Performance Anomaly Detection via Trend Removal and Clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and improving the performance and availability of large-scale computing systems, such as cloud platforms, is challenging due to their heterogeneity and complexity, making it difficult to monitor key performance metrics and detect anomalies effectively.

Innovation Solution

A computer-implemented method and apparatus that detects trends in performance metrics, removes them to generate modified data, and uses a behavior clustering model to identify performance anomalies, facilitating accurate and efficient anomaly detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If monitoring data is collected from multiple independently developed computing devices with diverse hardware configurations, then the system can achieve comprehensive performance monitoring, but the complexity of detecting anomalies increases significantly

Engineering Contradiction:
Improveperformance monitoring coverageVSAvoidanomaly detection complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms heterogeneous monitoring data from diverse hardware configurations into a unified representation by removing trends and normalizing the data. This creates a homogeneous input format for the behavior clustering model, enabling consistent anomaly detection across different device types while maintaining comprehensive monitoring coverage

Inventive Principle:
Principle #33Homogeneity

Solution Approach 2:

The patent introduces a behavior clustering model as an intermediary layer between raw monitoring data and anomaly detection. This model learns normal behavior patterns from historical data and serves as a mediator to identify deviations, simplifying the detection process in heterogeneous environments

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If trend removal is applied to monitoring data to improve anomaly detection accuracy, then false positives are reduced, but additional data processing steps are required

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoiddata processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts and removes trends from monitoring data before feeding it to the behavior clustering model. By separating the trend component from the raw data, the system improves anomaly detection accuracy by focusing on deviations from expected patterns rather than absolute values, while keeping the processing pipeline manageable

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11269714B2Performance anomaly detection
Publication Date: 2022.03.08 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11269714B2 patent drawing
  • US11269714B2 patent drawing
  • US11269714B2 patent drawing

AI summary

Embodiments facilitating performance anomaly detection are described. A computer-implemented method comprises: detecting, by a device operatively coupled to one or more processing units, based on monitoring data of a plurality of performance metrics of a monitored device, at least one trend within the monitoring data of the respective performance metrics; removing, by the device, the at least one trend from the monitoring data of the respective performance metrics to generate modified data of the respective performance metrics; and detecting, by the device, a performance anomaly based on the modified data of the respective performance metrics and a behavior clustering model comprising at least one steady state.