Unified Event Stream Storage for Real-Time Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in efficiently managing and analyzing event streams for anomaly detection across diverse compute assets in cloud and non-cloud environments, particularly in terms of data ingestion, processing, and unified storage, which hinders real-time anomaly detection and response.

Innovation Solution

A data platform is implemented to ingest, process, and store event data from compute assets using agents that collect and report information, with data processing resources performing real-time anomaly detection and user interface resources providing results, while utilizing a unified storage system for event streams.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If event streams are stored in multiple separate databases for different compute assets, then each database can be optimized for its specific asset type, but the system complexity increases and unified anomaly detection becomes difficult

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidstorage system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges event streams from multiple compute assets into a single unified storage system. The storage system receives event streams from various compute assets (virtual machines, containers, physical servers) and stores them in a centralized location, enabling unified anomaly detection across all assets without requiring separate optimized databases for each asset type.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified storage system is designed to handle multiple types of event streams from different compute asset types using a single storage mechanism. The system can store, manage, and query event data from virtual machines, containers, and physical servers uniformly, eliminating the need for multiple specialized storage systems while maintaining detection accuracy across diverse environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Speed

If real-time processing of event streams is implemented, then anomaly detection speed improves, but data processing resources and computational overhead increase

Engineering Contradiction:
Improveanomaly detection speedVSAvoiddata processing power
Core Design Contradiction:
SpeedVSPower

Solution Approach 1:

The system performs preliminary actions by storing event streams in a unified structure that is pre-organized for efficient querying and analysis. The event streams are normalized and stored with appropriate indexing before anomaly detection is needed, so that when anomalies are detected, the data is already in the optimal format for rapid processing, reducing the computational overhead during real-time analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The unified storage system acts as an intermediary between event stream ingestion and anomaly detection processing. It receives raw event streams from various compute assets, normalizes and stores them in a standardized format, and provides efficiently queryable data to the anomaly detection system, thereby reducing the processing burden on real-time analysis while maintaining fast detection speeds.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If comprehensive monitoring of all compute assets is implemented, then security and compliance coverage improve, but data ingestion and processing volume increases

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoiddata volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system segments the monitoring function by compute asset type (virtual machines, containers, physical servers) while maintaining a unified storage structure. Each asset type's event streams are collected separately during ingestion but are stored in a standardized unified format, allowing comprehensive coverage of all asset types without creating separate storage systems that would increase overall data volume management complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12381901B1Unified storage for event streams in an anomaly detection framework
Publication Date: 2025.08.05 FORTINET INC
  • US12381901B1 patent drawing
  • US12381901B1 patent drawing
  • US12381901B1 patent drawing

AI summary

Providing unified storage for event streams in an anomaly detection framework, including: receiving, by an event streaming platform, first event data encoded in a first file format; converting, by the event streaming platform, the first event data into second event data encoded in a second file format for storage in a first remote storage system; and providing, to the first remote storage system, a command to load the second event data into the first remote storage system.