Virtual Asset Pattern Correlation with External Events

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security threat detection mechanisms in computing systems often require human intervention to evaluate anomalous operational characteristics, leading to service disruptions, as they struggle to correlate data patterns from virtual assets with external events effectively.

Innovation Solution

A method and system that correlate virtual asset patterns with external events by maintaining an external events library, allowing self-monitoring and self-healing virtual assets to recognize and respond to deviations in operational patterns without human intervention by mapping detected patterns to corresponding external events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If computing systems use traditional security threat detection mechanisms comparing communications traffic to digital signatures, then known security threats can be detected, but anomalous operational characteristics that do not match known patterns cannot be automatically resolved and require human intervention

Engineering Contradiction:
Improvesecurity threat detection accuracyVSAvoidautomatic resolution of anomalous characteristics
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The system enables virtual assets to self-monitor their operational characteristics and automatically correlate detected anomalies with external event data from multiple sources. The virtual assets autonomously determine whether anomalies result from security threats or external events, eliminating the need for human intervention in resolving anomalous characteristics.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system introduces an intermediary correlation mechanism that bridges virtual asset operational data with external event information. This intermediary layer automatically matches anomalies against known external events (such as weather conditions, sports events, or holidays) to provide explanations for deviations without requiring human analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If computing systems cease operations to await human evaluation of anomalous operational characteristics, then security threats can be investigated, but service continuity is disrupted and productivity decreases

Engineering Contradiction:
Improvesecurity threat investigation capabilityVSAvoidservice continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Virtual assets automatically investigate and resolve anomalous operational characteristics by correlating their data with external event information. The system self-determines whether anomalies indicate security threats requiring investigation or external events causing temporary deviations, enabling continuous operation without human intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary correlation of operational characteristics with external event data before ceasing operations or requiring human intervention. By pre-establishing relationships between virtual asset metrics and external events, the system can immediately identify and explain anomalies, maintaining service continuity.

Inventive Principle:
Principle #10Preliminary action

3Speed

If computing systems monitor operational characteristics without correlating external events, then real-time detection is maintained, but false-positive alerts increase and measurement precision decreases

Engineering Contradiction:
Improvereal-time detection speedVSAvoidaccuracy of anomaly detection
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The system introduces external event data as an intermediary context layer that enriches real-time operational monitoring. By correlating detected anomalies with current external event information, the system distinguishes between genuine security threats and expected variations caused by external factors, improving measurement precision without sacrificing detection speed.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system continuously feeds external event information back into the monitoring process to refine anomaly detection. This feedback mechanism allows real-time correlation of operational characteristics with current external conditions, enabling the system to adjust its detection precision dynamically based on contextual information.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3175431B1Method and system for correlating self-reporting virtual asset data with external events to generate an external event identification database
Publication Date: 2020.09.02 INTUIT INC
  • EP3175431B1 patent drawingFigure 1
  • EP3175431B1 patent drawingFigure 2
  • EP3175431B1 patent drawingFigure 3

AI summary

A method and system for correlating patterns of operating virtual assets with external events includes receiving an identification of one of the external events, from one or more electronic sources, and receiving first patterns from one or more first virtual assets, according to one embodiment. The method and system include populating a database with the first patterns and the identification of the one of the external events to map the one of the external events to the first patterns, according to one embodiment. The method and system include receiving second patterns from one or more second virtual assets, and comparing the second patterns to the first patterns, according to one embodiment. The method and system include distributing the identification of the one of the external events to the one or more second virtual assets, if the second patterns are similar to the first patterns, according to one embodiment.