Anomaly Detection in Computing Systems via Hierarchical Metric Learning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing systems face challenges in detecting performance anomalies automatically, as setting thresholds for metrics is cumbersome and requires expertise, especially in large environments where many applications and metrics make manual setting infeasible.

Innovation Solution

A system employing learning logic and state determination logic that uses a hierarchical model to automatically determine state determination functions from historical metrics, allowing for the detection of normal or abnormal behavior without requiring manual threshold setting, by minimizing description length through information-theoretic principles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual threshold setting is used for performance metrics, then detection accuracy can be maintained, but the complexity and time required for configuration increases significantly

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidthreshold configuration complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system automatically learns and determines threshold values for performance metrics without requiring manual configuration. The learning logic analyzes historical data and autonomously establishes appropriate thresholds, allowing the system to self-configure and eliminating the need for expert intervention in threshold setting.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary learning from historical metrics to establish baseline thresholds before actual anomaly detection occurs. This preliminary action of learning and adapting to historical patterns enables accurate future detection without requiring manual threshold configuration at runtime.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual threshold setting is performed for all metrics, then detection reliability improves, but the time required for setup and maintenance increases

Engineering Contradiction:
Improvedetection reliabilityVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system automatically learns and determines threshold values for performance metrics without requiring manual configuration. The learning logic analyzes historical data and autonomously establishes appropriate thresholds, allowing the system to self-configure and eliminating the need for expert intervention in threshold setting.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously learns from historical metric data and adjusts thresholds based on observed patterns. This feedback mechanism allows the system to adapt to changing conditions and maintain reliable detection without requiring manual reconfiguration when system behavior evolves.

Inventive Principle:
Principle #23Feedback

3Loss of time

If automated threshold determination is implemented, then configuration time is reduced, but the complexity of the detection system increases

Engineering Contradiction:
Improveconfiguration timeVSAvoiddetection system complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent replaces manual mechanical threshold configuration with an automated learning system that uses information-theoretic principles. The learning logic substitutes human expertise and manual setup with algorithmic analysis of historical data, reducing configuration time while managing complexity through systematic learning approaches.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system transforms static manual threshold parameters into dynamic, learned parameters that automatically adapt to historical data patterns. By changing from fixed manual configuration to adaptive parameter learning, the system reduces configuration time while managing complexity through automated parameter determination.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If comprehensive monitoring of all metrics is implemented, then detection coverage improves, but the difficulty of managing and maintaining the system increases

Engineering Contradiction:
Improvemonitoring coverageVSAvoidsystem management ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system automatically learns and determines threshold values for performance metrics without requiring manual configuration. The learning logic analyzes historical data and autonomously establishes appropriate thresholds, allowing the system to self-configure and eliminating the need for expert intervention in threshold setting.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary learning from historical metrics to establish baseline thresholds before actual anomaly detection occurs. This preliminary action of learning and adapting to historical patterns enables accurate future detection without requiring manual threshold configuration at runtime.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7577550B2System and method for detecting performance anomalies in a computing system
Publication Date: 2009.08.18 HEWLETT PACKARD ENTERPRISE DEV LP
  • US7577550B2 patent drawing
  • US7577550B2 patent drawing
  • US7577550B2 patent drawing

AI summary

A method comprises receiving, by learning logic, historical metrics of a computing system being monitored. The learning logic determines, from the received historical metrics, forms of sub-functions that are included in an equation, wherein each sub-function represents a dependency between two components linked in a hierarchical structure representing the computing system being monitored. State determination logic receives metric values of the computing system being monitored, and determines states that minimize the equation composed of the sub-functions over the received metric values. Finally, anomalous behavior of the computing system may be detected based on the determined states.