Causality Graph Log Analysis for Incident Cause Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing incident event cause identification systems face challenges in accurately determining whether an incident in control systems is due to a cyberattack or mechanical failure, as they often lack sufficient alert types for chain relationship creation and underutilize unmonitored device logs, relying heavily on analyst knowledge.

Innovation Solution

An incident event cause identification system that includes a device log information holding unit, a causality graph holding unit, an incident detection processing unit, a necessary log information determination processing unit, a necessary log information collection processing unit, a cause analysis processing unit, and an output unit, which extracts and analyzes necessary log information using a causality graph to efficiently identify incident causes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If all device log information is collected and analyzed, then the accuracy of incident cause identification is improved, but the information scrutiny time and processing complexity increase

Engineering Contradiction:
Improveincident cause identification accuracyVSAvoidinformation scrutiny time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the large volume of device log information into structured categories using a causality graph framework. The causality graph divides incident causes into hierarchical levels (direct causes, indirect causes, root causes) and organizes log information according to these categories, enabling selective analysis of relevant logs rather than examining all logs uniformly. This segmentation reduces scrutiny time while maintaining identification accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary organization of device log information by constructing a causality graph that pre-establishes relationships between incident events and their potential causes. The causality graph is built in advance with defined causal relationships, so when an incident occurs, the system can quickly retrieve and analyze only the pre-organized relevant log information rather than searching through all logs from scratch, significantly reducing analysis time.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive log information is stored, then the completeness of cause analysis is improved, but the information storage capacity requirements increase

Engineering Contradiction:
Improvecause analysis completenessVSAvoidinformation storage capacity
Core Design Contradiction:
ReliabilityVSVolume of stationary object

Solution Approach 1:

The patent extracts only the essential causal relationships from comprehensive log information and stores them in a compact causality graph structure. Instead of storing and processing all raw log data, the system extracts key causal links and stores them in the graph, which requires minimal storage space. The full log information can be retained in compressed or summarized form, while the causality graph provides the structured framework needed for complete cause analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If chain relationship of alerts is defined in advance, then the speed of incident classification is improved, but the adaptability to new incident types decreases

Engineering Contradiction:
Improveincident classification speedVSAvoidadaptability to new incident types
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic causality graph that can be updated and expanded as new incident types are discovered. The causality graph is not a static, fixed structure but can be dynamically modified to incorporate new causal relationships, new incident patterns, and emerging threat types. This dynamic nature allows the system to maintain fast classification speed for known incidents while simultaneously adapting to new incident types by updating the graph structure.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where analysis results from actual incidents are used to refine and update the causality graph. When new incident types or patterns are identified through analysis, this feedback loops back to update the causality graph, adding new causal relationships or modifying existing ones. This feedback-driven evolution enables the system to continuously improve its adaptability to new incident types while maintaining the efficiency benefits of pre-defined chain relationships for known patterns.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250004872A1Incident event cause identification system and incident event cause identification method
Publication Date: 2025.01.02 HITACHI LTD
  • US20250004872A1 patent drawing
  • US20250004872A1 patent drawing
  • US20250004872A1 patent drawing

AI summary

An incident event cause identification system includes a device log information holding unit that holds log information of a target device, a causality graph holding unit that holds a causality graph in which a relationship between an incident event and a cause thereof is associated, and an incident detection processing unit that detects an incident in the target device. A necessary log information determination processing unit extracts a causality graph of an associated type for the detected incident event and determines device log information necessary for cause identification on the basis of the extracted causality graph. A necessary log information collection processing unit collects the device log information determined by the necessary log information determination processing unit, and a cause analysis processing unit identifies a cause of the incident event by using the device log information collected by the necessary log information collection processing unit and the causality graph.