Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

22 results about "Incident analysis" patented technology

An incident analysis involves gathering facts by inspecting the incident scene, interviewing witnesses, reviewing documentation, and analyzing those facts to determine the causal factors. The causal analysis is easier and more effective when it is done in two phases, a primary event analysis and a causal factor analysis.

Method, apparatus, and computer program for responding to system incidents based on generative artificial intelligence

PendingUS20250307067A1Non-redundant fault processingIncident analysisMonitoring system
A processor implemented method including monitoring an event in a system, analyzing a log of the event to determine whether the event is a system incident, searching, responsive to the event being determined to be a system incident event, an internal knowledge base for causes of the system incident event and remedial actions for the system incident event, based on retrieval-augmented generation, prompting a first inquiry, the first inquiry including the log and a search result from the searching to a first LLM, and generating a first response including remedial actions for the system incident event by the first LLM, based on the first inquiry and the search result.
Owner:SAMSUNG SDS CO LTD

Industrial time sequence event analysis method and device based on causal regularization and medium

The invention discloses an industrial time sequence event analysis method and device based on causal regularization and a medium, and relates to the technical field of artificial intelligence, and the method comprises the steps: carrying out the multi-scale time sequence feature coding of multivariate time sequence data, and obtaining time sequence feature data; performing potential vector reconstruction of probability distribution on the time sequence feature data to determine reconstruction loss and distance measurement loss; based on the prior causal graph, obtaining a causal consistency loss function through acyclic constraint balance analysis; performing hyper-parameter consistency processing on the causal consistency loss function to determine an overall loss function and obtain a minimum overall loss; a small number of samples are finely adjusted to model convergence, and a CT-VAE model of the implicit label is determined; and inputting the data window into the model to obtain an event analysis result and an event diagnosis report. According to the method, the technical problems that in the prior art, industrial time sequence event analysis robustness is poor, the identification error is high, and implicit key event identification cannot be met are solved.
Owner:INSPUR GENERSOFT CO LTD

Network security event analysis method, system and equipment

The invention belongs to the field of network security, particularly relates to a network security event analysis method, system and equipment, and aims to solve the problem that the existing network security event analysis and detection technology is poor in detection effect. Comprising the following steps: determining common data and suspicious data in a network security data set; constructing a multi-dimensional base line for the suspicious data, and generating a composite feature vector in combination with the feature vector of the common data; identifying an abnormal line in the composite feature vector as an abnormal event node; constructing an event graph based on the relationship between different target devices, the relationship between the target device and the user, and the relationship between the target device and the abnormal event node; determining an event type based on a node feature matrix of the event graph; and generating a network security event analysis result based on the event type, the abnormal score, the event occurrence time, the event occurrence position and the attack path. The network security event analysis method and the network security event analysis device have stronger generalization ability for novel attacks, and improve the accuracy of network security event analysis.
Owner:TONGFANG KNOWLEDGE DIGITAL PUBLISHING TECH CO LTD

Event analysis method and device, equipment and storage medium

The invention belongs to the field of big data processing, and particularly relates to an event analysis method, device and equipment and a storage medium, target event information is obtained, the target event information is converted into event feature vectors, the event feature vectors are input into multiple analysis models respectively, and the analysis models output corresponding event types and initial risk levels respectively. Performing similarity matching on the event feature vector and a historical event feature vector of a historical event in a preset knowledge base, screening one or more pieces of historical event information of which the similarity score is greater than a preset threshold, and determining the credibility of each analysis model based on the historical event information and the event type, performing weighted fusion on the initial analysis result based on the credibility of each analysis model, and determining a target risk level corresponding to the target event information; according to the method, by combining multi-model analysis, historical data similarity matching and credibility weighted fusion, the accuracy of risk level judgment of the target event is improved.
Owner:HAINA CLOUD IOT TECH CO LTD +1

