The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Nov. 19, 2024

Filed:

Sep. 09, 2022
Applicant:

International Business Machines Corporation, Armonk, NY (US);

Inventors:

Lu An, Raleigh, NC (US);

An-Jie Andy Tu, Campbell, CA (US);

Xiaotong Liu, San Jose, CA (US);

Anbang Xu, San Jose, CA (US);

Rama Kalyani T. Akkiraju, Cupertino, CA (US);

Neil H. Boyette, Oregon City, OR (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 9/40 (2022.01); G06F 11/16 (2006.01); G06F 18/2411 (2023.01); H04L 41/0604 (2022.01); H04L 41/0631 (2022.01); H04L 43/0817 (2022.01);
U.S. Cl.
CPC ...
H04L 63/1425 (2013.01); G06F 11/16 (2013.01); G06F 18/2411 (2023.01); H04L 41/0627 (2013.01); H04L 41/0645 (2013.01); H04L 43/0817 (2013.01);
Abstract

A computer-implemented method, a computer program product, and a computer system for log anomaly detection. A computer receives a windowed log of incoming raw log messages. A computer compares statistical distribution metrics of entities in the windowed log with a statistical distribution extracted from a real-time statistical model for the entities. In response to the statistical distribution metrics being statistically different from the statistical distribution extracted from the real-time statistical model for the entities, a computer tags the windowed log as an entity anomaly. A computer computes a distance between an average word embedding vector in the windowed log and a statistical distribution extracted form a real-time statistical model for word embeddings. In response to the distance being greater than a predetermined threshold, a computer tags the windowed log as a word embedding anomaly. A computer sends to a user an alert with an anomaly severity level.


Find Patent Forward Citations

Loading…