Security Issue Time-Series Tracking Across Computing Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems lack an efficient and comprehensive method to track and relate security issues over time across diverse computing environments, including cloud and non-cloud settings, which hinders effective security monitoring and anomaly detection.
Innovation Solution
A data platform is implemented to monitor and analyze data from compute assets using agents that collect and report information, generating polygraphs and graphs to identify anomalies and security threats, with data processing resources performing real-time analytics and user interface resources providing insights to users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing systems are used to monitor security issues, then basic monitoring is possible, but tracking and relating security issues over time across diverse computing environments is inefficient and comprehensive monitoring is lacking
Solution Approach 1:
The system segments the monitoring function by deploying agents across diverse computing environments (cloud and non-cloud) to collect local security data, then aggregates this segmented data at centralized processing resources. This allows comprehensive monitoring while maintaining efficiency through distributed data collection.
Solution Approach 2:
The patent introduces a temporal dimension to security monitoring by tracking security issues over time and relating them across different environments. The system maintains historical context and temporal relationships between security events, transforming static monitoring into dynamic, time-aware analysis that improves both reliability and productivity.
2Adaptability or versatility
If comprehensive monitoring across diverse computing environments is implemented, then security coverage is improved, but system complexity increases
Solution Approach 1:
The system employs universal agents that can operate across diverse computing environments (cloud and non-cloud) with a single unified architecture. These multi-functional agents handle various monitoring tasks consistently across different platforms, achieving broad environment coverage without proportionally increasing system complexity.
Solution Approach 2:
Agents serve as intermediary components between the diverse computing environments and the centralized data processing resources. These intermediaries abstract the complexity of different environments, collecting and normalizing data in a standardized format that simplifies downstream processing while maintaining comprehensive environment coverage.
3Speed
If real-time analytics are performed, then anomaly detection speed is improved, but data processing requirements and computational resources increase
Solution Approach 1:
The computational workload is segmented between distributed agents performing local real-time analytics and centralized processing resources handling aggregate analysis. This division allows fast local anomaly detection while reducing the computational burden on any single component, balancing speed requirements with resource consumption.
Solution Approach 2:
The system performs partial real-time analytics at the agent level, processing only the most critical security events locally while deferring less time-sensitive analysis to centralized resources. This selective approach maintains adequate anomaly detection speed while significantly reducing overall computational resource requirements.
Data Source
AI summary
Tracking and relating discovered security issues over time, including: identifying, based on a static code analysis scan of a non-executable representation of an application, a vulnerability in the application; gathering information describing one or more events associated with the vulnerability in the application; and generating, based on the information, a time-series analysis of the vulnerability.


