Pod Communication Anomaly Detection in Virtualized Data Centers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The virtualization of computing resources in data centers makes it difficult to detect and mitigate intruders and nefarious activities effectively.

Innovation Solution

Implementing agents on nodes within data centers to collect and report data, using a platform to create polygraphs that model datacenter activities, detect anomalies, and score deviations from expected behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtualization is implemented to provide efficient scalability and redundancy, then resource utilization and system availability are improved, but the ability to detect and mitigate intruders deteriorates

Engineering Contradiction:
Improveresource utilizationVSAvoidintruder detection capability
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces communication polygraphs as intermediary monitoring systems that observe and analyze communication patterns between virtualized components without interfering with their operation. These polygraphs serve as mediators that detect anomalies in pod-to-pod communication, enabling intruder detection while preserving the benefits of virtualization.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The monitoring system is segmented into multiple specialized polygraphs, each responsible for specific aspects of communication monitoring (e.g., pod identity verification, communication pattern analysis, anomaly detection). This segmentation allows comprehensive surveillance of virtualized environments without creating a single complex monitoring bottleneck.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If traditional monitoring methods are used in virtualized environments, then system complexity is reduced, but detection precision of malicious activities deteriorates

Engineering Contradiction:
Improvemonitoring system complexityVSAvoidmalicious activity detection precision
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The communication polygraphs implement continuous feedback loops where detected communication patterns are analyzed, compared against expected behavior, and used to generate alerts or adjust monitoring parameters. This feedback mechanism enables precise detection of malicious activities while maintaining manageable system complexity through automated response protocols.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12505126B1Pod communication alerting
Publication Date: 2025.12.23 FORTINET INC
  • US12505126B1 patent drawing
  • US12505126B1 patent drawing
  • US12505126B1 patent drawing

AI summary

An illustrative method includes accessing log data associated with one or more resources in a network environment; detecting, based on the log data, an anomaly associated with a communication made from a first pod instance to a second pod instance within the network environment; and generating an alert that the anomaly associated with the communication made from the first pod instance to the second pod instance has occurred.