US2021397982A1PendingUtilityA1

Intelligent anomaly identification and alerting system based on smart ranking of anomalies

Assignee: CISCO TECH INCPriority: May 11, 2016Filed: Sep 1, 2021Published: Dec 23, 2021
Est. expiryMay 11, 2036(~9.8 yrs left)· nominal 20-yr term from priority
G06F 11/0769G06F 11/3476G06F 11/3409G06F 11/0772G06F 11/30G06F 11/32G06N 5/025G06F 2201/81
62
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for ranking detected anomalies is disclosed. The method includes generating a graph based on a plurality of rules, wherein the graph comprises nodes representing metrics identified in the rules, edges connecting nodes where metrics associated with connected nodes are identified in a given rule, and edge weights of the edges each representing a severity level assigned to the given rule. The method further includes ranking nodes of the graph based on the edge weights. The method further includes ranking detected anomalies based on the ranking of the nodes corresponding to the metrics associated with the detected anomalies.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for ranking detected anomalies, the method comprising:
 defining a plurality of rules;   generating a graph of the plurality of rules, comprising:
 creating a plurality of nodes, each of the nodes corresponding to a metric of the plurality of rules, the rules including a first rule in which a single metric is a potential source of an anomaly and a second rule in which a pair of metrics is a potential source of anomaly; 
 connecting, for each node corresponding to a single metric of the rules, the corresponding each node to itself with an edge; 
 connecting, for each pair of metrics of the second rules, the corresponding pair of nodes with edges; 
 assigning each of the edges with an edge weight corresponding to a severity level of the corresponding rule that defined the edge; 
   detecting anomalies by comparing system metrics relative to the rules; and   ranking detected anomalies based on the ranking of the nodes corresponding to the metrics of the graph;   wherein the defining occurs before the detecting.   
     
     
         2 . The method of  claim 1 , further comprising:
 alerting an end user of the detected anomalies based on the ranking of the detected anomalies.   
     
     
         3 . The method of  claim 1 , wherein the plurality of rules each comprises:
 at least one metric describing a state of one or more resources; and   at least one condition, wherein each condition is defined for a corresponding metric.   
     
     
         4 . The method of  claim 1 , wherein the detected anomalies are detected by observing for anomalous metrics and/or anomalous log through statistical analysis. 
     
     
         5 . The method of  claim 1 , wherein edges are defined in the graph when two or more metrics and their corresponding conditions are connected in a given rule via a logical operation. 
     
     
         6 . The method of  claim 1 , wherein value for a given edge weight of a given edge connecting two nodes varies depending on a type of logical operation which connects metrics corresponding to the two nodes. 
     
     
         7 . The method of  claim 1 , wherein ranking nodes comprises:
 computing an importance value for a given node based on all edge weights of edges connected to the given node; and   upon computing importance values for all nodes, ranking the nodes based on the importance values.   
     
     
         8 . A non-transitory computer-readable medium comprising one or more instructions that when executed on a processor cause the processor to perform operations comprising:
 define a plurality of rules;   generate a graph of the plurality of rules, comprising:
 create a plurality of nodes, each of the nodes corresponding to a metric of the plurality of rules, the rules including a first rule in which a single metric is a potential source of an anomaly and a second rule in which a pair of metrics is a potential source of anomaly; 
 connect, for each node corresponding to a single metric of the rules, the corresponding each node to itself with an edge; 
 connect, for each pair of metrics of the second rules, the corresponding pair of nodes with edges; 
 assign each of the edges with an edge weight corresponding to a severity level of the corresponding rule that defined the edge; 
   detect anomalies by comparing system metrics relative to the rules; and   rank detected anomalies based on the ranking of the nodes corresponding to the metrics of the graph;   wherein the define occurs before the detect.   
     
     
         9 . The non-transitory computer-readable medium of  claim 8 , the operations further comprising:
 alerting an end user of the detected anomalies based on the ranking of the detected anomalies.   
     
     
         10 . The non-transitory computer-readable medium of  claim 8 , wherein the plurality of rules each comprises:
 at least one metric describing a state of one or more resources; and   at least one condition, wherein each condition is defined for a corresponding metric.   
     
     
         11 . The non-transitory computer-readable medium of  claim 8 , wherein the detected anomalies are detected by observing for anomalous metrics and/or anomalous log through statistical analysis. 
     
     
         12 . The non-transitory computer-readable medium of  claim 8 , wherein edges are defined in the graph when two or more metrics and their corresponding conditions are connected in a given rule via a logical operation. 
     
     
         13 . The non-transitory computer-readable medium of  claim 8 , wherein value for a given edge weight of a given edge connecting two nodes varies depending on a type of logical operation which connects metrics corresponding to the two nodes. 
     
     
         14 . The non-transitory computer-readable medium of  claim 8 , wherein the operation of rank nodes comprises:
 compute an importance value for a given node based on all edge weights of edges connected to the given node; and   upon compute importance values for all nodes, rank the nodes based on the importance values.   
     
     
         15 . A system, comprising:
 a non-transitory computer readable media storing instructions;   a processor programmed to cooperate with the instructions to perform operations comprising:
 define a plurality of rules; 
 generate a graph of the plurality of rules, comprising:
 create a plurality of nodes, each of the nodes corresponding to a metric of the plurality of rules, the rules including a first rule in which a single metric is a potential source of an anomaly and a second rule in which a pair of metrics is a potential source of anomaly; 
 connect, for each node corresponding to a single metric of the rules, the corresponding each node to itself with an edge; 
 connect, for each pair of metrics of the second rules, the corresponding pair of nodes with edges; 
 assign each of the edges with an edge weight corresponding to a severity level of the corresponding rule that defined the edge; 
 
 detect anomalies by comparing system metrics relative to the rules; and 
 rank detected anomalies based on the ranking of the nodes corresponding to the metrics of the graph; 
 wherein the define occurs before the detect. 
   
     
     
         16 . The system of  claim 15 , the operations further comprising:
 alerting an end user of the detected anomalies based on the ranking of the detected anomalies.   
     
     
         17 . The system of  claim 15 , wherein the plurality of rules each comprises:
 at least one metric describing a state of one or more resources; and   at least one condition, wherein each condition is defined for a corresponding metric.   
     
     
         18 . The system of  claim 15 , wherein the detected anomalies are detected by observing for anomalous metrics and/or anomalous log through statistical analysis. 
     
     
         19 . The system of  claim 15 , wherein edges are defined in the graph when two or more metrics and their corresponding conditions are connected in a given rule via a logical operation. 
     
     
         20 . The system of  claim 15 , wherein value for a given edge weight of a given edge connecting two nodes varies depending on a type of logical operation which connects metrics corresponding to the two nodes.

Join the waitlist — get patent alerts

Track US2021397982A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.