Metadata Fingerprinting for IT System Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information technology managers face challenges in monitoring and managing large IT architectures for failures, security breaches, and network utilization, as existing methods require analyzing extensive data content, which is computationally demanding and resource-intensive.

Innovation Solution

The method employs metadata analysis by creating and comparing metadata fingerprints from data sources over time to detect deviations within a specified tolerance, generating alerts for anomalies, thereby reducing the need to analyze data content and simplifying the monitoring of systems and virtual machines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If data content analysis is performed to monitor and detect failures, security breaches, and network utilization, then monitoring accuracy is improved, but computational resource consumption increases

Engineering Contradiction:
Improvemonitoring accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the essential metadata characteristics from data sources rather than analyzing complete data content. Metadata fingerprints capture key identifying features (data quantity, type, timing) while excluding unnecessary content details, enabling monitoring with reduced computational overhead while maintaining detection accuracy for failures, security breaches, and network utilization anomalies.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The monitoring system segments the analysis task into two parts: (1) extraction of metadata fingerprints from data sources, and (2) comparison of these fingerprints against baseline profiles. This segmentation allows the system to focus computational resources on comparing compact metadata representations rather than processing entire data contents, thereby reducing resource consumption while preserving monitoring effectiveness.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If complete data content is analyzed for system monitoring, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system extracts only essential metadata characteristics (fingerprints) from data sources, eliminating the need to process and store complete data contents. This extraction approach simplifies the monitoring system architecture by working with compact metadata representations rather than voluminous data content, reducing system complexity while maintaining detection accuracy through focused analysis of critical attributes.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates simplified copies of data source characteristics in the form of metadata fingerprints. These fingerprints serve as representative copies that capture essential identifying features without replicating the full data content. By comparing these compact copies against baseline profiles, the system achieves accurate detection with significantly reduced complexity compared to analyzing complete data contents.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9154386B2Using metadata analysis for monitoring, alerting, and remediation
Publication Date: 2015.10.06 TDI TECHNOLOGIES INC
  • US9154386B2 patent drawing
  • US9154386B2 patent drawing
  • US9154386B2 patent drawing

AI summary

In certain embodiments, a method for monitoring, alerting and remediation of systems is provided. The method provides for receiving data from one or more data sources and logging the data. A first metadata fingerprint is created for a particular data source. The first metadata fingerprint is indicative of a first quantity of data output for the particular data source. A second metadata fingerprint is created for the same data source. The second metadata fingerprint is indicative of a second quantity of data output for the data source. The second metadata fingerprint is created from data received at a different point in time from the first metadata fingerprint. The first metadata fingerprint is compared with the second metadata fingerprint associated with the particular data source. An alert is generated when the comparison indicates that the first metadata fingerprint does not correspond within a specified tolerance to the second metadata fingerprint.