Systems and methods for multivariate anomaly detection in software monitoring
US-2020351283-A1 · Nov 5, 2020 · US
US11775654B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11775654-B2 |
| Application number | US-202017120333-A |
| Country | US |
| Kind code | B2 |
| Filing date | Dec 14, 2020 |
| Priority date | Dec 14, 2020 |
| Publication date | Oct 3, 2023 |
| Grant date | Oct 3, 2023 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Examples described herein provide a computer-implemented method that includes detecting an anomaly associated with an object of a computer system and determining an importance classification of the object. An object relationship of the object is determined with respect to one or more other objects of the computer system. An impact score of the anomaly is determined based on the importance classification and the object relationship. An anomaly report is output with the impact score.
Opening claim text (preview).
What is claimed is: 1. A computer-implemented method comprising: analyzing a plurality of jobs configured to execute on a computer system; determining one or more objects associated with execution of the jobs; constructing a relationship graph comprising a plurality of nodes that link the jobs with the one or more objects; detecting an anomaly associated with an object of the computer system; determining an importance classification of the object; determining an object relationship of the object with respect to one or more other objects of the computer system based on the relationship graph; determining an impact score of the anomaly based on the importance classification and the object relationship; and outputting an anomaly report with the impact score. 2. The computer-implemented method of claim 1 , wherein determining the object relationship of the object with respect to the one or more other objects of the computer system comprises analyzing the relationship graph to identify dependencies between the jobs and the one or more objects. 3. The computer-implemented method of claim 1 , wherein the impact score is based on a combination of a historical relationship and a current value of the object relationship. 4. The computer-implemented method of claim 1 , wherein the impact score distinguishes between multiple levels of priority comprising: a high priority, a discretionary priority, and an unknown priority. 5. The computer-implemented method of claim 1 , wherein the impact score is based on one or more user-defined rules. 6. A system comprising: a memory comprising computer readable instructions; and a processing device for executing the computer readable instructions, the computer readable instructions controlling the processing device to perform operations comprising: analyzing a plurality of jobs configured to execute on a computer system; determining one or more objects associated with execution of the jobs; constructing a relationship graph comprising a plurality of nodes that link the jobs with the one or more objects; detecting an anomaly associated with an object of the computer system; determining an importance classification of the object; determining an object relationship of the object with respect to one or more other objects of the computer system based on the relationship graph; determining an impact score of the anomaly based on the importance classification and the object relationship; and outputting an anomaly report with the impact score. 7. The system of claim 6 , wherein determining the object relationship of the object with respect to the one or more other objects of the computer system comprises analyzing the graph to identify dependencies between the jobs and the one or more objects. 8. The system of claim 6 , wherein the impact score is based on a combination of a historical relationship and a current value of the object relationship. 9. The system of claim 6 , wherein the impact score distinguishes between multiple levels of priority comprising: a high priority, a discretionary priority, and an unknown priority. 10. The system of claim 6 , wherein the impact score is based on one or more user-defined rules. 11. A computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a processor to cause the processor to perform operations comprising: analyzing a plurality of jobs configured to execute on a computer system; determining one or more objects associated with execution of the jobs; constructing a relationship graph comprising a plurality of nodes that link the jobs with the one or more objects; detecting an anomaly associated with an object of the computer system; determining an importance classification of the object; determining an object relationship of the object with respect to one or more other objects of the computer system based on the relationship graph; determining an impact score an impact score of the anomaly based on the importance classification and the object relationship; and outputting an anomaly report with the impact score. 12. The computer program product of claim 11 , wherein determining the object relationship of the object with respect to the one or more other objects of the computer system comprises analyzing the relationship graph to identify dependencies between the jobs and the one or more objects. 13. The computer program product of claim 11 , wherein the impact score is based on a combination of a historical relationship and a current value of the object relationship, and the impact score distinguishes between multiple levels of priority comprising: a high priority, a discretionary priority, and an unknown priority. 14. The computer program product of claim 11 , wherein the impact score is based on one or more user-defined rules. 15. The computer-implemented method of claim 1 , further comprising: determining whether the impact score exceeds a threshold; and causing an action to be taken to remedy the anomaly associated with the impact score that exceeds the threshold. 16. The system of claim 6 , wherein the computer readable instructions controlling the processing device are configured to perform operations comprising: determining whether the impact score exceeds a threshold; and causing an action to be taken to remedy the anomaly associated with the impact score that exceeds the threshold. 17. The computer program product of claim 11 , wherein the program instructions are executable by the processor to cause the processor to perform operations comprising: determining whether the impact score exceeds a threshold; and causing an action to be taken to remedy the anomaly associated with the impact score that exceeds the threshold.
Assessing vulnerabilities and evaluating computer system security · CPC title
Scheduling strategies for dispatcher, e.g. round robin, multi-level priority queues · CPC title
Graphs; Linked lists (G06F16/9027 takes precedence) · CPC title
involving event detection and direct action · CPC title
Error or fault detection not based on redundancy (power supply failures G06F1/30; network fault management H04L41/06) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.