A method, apparatus, device and medium for network security incident analysis

PendingCN122293423ALinguistic modelIncident analysis
This application discloses a method, apparatus, device, and medium for network security incident assessment, relating to the field of computer technology. It is applied to a network security incident assessment system. The system deploys a large language model within an analysis chain framework to perform progressive reasoning. The method includes: extracting target assessment features related to network security threats from multi-source heterogeneous data; determining at least one threat hypothesis scenario based on the target assessment features; assigning positive weights to supporting evidence for the scenario and negative weights to rebuttal evidence for the scenario; performing reasoning analysis on the evidence set to generate a target assessment report for the threat hypothesis scenario; the evidence set is obtained based on target evidence carrying the aforementioned weights. This application avoids interference from different contextual scenarios in the judgment; avoids the problem of lack of reasoning basis in the reasoning process; significantly reduces misjudgments and omissions; and solves the problem of insufficient understanding and adaptability of general large language models to network security expertise.
Owner:SANGFOR TECH INC

Group-based fraud detection decisioning

A computer system for detecting and assessing fraud risk employs group-based analysis to identify complex fraud patterns across various industries. The system identifies and analyzes groups of connected incidents by linking related events based on similarities in suspect identifiers, creating a network that reveals broader fraudulent behavior patterns. When processing a new incident, the system compares it against established groups of connected incidents, detecting subtle connections that may indicate relationships to known fraud patterns. This comparison can range from basic identifier matching to sophisticated analysis of multiple data points across different incidents within a group. Based on this comparison, the system generates a comprehensive fraud risk assessment for the new incident, leveraging collective information from grouped incidents to provide a nuanced and accurate evaluation of potential fraud risk. By considering new incidents in the context of established fraud patterns, the system offers insights not possible through individual incident analysis.
Owner:DETECTIVE ANALYTICS IP HOLDINGS LLC

Temporal graph-based anomaly analysis and control in cyber physical systems

ActiveUS12670059B2Incident analysisEngineering
Systems and methods are provided for incident analysis in Cyber-Physical Systems (CPS) using a Temporal Graph-based Incident Analysis System (TGIAS) and / or Transition Based Categorical Anomaly Detection (TCAD). Dynamically gathered multimodal data from a distributed network of sensors across the CPS are preprocessed to identify abnormal sensor readings indicative of potential incidents, and a multi-layered incident timeline graph, representing abnormal sensor readings, relationships to specific CPS components, and temporal sequencing of events is constructed. Severity scores are calculated, and severity rankings are assigned to identified anomalies based on a composite index including impact on CPS operation, comparison with historical incident data, and predictive risk assessments. Probable root causes of incidents and pathways for anomaly propagation through the CPS are identified using causal interference and the incident timeline graph to detect underlying vulnerabilities and predict future system weaknesses. Recommended actions are generated and executed for incident resolution and system optimization.
Owner:NEC CORP

Risk event analysis method and system and storage medium

The embodiment of the invention discloses a risk event analysis method and system and a storage medium, and is applied to the technical field of information processing. The method comprises the following steps: acquiring multi-dimensional data of a to-be-analyzed area, constructing a digital twin base based on the multi-dimensional data, and performing unified three-dimensional grid coding on the digital twin base to form a space-time cube model comprising a plurality of space grids, and selecting a plurality of to-be-analyzed space grids of the risk event interest area from the plurality of space grids according to the weather monitoring data, and analyzing occurrence conditions of risk events on the plurality of to-be-analyzed space grids. In this way, by finding out the risk event interest area, only the risk event interest area needs to be analyzed, all sub-areas of the to-be-analyzed area do not need to be analyzed, the calculation amount can be reduced, and the risk analysis efficiency can be improved; and when risk analysis is carried out on the risk event interest area, parallel analysis can be carried out on a plurality of to-be-analyzed space grids in the risk event interest area, so that the risk analysis efficiency is further improved.
Owner:SHENZHEN SMARTCITY TECH DEV GRP CO LTD

