Computer system and method for detecting regularly occurring alarms in automation and industrial control systems
Computer monitoring system and method for determining one or more clusters of regularly occurring time periods for alarm events contained in alarm data that includes alarm change of state event and an associated time stamp for each alarm change of state event, wherein each regularly occurring time period is sampled to include a same number of time spaced intervals. Detect alarm events contained in each time spaced interval to associate each time spaced interval with a value dependent upon the detected zero or more alarm events in this interval. Determine vector of alarm state values for each regularly occurring time period. Determine a distance metric between each pair of respective regularly occurring time periods based on the determined vectors of alarm state values. Determine one or more clusters of regularly occurring time periods of alarm events in the defined time period based upon analysis of the determined distance metric.
1 . A computer monitoring system for determining one or more clusters of regularly occurring time periods for alarm events, for alarm data in a computer database managed by an automated and industrial control (AIC) system, wherein each regularly occurring time period is defined by a same number of time spaced intervals, comprising:
one or more storage devices having instructions stored thereon that, when executed by one or more processors, cause the one or more processors to:
capture from the computer database, alarm data for each of a plurality of regularly occurring time periods contained in a defined time period, wherein the captured alarm data includes alarm change of state events and an associated time stamp for each of the alarm change of state events;
analyze the captured alarm data to detect alarm events contained in each time spaced interval, for each regularly occurring time period;
compute a vector of alarm state values for each regularly occurring time period such that an alarm state value is associated with a time spaced interval, dependent upon: 1) a detected alarm event when there is at least one detected alarm event in the associated time spaced interval; or 2) with at least one other alarm state value in a previous time spaced interval when there is no detected alarm event in the associated time spaced interval;
determine a distance metric between each pair of respective regularly occurring time periods based on the computed vectors of alarm state values in each respective pair of regularly occurring time periods;
determine one or more clusters of regularly occurring time periods of alarm events in the defined time period, based upon analysis of the determined distance metric between each pair of respective regularly occurring time periods; and
provide a tangible output identifying the determined one or more clusters of regularly occurring time periods of alarm events in the defined time period.
2 . The computer monitoring system as recited in claim 1 , wherein each value in the vector of alarm state values is computed as: 1) a “1” when a last alarm event in the associated time spaced interval is an alarm event; 2) a “0” when the last alarm event in the associated time spaced interval is a reset event; and 3) equal to a value of a previous time spaced interval containing alarm events when there are no alarm events in the associated time spaced interval.
3 . The computer monitoring system as recited in claim 1 , wherein each regularly occurring time period consists of a regularly reoccurring calendar defined period of time.
4 . The computer monitoring system as recited in claim 3 , wherein the calendar defined period of time consists of one of: a calendar day, a calendar week, or a calendar month.
5 . The computer monitoring system as recited in claim 1 , wherein the time spaced intervals are one (1) minute time intervals.
6 . The computer monitoring system as recited in claim 1 , wherein the AIC is one of either a building management system (BMS) or a supervisory control and data acquisition (SCADA) system.
7 . The computer monitoring system as recited in claim 1 , wherein the alarm data is networked captured via a communications network.
8 . The computer monitoring system as recited in claim 1 , wherein the distance metric is a hamming distance.
9 . The computer monitoring system as recited in claim 8 , wherein determining the hamming distance between each successive time spaced regularly occurring time period further includes normalizing each hamming distance.
10 . The computer monitoring system as recited in claim 1 , wherein determining one or more clusters of regularly occurring time periods of alarm events includes:
analyze each cluster of regularly occurring time periods of alarm events to determine certain metadata associated with each cluster; and
analyze the determined metadata for each cluster of regularly occurring time periods of alarm events to identify one or more clusters as a valid alarm periodicity cluster.
11 . The computer monitoring system as recited in claim 10 , whereby the tangible output identifies only valid clusters.
12 . The computer monitoring system as recited in claim 1 , wherein the one or more processors are further configured to determine clusters of regularly occurring time periods of alarm events in the defined time period using a plurality of unsupervised learning clustering algorithms.
13 . The computer monitoring system as recited in claim 12 , wherein at least one unsupervised learning algorithm consists of agglomerative techniques.
14 . The computer monitoring system as recited in claim 12 , wherein each unsupervised learning algorithm consists of one of a k-means clustering algorithm, k-medoids clustering algorithm, agglomerative clustering, or spectral clustering.
15 . The computer monitoring system as recited in claim 12 , wherein the unsupervised learning clustering algorithms, and their respective hyperparameter value(s), are selected according to a clustering goodness metric, whereby the unsupervised learning clustering algorithm and hyperparameter value(s) leading to the highest score value is selected for determining the clusters of similar regularly occurring time periods of alarm data to be analyzed.
16 . The computer monitoring system as recited in claim 13 , wherein the one or more processors are further configured to compute an artificial intelligence (AI) goodness measurement metric for each of the unsupervised learning clustering algorithms, whereby the unsupervised clustering algorithm having a highest score value is selected for determining the clusters of similar regularly occurring time periods of alarm data to be analyzed.
