Hierarchical Transaction Classification for Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Monitoring systems face challenges in identifying and optimizing sets of multidimensional transaction categories due to the vast number of possible context factor combinations, leading to impracticality in monitoring all categories, with many containing insufficient transactions for reliable statistical analysis.
Innovation Solution
A system that determines an optimal set of transaction categories using a hierarchical classification space, merging specific categories into more generic ones to maximize transaction frequency and efficiently use monitoring capacities, while maintaining a predictable CPU and memory footprint for real-time processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If all possible transaction categories are monitored, then complete transaction classification coverage is achieved, but the system complexity and resource requirements become impractical
Solution Approach 1:
The patent segments the vast transaction classification space into hierarchical groups and subgroups. Instead of monitoring all possible categories simultaneously, the system divides them into manageable segments that can be processed independently, reducing overall system complexity while maintaining comprehensive coverage.
Solution Approach 2:
The patent applies local quality by assigning different monitoring depths to different transaction categories based on their characteristics. High-frequency categories receive more detailed monitoring while low-frequency categories are aggregated, optimizing resource allocation across the classification space.
2Measurement precision
If specific transaction categories are monitored, then detailed analysis is possible, but insufficient transaction data prevents reliable statistical analysis
Solution Approach 1:
The patent merges multiple specific transaction categories into broader groups when individual categories have insufficient transaction data. This combining approach ensures that statistical analysis can be performed reliably by aggregating data across related categories while preserving the ability to drill down to specific categories when sufficient data exists.
3Reliability
If transaction categories are merged into generic groups, then sufficient transaction data is available for statistical analysis, but loss of specific transaction information occurs
Solution Approach 1:
The patent implements a nested hierarchy where specific transaction categories are contained within broader groups, which are in turn contained within even broader categories. This nested structure allows the system to navigate between different levels of granularity, using specific categories when possible and falling back to broader groups when necessary, thereby preserving information at multiple levels simultaneously.
4Adaptability or versatility
If monitoring capacity is increased to track more categories, then more transaction categories can be monitored, but resource consumption and processing overhead increase
Solution Approach 1:
The patent applies partial action by monitoring only the most relevant transaction categories at any given time rather than all possible categories continuously. The system dynamically adjusts which categories are actively monitored based on current transaction patterns, ensuring sufficient monitoring coverage while avoiding the resource overhead of monitoring every possible category at maximum depth.
Data Source
AI summary
A system and method is disclosed that analyzes a set of historic transaction traces to identify an optimized set of transaction clusters with the highest transaction frequency. The transaction clusters are defined according to multiple parameters describing the execution context of the analyzed transactions. The transaction clusters are described by coordinates in a multidimensional, hierarchical classification space. Descriptive statistical data is extracted from historic transactions corresponding to previously identified transaction clusters and stored as reference data. Transaction trace data from currently executed transactions is analyzed to find a best matching historic transaction cluster. The current transaction traces are grouped according to their corresponding historic transaction cluster. Statistical data is extracted from those groups of current transaction trace and statistical test are performed that compare current and historic data on a per historic transaction cluster basis to identify deviations in performance and functional behavior of current and historic transactions.


