Anomaly detection with impact assessment

US11775654B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11775654-B2
Application numberUS-202017120333-A
CountryUS
Kind codeB2
Filing dateDec 14, 2020
Priority dateDec 14, 2020
Publication dateOct 3, 2023
Grant dateOct 3, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Examples described herein provide a computer-implemented method that includes detecting an anomaly associated with an object of a computer system and determining an importance classification of the object. An object relationship of the object is determined with respect to one or more other objects of the computer system. An impact score of the anomaly is determined based on the importance classification and the object relationship. An anomaly report is output with the impact score.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method comprising: analyzing a plurality of jobs configured to execute on a computer system; determining one or more objects associated with execution of the jobs; constructing a relationship graph comprising a plurality of nodes that link the jobs with the one or more objects; detecting an anomaly associated with an object of the computer system; determining an importance classification of the object; determining an object relationship of the object with respect to one or more other objects of the computer system based on the relationship graph; determining an impact score of the anomaly based on the importance classification and the object relationship; and outputting an anomaly report with the impact score. 2. The computer-implemented method of claim 1 , wherein determining the object relationship of the object with respect to the one or more other objects of the computer system comprises analyzing the relationship graph to identify dependencies between the jobs and the one or more objects. 3. The computer-implemented method of claim 1 , wherein the impact score is based on a combination of a historical relationship and a current value of the object relationship. 4. The computer-implemented method of claim 1 , wherein the impact score distinguishes between multiple levels of priority comprising: a high priority, a discretionary priority, and an unknown priority. 5. The computer-implemented method of claim 1 , wherein the impact score is based on one or more user-defined rules. 6. A system comprising: a memory comprising computer readable instructions; and a processing device for executing the computer readable instructions, the computer readable instructions controlling the processing device to perform operations comprising: analyzing a plurality of jobs configured to execute on a computer system; determining one or more objects associated with execution of the jobs; constructing a relationship graph comprising a plurality of nodes that link the jobs with the one or more objects; detecting an anomaly associated with an object of the computer system; determining an importance classification of the object; determining an object relationship of the object with respect to one or more other objects of the computer system based on the relationship graph; determining an impact score of the anomaly based on the importance classification and the object relationship; and outputting an anomaly report with the impact score. 7. The system of claim 6 , wherein determining the object relationship of the object with respect to the one or more other objects of the computer system comprises analyzing the graph to identify dependencies between the jobs and the one or more objects. 8. The system of claim 6 , wherein the impact score is based on a combination of a historical relationship and a current value of the object relationship. 9. The system of claim 6 , wherein the impact score distinguishes between multiple levels of priority comprising: a high priority, a discretionary priority, and an unknown priority. 10. The system of claim 6 , wherein the impact score is based on one or more user-defined rules. 11. A computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a processor to cause the processor to perform operations comprising: analyzing a plurality of jobs configured to execute on a computer system; determining one or more objects associated with execution of the jobs; constructing a relationship graph comprising a plurality of nodes that link the jobs with the one or more objects; detecting an anomaly associated with an object of the computer system; determining an importance classification of the object; determining an object relationship of the object with respect to one or more other objects of the computer system based on the relationship graph; determining an impact score an impact score of the anomaly based on the importance classification and the object relationship; and outputting an anomaly report with the impact score. 12. The computer program product of claim 11 , wherein determining the object relationship of the object with respect to the one or more other objects of the computer system comprises analyzing the relationship graph to identify dependencies between the jobs and the one or more objects. 13. The computer program product of claim 11 , wherein the impact score is based on a combination of a historical relationship and a current value of the object relationship, and the impact score distinguishes between multiple levels of priority comprising: a high priority, a discretionary priority, and an unknown priority. 14. The computer program product of claim 11 , wherein the impact score is based on one or more user-defined rules. 15. The computer-implemented method of claim 1 , further comprising: determining whether the impact score exceeds a threshold; and causing an action to be taken to remedy the anomaly associated with the impact score that exceeds the threshold. 16. The system of claim 6 , wherein the computer readable instructions controlling the processing device are configured to perform operations comprising: determining whether the impact score exceeds a threshold; and causing an action to be taken to remedy the anomaly associated with the impact score that exceeds the threshold. 17. The computer program product of claim 11 , wherein the program instructions are executable by the processor to cause the processor to perform operations comprising: determining whether the impact score exceeds a threshold; and causing an action to be taken to remedy the anomaly associated with the impact score that exceeds the threshold.

Assignees

Inventors

Classifications

  • G06F21/577Primary

    Assessing vulnerabilities and evaluating computer system security · CPC title

  • Scheduling strategies for dispatcher, e.g. round robin, multi-level priority queues · CPC title

  • Graphs; Linked lists (G06F16/9027 takes precedence) · CPC title

  • G06F21/554Primary

    involving event detection and direct action · CPC title

  • Error or fault detection not based on redundancy (power supply failures G06F1/30; network fault management H04L41/06) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11775654B2 cover?
Examples described herein provide a computer-implemented method that includes detecting an anomaly associated with an object of a computer system and determining an importance classification of the object. An object relationship of the object is determined with respect to one or more other objects of the computer system. An impact score of the anomaly is determined based on the importance class…
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification G06F21/577. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Oct 03 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).