Ontology Knowledge Graph for Computer Incident Prediction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Complex computer systems face challenges in managing incidents due to non-homogeneous data sources and the risk of manual monitoring being incomplete and non-optimal, which can lead to undetected cyber risks.
Innovation Solution
A knowledge graph is constructed based on a predetermined ontology to integrate incident data and semantic connections, enabling homogeneous processing and the use of graph processing methods to analyze and predict potential incidents, thereby identifying risky applications and preventing major incidents.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual incident management is used in complex computer systems, then operational flexibility is maintained, but monitoring completeness and risk detection capability deteriorate
Solution Approach 1:
The system segments incident management into automated data collection from multiple sources, knowledge graph construction with standardized schemas, and AI-driven analysis components. This segmentation enables comprehensive monitoring while maintaining operational flexibility through modular architecture.
Solution Approach 2:
A knowledge graph serves as an intermediary layer between heterogeneous data sources and incident management processes. It standardizes diverse data into unified schemas, enabling complete monitoring without sacrificing operational flexibility.
2Quantity of substance
If data is collected from multiple disconnected software systems, then data coverage is improved, but data homogeneity and processing efficiency deteriorate
Solution Approach 1:
The knowledge graph implements universal schemas that can accommodate multiple data sources with different formats. A single graph structure handles diverse incident data, system logs, and metadata from disconnected software systems, enabling broad data coverage without proportional increases in processing complexity.
Solution Approach 2:
The system transforms heterogeneous data parameters into standardized schemas through the knowledge graph. Different data sources are converted into unified parameter structures, allowing efficient processing while maintaining comprehensive data coverage.
3Ease of manufacture
If traditional incident management methods are used, then implementation simplicity is maintained, but accuracy in determining application risk deteriorates
Solution Approach 1:
The system employs self-service mechanisms where the knowledge graph automatically constructs itself from collected data, and AI algorithms autonomously analyze patterns to assess application risk. This maintains implementation simplicity while achieving high risk assessment accuracy through automated intelligence.
Solution Approach 2:
Traditional manual risk assessment mechanisms are replaced with AI-driven analysis of the knowledge graph. The system substitutes human analysis with automated machine learning models that process graph data to determine application risk, significantly improving measurement precision.
Data Source
Figure 1
Figure 2
AI summary
The method (200) serves to manage computer incidents linked to an application in a computer system, and comprises the steps of: a) constructing (220) a knowledge graph of the computer system based on a predetermined ontology, b) selecting (230) by traversing said knowledge graph computer incident linked to said application in a time interval, and constructing a past time series of incidents, c) determining (240) from said past time series of incidents a future time series of incidents based on a statistical analysis, d) making (250) a comparison of a trend of said future time series of incidents with respect to a trend of said past time series of incidents taking into account a variability of said past time series of incidents, and) on the basis of said comparison deciding (260) whether said application is safe or risky and consequently reporting said application; the ontology-based knowledge graph allows to store in an integrated way not simply data relative to incidents, but also connections between the data and semantics of the connections: in addition, constructing a knowledge graph starting from nonhomogeneous data and/or information allows a homogeneous processing despite the non-homogeneity of starting data and/or information.