IT Anomaly Detection via Document Clustering and ML

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anomaly detection in IT systems relies on manual monitoring, which is often inadequate and fails to accurately identify issues due to limited administrator knowledge and incomplete performance metrics, leading to undetected errors and potential system failures.

Innovation Solution

A method that generates vectors from documents about IT systems to represent words, clusters these vectors, and uses machine learning to identify features, training a model to automatically detect anomalies based on these features during system operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual monitoring is used for anomaly detection in IT systems, then device complexity is reduced, but reliability and measurement precision deteriorate due to limited administrator knowledge and incomplete performance metrics

Engineering Contradiction:
Improveanomaly detection reliabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically generates performance metrics and clusters documents without requiring administrator intervention. The machine learning model autonomously identifies anomalies by analyzing clustered document features, enabling the system to self-monitor and self-diagnose IT system issues without human expertise.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual monitoring processes with automated machine learning-based anomaly detection. Instead of relying on human administrators to monitor system performance, the system uses computational algorithms to process documents, generate metrics, and identify anomalies automatically.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If manual monitoring is used, then ease of operation is improved, but productivity deteriorates due to inadequate detection capabilities and potential system failures going undetected

Engineering Contradiction:
Improveanomaly detection efficiencyVSAvoidmonitoring operation simplicity
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The system performs preliminary processing by automatically generating performance metrics and clustering documents before anomaly detection. This pre-processing organizes information in advance, enabling efficient and accurate anomaly identification without requiring complex real-time analysis during operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary layer of automated processing between data collection and anomaly detection. The machine learning model acts as a mediator that processes raw documents and metrics, transforming them into actionable anomaly insights, thereby bridging the gap between simple data collection and sophisticated analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If automated machine learning-based monitoring is implemented, then reliability and measurement precision are improved, but device complexity and initial setup requirements increase

Engineering Contradiction:
Improveperformance metric precisionVSAvoidsystem architecture complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the monitoring process into distinct functional modules: document processing, performance metric generation, document clustering, and anomaly detection. This segmentation allows each component to be optimized independently and simplifies the overall system architecture by dividing complex tasks into manageable units.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The machine learning model serves multiple functions within the system: it processes documents, generates performance metrics, clusters related information, and identifies anomalies. This multi-functionality reduces the need for separate specialized components, thereby reducing overall system complexity while maintaining high measurement precision.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11743133B2Automatic anomaly detection
Publication Date: 2023.08.29 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11743133B2 patent drawing
  • US11743133B2 patent drawing
  • US11743133B2 patent drawing

AI summary

A method includes generating a plurality of vectors representing words in a plurality of documents about an information technology (IT) system and clustering the plurality of vectors to produce a plurality of clusters. The method also includes identifying a cluster of the plurality of clusters that contains a plurality of clustered vectors, generating a feature based on a plurality of words represented by the plurality of clustered vectors, and training a machine learning model to identify an anomaly in the IT system based on the feature.