17 . The computer monitoring system as recited in claim 16 , wherein the AI goodness measurement metric is one of a Silhouette score, a Calinski-Harabasz Index, or a Davies-Bouldin index, or a combination thereof.
18 . The computer monitoring system as recited in claim 1 , wherein providing a tangible output includes causing a graphical user interface (GUI) to be generated on a computer display graphically indicating each identified valid cluster of regularly occurring time periods of alarm events.
19 . A computer-implemented method for determining one or more clusters of regularly occurring time periods for alarm events, for alarm data in a computer database managed by an automated and industrial control (AIC) system, wherein each regularly occurring time period is defined by a same number of time spaced intervals, comprising:
capturing, in a computer processor, from the computer database, alarm data for each of a plurality of regularly occurring time periods contained in a defined time period, wherein the captured alarm data includes alarm change of state events and an associated time stamp for each of the alarm change of state events;
analyzing, in the computer processor, the captured alarm data to detect alarm events contained in each time spaced interval, for each regularly occurring time period;
computing, by the computer processor, a vector of alarm state values for each regularly occurring time period such that an alarm state value is associated with a time spaced interval, dependent upon: 1) a detected alarm event when there is at least one detected alarm event in the associated time spaced interval; or 2) with at least one other alarm state value in a previous time spaced interval when there is no detected alarm event in the associated time spaced interval;
determining, by the computer processor, a distance metric between each pair of respective regularly occurring time periods based on the computed vectors of alarm state values in each respective pair of regularly occurring time periods;
determining, by the computer processor, one or more clusters of regularly occurring time periods of alarm events in the defined time period, based upon analysis of the determined distance metric between each pair of respective regularly occurring time periods; and
providing, by the computer processor, a tangible output identifying the determined one or more clusters of regularly occurring time periods of alarm events in the defined time period.
20 . The computer-implemented method as recited in claim 19 , wherein each value in the vector of alarm state values is computed as: 1) a “1” when a last alarm event in the associated time spaced interval is an alarm event; 2) a “0” when the last alarm event in the associated time spaced interval is a reset event; and 3) equal to a value of a previous time spaced interval containing alarm events when there are no alarm events in the associated time spaced interval.
21 . The computer-implemented method as recited in claim 19 , wherein each regularly occurring time period consists of a regularly reoccurring calendar defined period of time.
22 . The computer-implemented method as recited in claim 21 , wherein the calendar defined period of time consists of one of: a calendar day, a calendar week, or a calendar month.
23 . The computer-implemented method as recited in claim 19 , wherein the time spaced intervals are one (1) minute time intervals.
24 . The computer-implemented method as recited in claim 19 , wherein the AIC is one of a building management system (BMS) or a supervisory control and data acquisition (SCADA) system.
25 . The computer-implemented method as recited in claim 19 , wherein the alarm data is networked captured via a communications network.
26 . The computer-implemented method as recited in claim 19 , wherein the distance metric is a hamming distance.
27 . The computer-implemented method as recited in claim 26 , wherein determining the hamming distance between each successive time spaced regularly occurring time period further includes normalizing each hamming distance.
28 . The computer-implemented method as recited in claim 19 , wherein determining one or more clusters of regularly occurring time periods of alarm events further includes:
analyzing each cluster of regularly occurring time periods of alarm events to determine certain metadata associated with each cluster; and
analyzing the determined metadata for each cluster of regularly occurring time periods of alarm events to identify one or more clusters as a valid alarm periodicity cluster.
29 . The computer-implemented method as recited in claim 28 , whereby the tangible output identifies only valid clusters.
30 . The computer-implemented method as recited in claim 19 , further including determining clusters of regularly occurring time periods of alarm events in the defined time period using a plurality of unsupervised learning clustering algorithms.
31 . The computer-implemented method as recited in claim 30 , wherein at least one unsupervised learning algorithm consists of agglomerative techniques.
32 . The computer-implemented method as recited in claim 30 , wherein each unsupervised learning algorithm consists of one of a k-means clustering algorithm, k-medoids clustering algorithm, agglomerative clustering, or spectral clustering.
33 . The computer-implemented method as recited in claim 30 , wherein the unsupervised learning clustering algorithms, and their respective hyperparameter value(s), are selected according to a clustering goodness metric, whereby the unsupervised learning clustering algorithm and hyperparameter value(s) leading to the highest score value is selected for determining the clusters of similar regularly occurring time periods of alarm data to be analyzed.
34 . The computer-implemented method as recited in claim 33 , wherein the clustering goodness metric is a Silhouette score, a Calinski-Harabasz Index, a Davies-Bouldin index, or a combination thereof.
35 . The computer-implemented method as recited in claim 31 , the method further comprising computing an artificial intelligence (AI) goodness measurement metric for each of the unsupervised learning clustering algorithms, whereby the unsupervised clustering algorithm having a highest score value is selected for determining the clusters of similar regularly occurring time periods of alarm data to be analyzed.
36 . The computer-implemented method as recited in claim 19 , wherein providing a tangible output includes causing a graphical user interface (GUI) to be generated on a computer display graphically indicating each identified valid cluster of regularly occurring time periods of alarm events.