×

DETECTION METHOD AND INFORMATION PROCESSING DEVICE

  • US 20170097863A1
  • Filed: 10/03/2016
  • Published: 04/06/2017
  • Est. Priority Date: 10/05/2015
  • Status: Active Grant
First Claim
Patent Images

1. A method for detecting an anomaly in a computer system, the method comprising:

  • generating a plurality of pieces of correlation information based on correlations between changes in each item in each of different pairs of items in a plurality of items per unit period of time in a time series, each item relating to at least one of an operation, a performance, or a load in the computer system, each of the plurality of pieces of correlation information being generated for the plurality of items in one unit period of time in the time series;

    clustering the plurality of pieces of correlation information into a plurality of clusters, each cluster representing a state of the computer system and including a subset of the plurality of pieces of correlation information meeting a threshold for similarity;

    generating transition probabilities between each pair of the plurality of clusters; and

    determining the anomaly in the computer system based on the transition probability from one of the plurality of clusters in a first unit period of time to another one of the plurality of clusters in a second unit period of time.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×