A large model log violation scene processing method, system, device and medium

ActiveCN121257670BInference methodsPathPingIncident analysis
This application discloses a method, system, device, and medium for handling violation scenarios in large-scale model logs, mainly relating to the field of violation handling technology. It aims to address the problems of rigid rules, limited coverage, knowledge silos, lack of correlation, reliance on experts, and high iteration costs in existing solutions. The method includes: tracking behavioral nodes corresponding to several consecutive raw logs to form a behavioral node sequence; comparing the behavioral node sequence with preset legal path sequences in a behavior tree model library to determine if a preset abnormal node sequence exists; when an abnormal node sequence exists, determining whether it conforms to an event sequence corresponding to any rule in the event analysis rule library; if it does, entering the preset alarm scheme corresponding to the event sequence; if it does not, entering the unknown scenario mining process, inputting the abnormal node sequence into a trained second large-scale language model to obtain an initial processing scheme, and inputting the initial processing scheme into a preset verification terminal to obtain the final processing scheme.
Owner:中孚安全技术有限公司

System

PendingJP2026033695AOffice automationIncident analysisData mining
An object of a system according to an embodiment is to share near-miss incidents experienced by employees and prevent mistakes as a whole.SOLUTION: A system includes an input part, an analysis part, a database part, and a provision part. The input unit inputs a near-miss incident event experienced by an employee during work. The analysis unit analyzes the near-miss incident event input by the input unit and extracts a dangerous point and a pattern. The database unit registers the dangerous point and the pattern extracted by the analysis unit in a database. The providing part provides the information registered in the database part so that the employee can access the information.SELECTED DRAWING: Figure 1
Owner:SOFTBANK GROUP CORP

Temporal graph-based incident analysis and control in cyber physical systems

Systems and methods are provided for incident analysis in Cyber-Physical Systems (CPS) using a Temporal Graph-based Incident Analysis System (TGIAS) and / or Transition Based Categorical Anomaly Detection (TCAD). Dynamically gathered multimodal data from a distributed network of sensors across the CPS are preprocessed to identify abnormal sensor readings indicative of potential incidents, and a multi-layered incident timeline graph, representing abnormal sensor readings, relationships to specific CPS components, and temporal sequencing of events is constructed. Severity scores are calculated, and severity rankings are assigned to identified anomalies based on a composite index including impact on CPS operation, comparison with historical incident data, and predictive risk assessments. Probable root causes of incidents and pathways for anomaly propagation through the CPS are identified using causal interference and the incident timeline graph to detect underlying vulnerabilities and predict future system weaknesses. Recommended actions are generated and executed for incident resolution and system optimization.
Owner:NEC CORP

Large model log violation scene processing method, system and device and medium

The invention discloses a large-model log violation scene processing method, system and device and a medium, mainly relates to the technical field of violation processing, and is used for solving the problems of rule stiffness, limited coverage, knowledge islanding, lack of association, dependency on experts and high iteration cost in the existing scheme. Comprising the steps of tracking behavior nodes corresponding to a plurality of continuous original logs to form a behavior node sequence; comparing the behavior node sequence with a preset legal path sequence in a behavior tree model library, and determining whether a preset abnormal node sequence exists or not; when the abnormal node sequence exists, determining whether the abnormal node sequence accords with an event sequence corresponding to any rule in an event analysis rule base, and when the abnormal node sequence accords with the event sequence corresponding to any rule in the event analysis rule base, entering a preset alarm scheme corresponding to the event sequence; and if not, entering an unknown scene mining process, inputting the abnormal node sequence into a trained second large language model to obtain an initial processing scheme, and inputting the initial processing scheme into a preset verification terminal to obtain a final processing scheme.
Owner:中孚安全技术有限公司

Cast-in-situ bored pile construction risk analysis method and system

The invention provides a cast-in-situ bored pile construction risk analysis method and system, and belongs to the technical field of risk identification, and the method comprises the following steps: determining a top event of a cast-in-situ bored pile construction risk by using an accident tree analysis method, analyzing an intermediate event and a basic event of an accident according to the top event, and constructing an accident tree; solving a minimum cut set of top events in the accident tree by using a Boolean algebraic method; drawing a dual tree of the accident tree by using duality of the minimum path set and the minimum cut set, and solving the accident tree by using a Boolean algebraic method to obtain the minimum path set of the top event; judging the structural importance degree of the basic event to the top event according to the occurrence frequency of the basic event in the minimum cut set or the minimum path set; and judging the risk factor of the top event through the minimum cut set, the minimum path set or the structural importance degree. According to the invention, the occurrence of accidents can be comprehensively analyzed, and prevention measures with strong pertinence are provided for avoiding the occurrence of accidents.
Owner:JIANGXI ENG CONSULTING CENT CO LTD

