Anomaly Detection for Automated IT Processes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional alerting tools for monitoring automated IT processes in large landscapes are resource-intensive and often produce inaccurate results, struggling to scale effectively and frequently generate false positives due to their reliance on thresholds set based on experience and past executions.

Innovation Solution

A model-based anomaly detection system that processes historical data to calculate outlier scores for IT process executions, using distribution parameters and probability distributions to identify anomalous events and provide context-aware alerts, thereby enhancing alerting capabilities within existing IT landscape management systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional alerting tools use thresholds and threshold combinations in alerting rules, then alerting can be implemented with simple rules, but computing resources are consumed excessively and results are inaccurate

Engineering Contradiction:
Improvealerting accuracyVSAvoidcomputing resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent transforms the alerting approach from using fixed threshold values to using statistical distribution parameters (mean, standard deviation) derived from historical data. This allows the system to adapt to changing process behaviors and reduce false positives while maintaining computational efficiency through standardized statistical calculations.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system performs preliminary analysis by collecting and analyzing historical process execution data before implementing alerting. Distribution parameters are pre-calculated from historical data, enabling the system to quickly evaluate current executions against established baselines without performing complex real-time analysis, thus reducing computing resource consumption during operation.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If traditional alerting tools use thresholds based on experience and past executions, then implementation is straightforward, but the system does not scale well for large IT systems

Engineering Contradiction:
ImprovescalabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal alerting framework that can be applied across diverse IT processes and systems. By using standardized statistical distribution parameters rather than process-specific threshold rules, the system achieves scalability across large IT landscapes while maintaining manageable complexity through a unified approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system transitions from static, experience-based thresholds to dynamic, data-driven distribution parameters. This transformation enables the alerting system to adapt automatically to different processes and scales, as the statistical approach works consistently across varying process types and system sizes without requiring manual recalibration.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If traditional alerting tools monitor attributes with fixed thresholds, then the monitoring rules are simple to define, but false positives are frequently generated

Engineering Contradiction:
Improvealerting reliabilityVSAvoidmonitoring complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces fixed threshold parameters with statistical distribution parameters (mean and standard deviation) calculated from historical data. This allows the monitoring system to dynamically adapt to normal process variations and only alert on true anomalies, significantly reducing false positives while maintaining reliable detection of actual problems.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system continuously monitors process executions and uses historical data to refine its understanding of normal behavior. By comparing current executions against established distribution baselines and updating its model over time, the system improves its ability to distinguish between normal variations and true anomalies, enhancing reliability while managing complexity through automated learning.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11568279B2Anomaly detection for automated information technology processes
Publication Date: 2023.01.31 SAP SE
  • US11568279B2 patent drawing
  • US11568279B2 patent drawing
  • US11568279B2 patent drawing

AI summary

Methods, systems, and computer-readable storage media for receiving a record including a set of attributes, each attribute having an attribute value, the record representing automatic execution of an IT process within a managed system, retrieving a model representing historical executions of the IT process and including a set of distribution parameters associated with a first type of attribute and a set of probability distributions associated with a second type of attribute, determining, for a first attribute, a first score based on distribution parameters and a value, determining, for a second attribute, a second score based on a probability distribution and a value, the second attribute being of the second type of attribute, and selectively indicating that the IT process is anomalous based on an outlier score.