Knowledge Graph Root Cause Analysis for IT Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional monitoring solutions for technology stacks struggle to understand complex interrelationships between components, rely on subjective institutional knowledge, and require significant tuning for each case, failing to provide objective anomaly detection and root cause analysis.

Innovation Solution

A system and method for anomaly detection that generates knowledge graphs from time-series data, determining connections and impact scores between metrics, and uses a root cause determination engine to identify root cause candidates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If conventional monitoring solutions are used, then implementation is straightforward, but they cannot understand complex interrelationships between components and fail to extract meaningful information

Engineering Contradiction:
Improvemeaningful information extractionVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent introduces a knowledge graph as an intermediary structure that represents the complex interrelationships between infrastructure components. The knowledge graph serves as a mediator between raw time-series data and anomaly detection algorithms, enabling the system to understand and extract meaningful information about component relationships without requiring the algorithms themselves to be overly complex.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary action by pre-building and maintaining knowledge graphs that capture the interrelationships between components before anomaly detection is needed. This preliminary structuring of relationships allows the anomaly detection system to operate more efficiently by querying pre-processed relationship data rather than analyzing raw data in real-time.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If manually driven metrics or alerts are used, then implementation is simple, but they require deep institutional knowledge and are subjective

Engineering Contradiction:
Improveanomaly detection objectivityVSAvoidimplementation complexity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system implements self-service by automatically generating knowledge graphs and detecting anomalies without requiring manual configuration or deep institutional knowledge. The automated anomaly detection system queries the knowledge graph and time-series data to objectively identify anomalies, eliminating the need for operators to manually define metrics or interpret complex relationships.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the parameters of anomaly detection from manual, subjective metric definitions to automated, objective queries against structured knowledge graphs. By transforming the detection approach from manual threshold-setting to automated pattern recognition in the knowledge graph, the system achieves more precise and objective anomaly detection.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If conventional monitoring solutions are used, then they work for specific cases, but they require significant tuning on a case-by-case basis and are not generally applicable

Engineering Contradiction:
Improvegeneral applicabilityVSAvoidtuning time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent achieves universality by creating a knowledge graph framework that can represent different infrastructure components and their relationships in a standardized way. This universal representation allows the same anomaly detection system to be applied across different infrastructure types without requiring case-by-case tuning, as the knowledge graph can adapt to various configurations through automated relationship extraction.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260064514A1Systems and methods for automated anomaly detection
Publication Date: 2026.03.05 OPTUM INC
  • US20260064514A1 patent drawing
  • US20260064514A1 patent drawing
  • US20260064514A1 patent drawing

AI summary

Systems and computer-implemented methods are disclosed for detecting a system anomaly. A computer-implemented method comprises: receiving, by a data storage module, time-series data from a plurality of sensors of an information technology infrastructure, each sensor corresponding to a respective metric; detecting a plurality of anomalies in the time-series data stored in the data storage module; generating a knowledge graph by: determining connections between the plurality of metrics based on the time-series data; and for each connection, determining a respective weight based on an impact score for metrics joined by the connection; and configuring a root cause determination engine to output one or more metrics as root cause candidates, the one or more metrics based on the knowledge graph, in response to input of a query associated with at least one metric.