Power grid dispatching event analysis method and device and electronic equipment

PendingCN122635883AIncident analysisPower grid
Embodiments of the present application provide a power grid dispatch event analysis method, device and electronic equipment. The method comprises: acquiring multi-source heterogeneous data; preprocessing the multi-source heterogeneous data to form a structured event feature dataset; constructing a multi-layer causal relationship graph based on the event feature dataset; based on the multi-layer causal relationship graph, performing root cause analysis on an occurred power grid dispatch event chain to obtain a root cause analysis result, the root cause analysis result comprising a root node of the power grid dispatch event chain and a causal propagation path from the root node to a symptom event. The method can deeply reveal the occurrence mechanism and evolution law of the power grid dispatch event from the causal perspective, and realize accurate tracing from the symptom event to the root cause event.
Owner:MEIZHOU POWER SUPPLY BUREAU OF GUANGDONG POWER GRID CORP

Concentrator operation management method and system based on data processing

The application discloses a concentrator operation management method and system based on data processing and belongs to the technical field of data processing. The system comprises a data sensing module, an event analysis module, an operation management module and a reporting transmission module. The data sensing module collects historical records, operation parameters and triggered events of electric energy meters through the concentrator; the event analysis module establishes a causal relationship chain according to the historical records, marks the triggered events and calculates a weight index in combination with the causal relationship chain; the operation management module is used for evaluating event states and performing screening, calculating priority indexes of the electric energy meters and generating an event record table according to the weight indexes and the priority indexes; and the reporting transmission module reports the marked events in the event record table one by one, and if the reporting fails, calculates a transmission kinetic index of the corresponding marked event, so as to determine whether to continue reporting. The application optimizes the event reporting process by the dynamic priority management and the adaptive reporting mechanism based on the event relationship chain, and improves the event management efficiency.
Owner:JIANGSU INST OF METROLOGY

Lost index acquisition method and device

The invention provides a method and a device for acquiring a loss index. The method comprises the following steps: acquiring a target security event analysis report; identifying a uniform resource locator (URL) in the target security event analysis report; identifying target content corresponding to the path field from the URL; searching a first target language corresponding to the target content in a content-language corresponding relationship, wherein the content-language corresponding relationship comprises various languages and contents correspondingly identified in a path of the URL; and obtaining the IOC from the target security event analysis report based on the first target language. Through the URL of the security event analysis report, the origin of the security event analysis report can be accurately determined, and then the language of the security event analysis report is accurately determined. The target security event analysis report is subjected to IOC identification by adopting a correct language, and the IOC can be correctly identified, so that the accuracy of IOC information acquisition is improved.
Owner:QI AN XIN TECHNOLOGY GROUP INC

Method and device for analyzing operation events, electronic device and storage medium

The present disclosure discloses an operation event analysis method and device, an electronic device and a storage medium. According to the present application, the event knowledge base is constructed based on historical event data and the causal analysis model is trained, the sufficient extraction and fusion analysis of event characteristics are realized, the direct cause and the systematic cause can be accurately identified without relying on manual annotation, the knowledge base and the model are dynamically updated through new event data to improve the generalization ability, the feedback document is automatically associated with the historical experience, the technical effects of improving the operation event analysis efficiency of the nuclear power plant, enhancing the accuracy and comprehensiveness of event cause identification, reducing the occurrence of repetitive failures, strengthening the experience inheritance and risk prevention and control capability, and further ensuring the operation safety and stability of the nuclear power plant are achieved.
Owner:HUANENG NUCLEAR ENERGY TECH RES INST CO LTD +1

