Anomaly Detection System with Automated Playbook and Chat Coordination

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current ticketing systems lack automation in identifying the exact issue and the optimal group of professionals needed to resolve IT system anomalies, often requiring a skilled employee to manually determine the best team for efficient resolution.

Innovation Solution

A computerized system that generates a profile to monitor software programs, detects anomalies by analyzing deviations from normal operation, and organizes chat services by identifying relevant professionals from a knowledge base to collaborate on resolving the issue, using deep learning to craft expert conversations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual identification of issues and professionals is used, then expertise and accuracy are improved, but time consumption and productivity are worsened

Engineering Contradiction:
Improveaccuracy of issue identificationVSAvoidtime to resolve anomaly
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs self-service by automatically detecting anomalies, identifying affected programs, selecting appropriate playbooks, and organizing chat services without human intervention. The computer system serves itself to resolve issues by leveraging stored baseline data, anomaly detection algorithms, and pre-configured playbook repositories, eliminating the need for manual issue identification while maintaining high accuracy through systematic comparison against known patterns.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-storing baseline data for normal program operations and pre-organizing playbook repositories with resolution procedures for various anomaly types. These preparatory measures enable rapid automated response when anomalies occur, as the system can immediately compare current state against pre-established baselines and deploy appropriate playbooks without time-consuming manual analysis.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If automated anomaly detection is implemented, then productivity and response time are improved, but device complexity and implementation difficulty are worsened

Engineering Contradiction:
Improveanomaly detection speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments the anomaly detection process into distinct modular components: baseline data collection, anomaly detection algorithms, playbook selection logic, and chat service coordination. Each component operates independently with well-defined interfaces, allowing the complex system to be managed through manageable segments. The segmentation enables parallel processing of multiple anomalies and facilitates independent optimization of each functional module.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces intermediary elements including standardized data structures for storing baseline information, structured playbook formats with defined schemas, and intermediate representation layers between detection algorithms and resolution actions. These intermediaries simplify the overall system architecture by providing standardized interfaces and abstraction layers that reduce the complexity of integrating diverse components.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If comprehensive monitoring of all programs is performed, then detection accuracy is improved, but computational resource consumption is worsened

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidcomputational resource usage
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system applies local quality by focusing monitoring resources on specific programs and parameters that are most critical or show signs of abnormality. Rather than uniformly monitoring all programs with equal intensity, the system adapts its monitoring granularity and depth based on the specific program, its importance to system operation, and preliminary indicators of potential issues. This localized approach maintains high detection accuracy for critical systems while reducing overall computational burden.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically changes monitoring parameters such as sampling frequency, data collection depth, and analysis intensity based on system conditions, program criticality, and detected anomaly patterns. When normal operation is detected, monitoring parameters are reduced to conserve resources; when anomalies are detected or suspected, parameters are intensified to improve detection accuracy. This adaptive parameter adjustment maintains effectiveness while optimizing resource consumption.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11625237B2Autonomous contextual software support anomaly detection and playbook automation
Publication Date: 2023.04.11 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11625237B2 patent drawing
  • US11625237B2 patent drawing
  • US11625237B2 patent drawing

AI summary

A computer generates a profile, where the profile comprises one or more programs to monitor. The computer determines a baseline for each of the one or more programs by collecting one or more values associated with a normal operation for each of the one or more programs. The computer detects an anomaly based on deviation of the one or more values from the normal operation. Based on identifying a playbook for the anomaly, the computer applies the playbook on the program from the one or more programs. The computer organizes chat services based on identifying one or more members associated with the anomaly.