Event Anomaly Analysis Using Probabilistic Graph Analytics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise environments face challenges in analyzing vast amounts of log files to detect cyber threats and anomalies in real-time due to the opaque nature of modern computing systems and the difficulty in correlating data from heterogeneous sources, leading to delayed detection of security incidents.

Innovation Solution

An event anomaly analysis and prediction apparatus that utilizes machine learning and graph analytics to model agent behaviors, detect anomalies, and provide real-time alerts by creating probabilistic event graphs, ranking events, and generating rules for anomaly detection and control, enabling proactive security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If traditional log file analysis methods are used, then system complexity is low, but detection speed and real-time anomaly identification are slow

Engineering Contradiction:
Improvedetection speedVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent replaces traditional mechanical log analysis methods with machine learning models and graph analytics algorithms. The system uses trained models to automatically detect anomalies in log files, transitioning from manual pattern matching to intelligent automated analysis, thereby significantly improving detection speed while managing complexity through algorithmic approaches.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces graph analytics as an intermediary layer between raw log data and anomaly detection. By transforming log events into graph structures with nodes and edges representing entities and relationships, the system enables more efficient pattern recognition and real-time anomaly identification without requiring direct complex analysis of raw logs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive log data from heterogeneous sources is analyzed, then measurement precision improves, but difficulty of detecting and measuring increases

Engineering Contradiction:
Improveanomaly detection precisionVSAvoiddata correlation difficulty
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments heterogeneous log data from multiple sources into standardized graph structures. By dividing complex multi-source log data into discrete events represented as graph nodes and relationships as edges, the system maintains high measurement precision while reducing the difficulty of detecting and measuring correlations through structured representation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms raw log parameters into graph analytics parameters such as node attributes, edge weights, and path probabilities. This parameter transformation enables precise anomaly detection by converting heterogeneous data formats into a unified graph-based parameter system that facilitates efficient correlation analysis.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If machine learning and graph analytics are implemented, then productivity in anomaly detection improves, but device complexity increases

Engineering Contradiction:
Improveanomaly detection efficiencyVSAvoidapparatus complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-training machine learning models on historical log data and pre-computing graph analytics baselines. This allows the system to rapidly detect anomalies in real-time without performing complex computations during actual detection, thereby improving productivity while managing apparatus complexity through offline preparation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10909241B2Event anomaly analysis and prediction
Publication Date: 2021.02.02 ACCENTURE GLOBAL SERVICES LTD
  • US10909241B2 patent drawing
  • US10909241B2 patent drawing
  • US10909241B2 patent drawing

AI summary

According to an example, event anomaly analysis and prediction may include accessing a master directed graph that specifies known events and transitions between the known events, and ranking each of the known events. Each of the ranked known events may be clustered into a plurality of anomaly categories. A plurality of rules to analyze new events may be determined based on the plurality of anomaly categories. A determination may be made, based on an application of the plurality of rules to data that is to be analyzed for an anomaly, whether the data includes the anomaly. In response to a determination that the data includes the anomaly, a device associated with the data may be controlled.