applies preliminary action by performing complex kernel trace collection, feature extraction, and anomaly model creation in advance during training. This preliminary processing simplifies the operational monitoring system, as the heavy computational burden is completed beforehand, leaving only lightweight anomaly detection tasks for the operational phase. This reduces device complexity in the ongoing monitoring operation while maintaining real-time monitoring capability.
Data Source
AI summary
A monitoring server apparatus comprises an operation section configured to collect from monitored apparatuses predetermined logs excluding kernel trace information during operation, monitor an anomaly of the monitored apparatuses using a model created in advance, and perform dynamic monitoring by narrowing its focus to kernel space of a monitored apparatus having the anomaly when any anomaly has occurred.


