Parallel Anomaly Detection Device with Associative Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing anomaly detection methods in monitored systems, such as plants, face challenges in making comprehensive determinations at an early stage due to differences in detection timings across various types of monitored data, leading to delayed identification of anomalies.
Innovation Solution
An anomaly detection device with parallel detection units for different types of monitored data, storing and associating anomalous data to enable early comprehensive determination by retrieving relevant data when an anomaly is detected.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If anomaly detection is performed using multiple types of monitored data in parallel, then comprehensive determination capability is improved, but detection timing synchronization deteriorates causing delayed comprehensive determination
Solution Approach 1:
The patent applies preliminary action by storing anomalous data from different monitored data types in advance in a storage unit before comprehensive determination is needed. When an anomaly is detected in one data type, the system can immediately retrieve previously stored anomalous data from other types without waiting for their detection cycles, enabling timely comprehensive determination while maintaining parallel monitoring of multiple data types
2Speed
If anomaly detection uses measured values of performance indexes, then early anomaly detection is improved, but cause identification capability deteriorates
Solution Approach 1:
The patent merges multiple types of monitored data including measured values of performance indexes, system logs, and SNS information into a unified anomaly detection system. By combining these different data types with complementary characteristics, the system achieves both early anomaly detection (from performance indexes) and cause identification (from system logs and SNS information) simultaneously through comprehensive determination
3Loss of information
If anomaly detection uses system logs, then cause identification is improved, but early detection capability deteriorates
Solution Approach 1:
The patent introduces an intermediary storage unit that holds anomalous data from different monitored data types. This storage unit acts as a mediator that allows the system to retrieve previously detected anomalies from system logs and other sources when anomalies are detected in performance indexes, enabling fast comprehensive determination without requiring real-time synchronization of all data types
Data Source
AI summary
A first anomaly detection unit detects anomalous first monitored data from among a plurality of first monitored data obtained from a monitored system. A second anomaly detection unit operates in parallel with the first anomaly detection unit and detects anomalous second monitored data from among a plurality of second monitored data obtained from the monitored system. In a first storage unit, the anomalous first monitored data and the anomalous second monitored data detected before lapse of a given time from detection time of the anomalous first monitored data are stored in association with each other. A first determination unit, when the anomalous first monitored data is detected, retrieves the anomalous second monitored data associated with the detected anomalous first monitored data from the first storage unit and outputs a first anomaly detection result including the retrieved anomalous second monitored data and the detected anomalous first monitored data.


