Virtual Asset Pattern Correlation with External Events
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security threat detection mechanisms in computing systems often require human intervention to evaluate anomalous operational characteristics, leading to service disruptions, as they struggle to correlate data patterns from virtual assets with external events effectively.
Innovation Solution
A method and system that correlate virtual asset patterns with external events by maintaining an external events library, allowing self-monitoring and self-healing virtual assets to recognize and respond to deviations in operational patterns without human intervention by mapping detected patterns to corresponding external events.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If computing systems use traditional security threat detection mechanisms comparing communications traffic to digital signatures, then known security threats can be detected, but anomalous operational characteristics that do not match known patterns cannot be automatically resolved and require human intervention
Solution Approach 1:
The system enables virtual assets to self-monitor their operational characteristics and automatically correlate detected anomalies with external event data from multiple sources. The virtual assets autonomously determine whether anomalies result from security threats or external events, eliminating the need for human intervention in resolving anomalous characteristics.
Solution Approach 2:
The system introduces an intermediary correlation mechanism that bridges virtual asset operational data with external event information. This intermediary layer automatically matches anomalies against known external events (such as weather conditions, sports events, or holidays) to provide explanations for deviations without requiring human analysis.
2Reliability
If computing systems cease operations to await human evaluation of anomalous operational characteristics, then security threats can be investigated, but service continuity is disrupted and productivity decreases
Solution Approach 1:
Virtual assets automatically investigate and resolve anomalous operational characteristics by correlating their data with external event information. The system self-determines whether anomalies indicate security threats requiring investigation or external events causing temporary deviations, enabling continuous operation without human intervention.
Solution Approach 2:
The system performs preliminary correlation of operational characteristics with external event data before ceasing operations or requiring human intervention. By pre-establishing relationships between virtual asset metrics and external events, the system can immediately identify and explain anomalies, maintaining service continuity.
3Speed
If computing systems monitor operational characteristics without correlating external events, then real-time detection is maintained, but false-positive alerts increase and measurement precision decreases
Solution Approach 1:
The system introduces external event data as an intermediary context layer that enriches real-time operational monitoring. By correlating detected anomalies with current external event information, the system distinguishes between genuine security threats and expected variations caused by external factors, improving measurement precision without sacrificing detection speed.
Solution Approach 2:
The system continuously feeds external event information back into the monitoring process to refine anomaly detection. This feedback mechanism allows real-time correlation of operational characteristics with current external conditions, enabling the system to adjust its detection precision dynamically based on contextual information.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method and system for correlating patterns of operating virtual assets with external events includes receiving an identification of one of the external events, from one or more electronic sources, and receiving first patterns from one or more first virtual assets, according to one embodiment. The method and system include populating a database with the first patterns and the identification of the one of the external events to map the one of the external events to the first patterns, according to one embodiment. The method and system include receiving second patterns from one or more second virtual assets, and comparing the second patterns to the first patterns, according to one embodiment. The method and system include distributing the identification of the one of the external events to the one or more second virtual assets, if the second patterns are similar to the first patterns, according to one embodiment.