Interactive Security Threat Analysis Across Compute Assets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems struggle to effectively detect and analyze multifaceted security threats within complex compute environments, such as cloud environments, due to the sheer volume and variety of data generated, which often leads to missed anomalies and inefficiencies in security monitoring and response.

Innovation Solution

A data platform is implemented to ingest, process, and present composite events indicative of multifaceted security threats, utilizing agents to collect data from compute assets, perform data security monitoring, and provide real-time anomaly detection and remediation services, with user interface resources for interactive analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive security monitoring is implemented across complex compute environments, then detection capability is improved, but system complexity and data volume increase

Engineering Contradiction:
Improvesecurity threat detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments security monitoring into multiple specialized agents (compute agent, network agent, storage agent) that operate independently on different compute assets. Each agent handles specific monitoring tasks locally, reducing the complexity burden on any single system component while enabling comprehensive coverage across the entire compute environment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The data lake serves as an intermediary layer between the various security agents and the analysis system. It collects, stores, and pre-processes security data from multiple sources before analysis, decoupling the complexity of data collection from the analysis process and enabling scalable monitoring without proportionally increasing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If real-time security analysis is performed on all collected data, then response time is improved, but processing resources and computational complexity increase

Engineering Contradiction:
Improvesecurity response timeVSAvoidcomputational resources
Core Design Contradiction:
Loss of timeVSPower

Solution Approach 1:

The system performs preliminary data processing and feature extraction at the agent level before data reaches the central analysis system. Agents locally filter, aggregate, and prepare security events, performing computationally intensive tasks upstream. This reduces the volume and complexity of data requiring real-time analysis centrally, enabling faster response without proportionally increasing computational resources.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies selective real-time analysis only to high-priority security events and critical compute assets, while using batch processing for less critical data. This partial real-time approach maintains fast response for most security incidents while reducing overall computational burden compared to universal real-time processing of all data.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If detailed security data is collected from all compute assets, then analysis precision is improved, but data volume and storage requirements increase

Engineering Contradiction:
Improvesecurity anomaly detection precisionVSAvoiddata volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system collects and stores security data with varying levels of detail depending on the specific compute asset and its security risk profile. Critical assets receive comprehensive monitoring with high precision, while less critical assets receive standardized monitoring. This local quality approach maintains high detection precision where needed while reducing overall data volume.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The data lake extracts and stores only the essential security-relevant features and events from raw compute data, filtering out redundant information. By taking out only the critical security attributes (such as user actions, resource access patterns, and anomaly indicators) rather than all possible data, the system maintains analysis precision while significantly reducing data volume and storage requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12500910B1Interactive analysis of multifaceted security threats within a compute environment
Publication Date: 2025.12.16 FORTINET INC
  • US12500910B1 patent drawing
  • US12500910B1 patent drawing
  • US12500910B1 patent drawing

AI summary

Data platforms described herein are configured to monitor a compute environment and facilitate interactive analysis of multifaceted security threats within the compute environment. Such a data platform may determine that one or more assets within the compute environment are possibly being targeted by a multifaceted security threat and present an interactive user interface. The user interface may be configured to display an identifier indicative of the multifaceted security threat, a set of selectable evidence items each associated with a different facet of the multifaceted security threat and assessed based on the monitoring of the compute environment, and a presentation pane for displaying information. As such, the data platform may detect a selection of a particular evidence item from the set of selectable evidence items and, in response to the selection, populate the presentation pane with information related to the particular evidence item. Corresponding methods, systems, and products are also disclosed.