Anomaly Detection Server System Dynamic Thresholds
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Monitoring and detecting anomalies in the operating parameters of multiple servers is challenging due to difficulties in determining normal and anomalous measurements, often relying on anecdotal evidence or incorrect assumptions about environmental conditions.
Innovation Solution
Anomaly detection server system with a metric analyzer module and user interface module that dynamically calculates reference values and tolerable ranges based on environmental variables, allowing for real-time monitoring and notification of anomalies in server operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional monitoring systems with fixed thresholds are used, then anomaly detection is simplified, but the accuracy of anomaly detection deteriorates due to reliance on anecdotal evidence and incorrect assumptions about environmental conditions
Solution Approach 1:
The patent implements dynamic threshold adjustment by continuously learning the normal operating range of servers using statistical methods. Instead of fixed thresholds, the system adapts thresholds based on historical data and environmental variables, allowing the monitoring system to evolve with changing server conditions while maintaining operational simplicity.
Solution Approach 2:
The system changes the parameters used for anomaly detection by incorporating multiple environmental variables (CPU usage, memory usage, disk I/O, network traffic) and using statistical parameters (mean, standard deviation, percentiles) to dynamically determine thresholds. This transforms the static threshold approach into a multi-parameter dynamic system that improves accuracy without complicating operation.
2Measurement precision
If dynamic calculation of reference values based on environmental variables is implemented, then anomaly detection accuracy is improved, but system complexity increases
Solution Approach 1:
The monitoring system performs self-service by automatically learning and adapting to each server's normal operating patterns without requiring manual configuration. The system autonomously collects historical data, calculates statistical parameters, determines dynamic thresholds, and adjusts monitoring parameters automatically, reducing the need for expert intervention while improving detection accuracy.
Solution Approach 2:
The system implements feedback loops where anomaly detection results and historical performance data are continuously fed back into the learning mechanism. This feedback enables the system to refine its understanding of normal vs. anomalous behavior over time, improving accuracy while the automated feedback process manages the complexity of dynamic calculations.
3Reliability
If comprehensive monitoring of multiple server parameters is performed, then detection coverage is improved, but the difficulty of determining normal versus anomalous measurements increases
Solution Approach 1:
The patent segments the complex monitoring task by creating separate metric analyzer modules for different types of servers (web servers, database servers, etc.) and different performance metrics. Each module specializes in analyzing specific parameters, breaking down the overall complexity into manageable segments while maintaining comprehensive coverage across all server types and metrics.
Solution Approach 2:
The system implements a universal anomaly detection framework that can handle multiple server types and parameters through a common statistical learning mechanism. The core detection engine serves multiple functions by adapting to different server configurations and parameter sets, reducing overall system complexity while maintaining comprehensive detection coverage across diverse environments.
Data Source
AI summary
Systems and methods are provided for analyzing operating metrics of monitored metric sources. Aspects of the present disclosure may present for display information associated with the monitored metric source and the analysis of its operating metrics. Analysis comprises determination of reference values and tolerance levels which represent allowable deviations from the reference values. Input data includes a measurement of an operating parameter and a time stamp. Input data may be saved to a data store for using in future analysis of other input data. When input data is determined to be outside the tolerance level, notifications may be issued to alert administrators or systems of the anomaly.


