Emerging Event Detection via State Automaton Burst Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for real-time detection of emerging clusters in time-series data are limited by their reliance on scanning time-windows of predefined widths, which can fail to detect clusters emerging over different temporal periods and are prone to noise and statistical artifacts, leading to false positives and false negatives, especially when dealing with new or infrequently occurring event types.
Innovation Solution
The system employs a finite- or infinite-state automaton to model temporal dynamics as frequency-dependent states, using vector representations of events in a hyperspace to identify clusters and determine their bursting likelihood, filtering noisy clusters, and aggregating redundant ones, thereby detecting emergent clusters without relying on predefined time-windows.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If scanning time-windows of predefined widths are used for real-time detection, then the detection process is simple and fast, but the detection accuracy deteriorates due to inability to detect clusters emerging over different temporal periods and susceptibility to noise
Solution Approach 1:
The patent replaces static predefined time-windows with a dynamic approach using a finite- or infinite-state automaton that adapts to the temporal characteristics of emerging clusters. The system models temporal dynamics as frequency-dependent states, allowing the detection mechanism to adjust its behavior based on the observed event frequency patterns rather than being constrained by fixed time intervals.
Solution Approach 2:
The system changes the parameter of time-window width from a fixed predefined value to a variable that depends on the observed event frequency. By using vector representations of events in hyperspace and analyzing frequency-dependent states, the system dynamically determines appropriate detection parameters based on the actual temporal patterns of the data being analyzed.
2Ease of manufacture
If conventional scanning methods are used, then the system is easy to implement, but false positives and false negatives increase due to noise and statistical artifacts
Solution Approach 1:
The patent introduces an intermediary layer between the raw event stream and the detection decision. The finite-state automaton acts as a mediator that processes events through multiple frequency-dependent states before reaching a detection conclusion. This intermediary processing stage filters out noise and statistical artifacts by requiring patterns to persist through state transitions, thereby reducing false positives and false negatives.
Solution Approach 2:
The system implements feedback through the finite-state automaton's state transitions, where the detection process continuously monitors and adjusts based on observed event frequencies. The automaton's states provide feedback about the current temporal pattern, allowing the system to refine its detection criteria dynamically and improve reliability by learning from past observations.
3Use of energy by moving object
If predefined time-windows are used for detection, then computational resources are conserved, but the system fails to detect clusters with new features or infrequently occurring events
Solution Approach 1:
The patent transitions from analyzing events in a single temporal dimension (fixed time-windows) to a higher-dimensional approach using vector representations in hyperspace. By representing events as vectors with multiple features and analyzing their distribution across frequency-dependent states, the system can detect clusters based on pattern similarity rather than temporal alignment, enabling detection of clusters with new features or infrequent occurrences while maintaining computational efficiency.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Technologies are provided for the monitoring, detection, and notification of emerging, related issues within a system, which may indicate a problem. Within a computing-security system, a sudden increase in the frequency of events associated with unauthorized logon attempts signal a real-time and ongoing security risk. A method monitors system-related events and generates a vector representation for each event based on event features. Clusters of related events are determined, and a state automaton is employed to determine a strength of temporal "bursty" activity for each cluster. Hypothesis testing is performed on each cluster to determine a likelihood that the cluster is a temporally emergent cluster. Clusters with a bursting likelihood above a threshold are determined to be an emergent cluster associated with an anomalous issue. A notification regarding the detected anomaly is provided. A remedial action addressing the anomaly is performed. Noisy clusters are filtered and aggregated based on their bursting likelihood and overlapping sub-spaces of the hyperspace.