Root cause isolation system and root cause isolation method

JP2026103163APending Publication Date: 2026-06-24HITACHI LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
HITACHI LTD
Filing Date
2024-12-12
Publication Date
2026-06-24

AI Technical Summary

Benefits of technology

【0009】 本発明によれば、事前準備の困難や工数を要することなく、検知された事象の原因を適切に切り分け可能にすることができる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026103163000001_ABST
    Figure 2026103163000001_ABST
Patent Text Reader

Abstract

This enables proper troubleshooting of detected events without requiring significant preparation or time investment. [Solution] The cause isolation system for isolating the cause of a detected event manages a path formation determination graph in which components of the target system that may be affected by a predetermined cause are designated as nodes, and the nodes are connected as edges. The cause isolation system associates the abnormal event related to the abnormality extracted from the detected event with the node related to the abnormal event in the path formation determination graph, and performs a path formation determination to determine whether a predetermined path is formed in the path formation determination graph by the associated abnormal event. Based on the determination result of the path formation determination, the cause isolation system evaluates the possibility that the cause of the detected event is the predetermined cause.
Need to check novelty before this filing date? Find Prior Art

Claims

1. A root cause isolation system for isolating the cause of a detection event detected in the target system, The processor of the aforementioned root cause isolation system is Among the components constituting the aforementioned target system, components that may experience ripple effects due to a predetermined cause are designated as nodes, and a path formation determination graph is managed by connecting these nodes as edges. The abnormal event related to the abnormality extracted from the detection event is associated with the node related to the abnormal event in the path formation determination graph, and a path formation determination is performed to determine whether a predetermined path is formed in the path formation determination graph by the associated abnormal event. Based on the result of the path formation determination, evaluate the likelihood that the cause of the detection event is the predetermined cause. A cause isolation system characterized by the following features.

2. A cause isolation system according to claim 1, The aforementioned processor, Multiple path formation determination graphs corresponding to each of the multiple predetermined causes are managed, Based on the abnormal event and the multiple path formation determination graphs, the path formation determination is performed. Based on the path formation determination result for each of the path formation determination graphs, the likelihood that the cause of the detection event is one of the predetermined causes is evaluated. Based on the comparison results obtained by comparing the likelihood that the cause of the abnormality is one of the predetermined causes, the cause of the detection event is determined to be one of the multiple predetermined causes, or it is determined that it cannot be determined to be any of the multiple predetermined causes. A cause isolation system characterized by the following features.

3. A cause isolation system according to claim 2, The aforementioned processor, The logs recorded in the aforementioned target system are acquired, Based on the aforementioned log, the abnormal event is detected and extracted from the detection event. A cause isolation system characterized by the following features.

4. A cause isolation system according to claim 3, The aforementioned processor, For each type of abnormal event, the log used to detect the abnormal event and the detection method are managed in the abnormal event master. Based on the aforementioned abnormal event master and the aforementioned log, the abnormal events are detected and extracted from the detected events. A cause isolation system characterized by the following features.

5. A cause isolation system according to claim 4, The aforementioned predetermined causes are an attack on the target system and a failure of the target system. The path formation determination graph comprises an attack path formation determination graph in which the nodes where the anomaly may propagate due to the attack are connected by the edges, and a failure path formation determination graph in which the nodes where the anomaly may propagate due to the failure are connected by the edges. The aforementioned processor, Based on the determination result of the path formation determination using the attack path formation determination graph, the possibility of an attack where the cause of the detected event is the attack is evaluated. Based on the result of the path formation determination using the fault path formation determination graph, the likelihood of the fault being the cause of the detected event is evaluated. Based on the comparison result obtained by comparing the evaluation result of the attack possibility and the evaluation result of the failure possibility, the cause of the detection event is determined to be either the attack or the failure, or it is determined that it is not possible to determine whether it is the attack or the failure. A cause isolation system characterized by the following features.

6. A cause isolation system according to claim 5, The aforementioned processor, The aforementioned abnormal event master manages information indicating whether the abnormal event may be caused by something other than the aforementioned attack. Based on the aforementioned abnormal event master, a determination is made to determine whether the abnormal event may be caused by something other than the aforementioned attack. Based on the determination result of the determination of the cause other than the attack and the determination result of the path formation determination based on the graph for determining the attack path formation, the possibility that the cause of the detected event is the attack is evaluated. A cause isolation system characterized by the following features.

7. A cause isolation system according to claim 6, The aforementioned processor, The abnormal event master manages information indicating the log that is recorded when the abnormal event occurs due to the failure, Based on the abnormal event master, a log existence determination is performed to determine whether a log exists that is recorded when the abnormal event occurs due to the failure. Based on the result of the log existence determination and the result of the path formation determination based on the fault path formation determination graph, the likelihood that the cause of the detected event is the fault is evaluated. A cause isolation system characterized by the following features.

8. A cause isolation system according to claim 5, The aforementioned processor, The detection event master manages information indicating whether the aforementioned detection event may be caused by something other than the aforementioned attack. Based on the detection event master, a determination is made as to whether the detection event may be caused by something other than the attack. Based on the aforementioned detection event master, the cause of the detection event that is determined not to be caused by anything other than the aforementioned attack is attributed to the aforementioned attack. Based on the detection event master, for the detection events that are determined to be potentially caused by something other than the attack, the path formation determination is performed based on the abnormal events extracted from the detection events and the attack path formation determination graph. A cause isolation system characterized by the following features.

9. A cause isolation system according to claim 5, The aforementioned processor, The output unit outputs the cause of the detection event, the extracted abnormal event, and the predetermined path through which the effects of the cause are presumed to have spread. A cause isolation system characterized by the following features.

10. A root cause isolation method executed by a root cause isolation system for isolating the cause of a detection event detected in the target system, The processor of the aforementioned root cause isolation system Among the components constituting the aforementioned target system, components that may experience ripple effects due to a predetermined cause are designated as nodes, and a path formation determination graph is managed by connecting these nodes as edges. The abnormal event related to the abnormality extracted from the detection event is associated with the node related to the abnormal event in the path formation determination graph, and a path formation determination is performed to determine whether a predetermined path is formed in the path formation determination graph by the associated abnormal event. Based on the result of the path formation determination, evaluate the likelihood that the cause of the detection event is the predetermined cause. A method for isolating the cause, characterized by having each of the following processes.

Citation Information

Patent Citations

  • Information processing device, information processing method and program

    JP2022007238A

  • Attack analysis device, attack analysis method, and attack analysis program

    JP2023006572A