Ontology-Based Root Cause Analysis for Business Application Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for diagnosing faults in business network nodes are insufficient as they only consider direct cause-and-effect relationships, leading to inappropriate remedial actions when indirect relationships are involved, causing the root cause of failures to be overlooked.

Innovation Solution

The system generates an ontology of business application nodes and their relationships, using data collection agents to monitor connections and state changes, allowing for the identification of both direct and indirect root causes of errors, enabling accurate fault diagnosis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional direct cause-and-effect monitoring is used, then the monitoring method is simple, but the root cause detection accuracy deteriorates when indirect relationships are involved

Engineering Contradiction:
Improveroot cause detection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the monitoring system into multiple intelligence levels: edge intelligence at individual nodes for local anomaly detection, cluster intelligence for intermediate analysis, and cloud intelligence for comprehensive root cause determination. This segmentation allows the system to achieve high detection accuracy through distributed analysis while managing complexity through hierarchical organization of monitoring functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cluster intelligence as an intermediary layer between edge nodes and cloud infrastructure. This intermediary performs intermediate analysis of anomalies detected at edge nodes, filtering and preprocessing data before sending to the cloud, thereby improving root cause detection accuracy while reducing the computational burden and complexity at any single level.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive node relationship analysis is implemented, then fault diagnosis accuracy improves, but the analysis time increases

Engineering Contradiction:
Improvefault diagnosis accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by continuously building and maintaining an ontology model of node relationships, traffic patterns, and dependencies in advance. When faults occur, the system can immediately query this pre-established model rather than analyzing relationships from scratch, thereby achieving high fault diagnosis accuracy while minimizing analysis time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies dynamics by implementing real-time adaptation of the ontology model based on changing network conditions, traffic patterns, and node states. The system dynamically updates relationship weights and anomaly thresholds, allowing comprehensive analysis to remain accurate while adapting to current system state, thus reducing the time needed for accurate fault diagnosis.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8656219B2System and method for determination of the root cause of an overall failure of a business application service
Publication Date: 2014.02.18 RED HAT INC
  • US8656219B2 patent drawing
  • US8656219B2 patent drawing
  • US8656219B2 patent drawing

AI summary

An ontology is generated for a business application on an enterprise network that describes one or more nodes that communicate with each other during the execution of the business application. An alert condition of the business application is detected, and the ontology for the business application is processed to determine one or more components of the ontology that are in an alert state. Further, a root cause view that indicates the one or more alert state components is generated and displayed to a user.