Monitoring Service for Enterprise Log Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Internal services within enterprises are not adequately monitored for performance, usage, and security, leading to inefficiencies and security concerns due to lack of visibility into service interactions and latency issues, which are difficult to identify.

Innovation Solution

A monitoring service that aggregates and analyzes log data from multiple services to detect anomalies, establish service relationship models, and provide alerts or remedial actions, enabling administrators to manage service performance and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If internal services are provided within an enterprise's own network, then security is assumed to be maintained, but monitoring capability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidmonitoring capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a monitoring service as an intermediary component that sits between service consumers and service providers. This monitoring service collects logs from service consumers, aggregates them, and analyzes them to detect anomalies without interfering with the actual service communication. The monitoring service acts as a mediator that provides visibility into internal service interactions while maintaining the security assumptions of the private network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If internal services are used by many different service consumers for many different purposes, then service versatility improves, but monitoring complexity increases

Engineering Contradiction:
Improveservice versatilityVSAvoidmonitoring complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The monitoring service is designed as a universal system that can monitor multiple services and service consumers simultaneously. It collects logs from various service consumers, aggregates them through a common processing pipeline, and analyzes them using unified anomaly detection algorithms. This multi-functional approach allows the system to handle diverse service interactions without requiring separate monitoring solutions for each service, thereby reducing overall complexity despite the high versatility of the monitored services.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If service providers rapidly change or evolve their internal services, then service adaptability improves, but monitoring accuracy deteriorates

Engineering Contradiction:
Improveservice adaptabilityVSAvoidmonitoring accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The monitoring service employs dynamic baseline profiles that automatically adapt to service changes. Instead of using static monitoring rules, the system continuously learns from observed service behavior patterns and updates its baselines accordingly. When services evolve or change their operational characteristics, the monitoring system detects these changes and adjusts its anomaly detection parameters dynamically, maintaining accuracy despite rapid service evolution.

Inventive Principle:
Principle #15Dynamics

4Reliability

If service consumers experience latency or interrupts, then service reliability deteriorates, but diagnostic capability worsens

Engineering Contradiction:
Improveservice reliabilityVSAvoiddiagnostic capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The monitoring service implements comprehensive feedback mechanisms that collect information about service consumer behavior, service provider responses, and interaction patterns. By continuously analyzing feedback logs from both service consumers and providers, the system can trace the root causes of latency and interrupts. The feedback mechanism enables the monitoring system to identify whether issues stem from service consumer problems, service provider failures, or network conditions, thereby improving diagnostic capability even when service reliability deteriorates.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8625757B1Monitoring services and service consumers
Publication Date: 2014.01.07 AMAZON TECH INC
  • US8625757B1 patent drawing
  • US8625757B1 patent drawing
  • US8625757B1 patent drawing

AI summary

A monitoring service may receive, from a plurality of service providers, log information pertaining to access calls made by service consumers to services or APIs provided by the service providers. The monitoring service aggregates and analyzes the log information for use in monitoring performance of the services, identifying anomalies, and the like. In some instances, the monitoring service may identify multiple services that are behaviorally interrelated based on at least one performance metric, and may group these services together into service groups for monitoring purposes. A service relationship model may be generated for each of the service groups that predicts how each service will behave relative to the other services in the service group. The monitoring service may monitor performance and use of the services based, at least in part, on the one or more service groups and the service relationship model for each group.