Anomaly Detection for Automated IT Processes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional alerting tools for monitoring automated IT processes in large landscapes are resource-intensive and often produce inaccurate results, struggling to scale effectively and frequently generate false positives due to their reliance on thresholds set based on experience and past executions.
Innovation Solution
A model-based anomaly detection system that processes historical data to calculate outlier scores for IT process executions, using distribution parameters and probability distributions to identify anomalous events and provide context-aware alerts, thereby enhancing alerting capabilities within existing IT landscape management systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional alerting tools use thresholds and threshold combinations in alerting rules, then alerting can be implemented with simple rules, but computing resources are consumed excessively and results are inaccurate
Solution Approach 1:
The patent transforms the alerting approach from using fixed threshold values to using statistical distribution parameters (mean, standard deviation) derived from historical data. This allows the system to adapt to changing process behaviors and reduce false positives while maintaining computational efficiency through standardized statistical calculations.
Solution Approach 2:
The system performs preliminary analysis by collecting and analyzing historical process execution data before implementing alerting. Distribution parameters are pre-calculated from historical data, enabling the system to quickly evaluate current executions against established baselines without performing complex real-time analysis, thus reducing computing resource consumption during operation.
2Adaptability or versatility
If traditional alerting tools use thresholds based on experience and past executions, then implementation is straightforward, but the system does not scale well for large IT systems
Solution Approach 1:
The patent creates a universal alerting framework that can be applied across diverse IT processes and systems. By using standardized statistical distribution parameters rather than process-specific threshold rules, the system achieves scalability across large IT landscapes while maintaining manageable complexity through a unified approach.
Solution Approach 2:
The system transitions from static, experience-based thresholds to dynamic, data-driven distribution parameters. This transformation enables the alerting system to adapt automatically to different processes and scales, as the statistical approach works consistently across varying process types and system sizes without requiring manual recalibration.
3Reliability
If traditional alerting tools monitor attributes with fixed thresholds, then the monitoring rules are simple to define, but false positives are frequently generated
Solution Approach 1:
The patent replaces fixed threshold parameters with statistical distribution parameters (mean and standard deviation) calculated from historical data. This allows the monitoring system to dynamically adapt to normal process variations and only alert on true anomalies, significantly reducing false positives while maintaining reliable detection of actual problems.
Solution Approach 2:
The system continuously monitors process executions and uses historical data to refine its understanding of normal behavior. By comparing current executions against established distribution baselines and updating its model over time, the system improves its ability to distinguish between normal variations and true anomalies, enhancing reliability while managing complexity through automated learning.
Data Source
AI summary
Methods, systems, and computer-readable storage media for receiving a record including a set of attributes, each attribute having an attribute value, the record representing automatic execution of an IT process within a managed system, retrieving a model representing historical executions of the IT process and including a set of distribution parameters associated with a first type of attribute and a set of probability distributions associated with a second type of attribute, determining, for a first attribute, a first score based on distribution parameters and a value, determining, for a second attribute, a second score based on a probability distribution and a value, the second attribute being of the second type of attribute, and selectively indicating that the IT process is anomalous based on an outlier score.