Security event analysis using network model context

A security incident analysis method includes: receiving information about a security incident; matching the security incident with one or more contents of a network model representing a system; analyzing additional context associated with the matching one or more contents of the network model; determining risk information about the security incident based at least in part on the analyzed additional context; and outputting an indication of the determined risk information.
Owner:C2A SEC LTD

Concentrator operation management method and system based on data processing

The invention discloses a concentrator operation management method and system based on data processing, and belongs to the technical field of data processing. The system comprises a data sensing module, an event analysis module, an operation management module and a report transmission module. The data sensing module collects historical records, operation parameters and triggered events of the electric energy meter through the concentrator; the event analysis module establishes a causal relationship chain according to historical records, marks a triggered event and calculates a weight index in combination with the causal relationship chain; the operation management module is used for evaluating event states, screening the event states, calculating the priority index of each electric energy meter, and generating an event record table according to the weight index and the priority index; and the report transmission module reports the marked events in the event record table one by one, and calculates the transmission kinetic energy indexes corresponding to the marked events if the report fails, thereby judging whether the report is continued or not. According to the method, the event reporting process is optimized based on the dynamic priority management of the event relation chain and the self-adaptive reporting mechanism, and the event management efficiency is improved.
Owner:JIANGSU INST OF METROLOGY

Language model-based incident analysis and resolution

PendingUS20260252432A1Linguistic modelIncident analysis
A system is described that utilizes one or more large language models (“LLMs”) and prior incident data to (1) summarize a potential root cause for an incident that has occurred and to propose one or more steps or operations to be executed to resolve the incident; and / or (2) identify a new incident, summarize a potential root cause for the incident, and propose one or more steps or operations to resolve the incident. By employing various implementations of the systems and methods utilizing LLMs and / or prior incident data described herein, the incident response and prevention system can quickly and accurately output steps or operations that can be executed to resolve service unavailability that has already occurred and / or can quickly and accurately identify service unavailability incidents that may occur in the future and that can clearly identify what steps or operations to execute to prevent the service unavailability incident from occurring.
Owner:PALANTIR TECHNOLOGIES INC

An apartment-based video monitoring abnormal behavior detection method and system

This invention relates to the field of intelligent video surveillance technology, and discloses a method and system for detecting abnormal behavior in apartment video surveillance. The method includes synchronously acquiring and segmenting the surveillance video stream into time-series video segments with overlapping areas; performing multi-level scene semantic analysis on each video segment; constructing a spatiotemporal correlation network based on the temporal and spatial relationships between video segments, and performing cross-time period behavior correlation analysis to generate continuous behavior chains; matching the behavior chains with an abnormal behavior rule base to determine and mark abnormal events; further, performing multi-dimensional causal tracing of abnormal events to generate an abnormal causal tracing graph, and formulating and executing a hierarchical handling strategy accordingly; finally, dynamically optimizing the rule base using strategy execution feedback data. This invention achieves continuous characterization of behavior chains by constructing a spatiotemporal correlation network, deepens event analysis through causal tracing graphs, and improves the coherence, accuracy, and interpretability of abnormal behavior detection.
Owner:YUXIN (NANJING) NETWORK TECH CO LTD

Equipment fault event analysis method based on data association mining and related equipment

The invention discloses an equipment fault event analysis method based on data association mining and related equipment, and relates to the technical field of power system fault analysis. Time alignment, space matching and causal association are performed on multi-source data such as operation parameters, state monitoring and communication interaction by constructing three types of fault association dimensions of time, space and causal; forming a cross-source data association mapping relation; extracting a fault initial equipment identifier, an occurrence time node, an influence equipment list and a fault performance feature set, reconstructing a propagation path of the fault between the equipment and generating a path map for visualization according to the fault initial equipment identifier, the occurrence time node, the influence equipment list and the fault performance feature set; and organizing the fault generation process, the propagation logic and the influence degree according to the time sequence and the trigger condition, and generating an equipment fault event analysis report.
Owner:STATE GRID SICHUAN ELECTRIC POWER CORP ELECTRIC POWER RES INST