Causality Service for Web Service Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and configuring web services applications is complex due to the need for logging, monitoring, and retaining account activity, often resulting in operational incidents and unusual behavior that are difficult to detect and address.

Innovation Solution

An insights and causality service using machine learning to analyze application data and API calls, identifying anomalies and providing actionable recommendations for remediation by determining causality between events and metrics, thus helping to detect operational incidents and risks proactively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If machine learning analysis is implemented to detect anomalies and determine causality, then detection precision and reliability are improved, but device complexity and computational resources increase

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the complex anomaly detection task into multiple specialized components: an anomaly detection service that identifies unusual patterns, a causality determination service that analyzes causal relationships, and a recommendation service that provides remediation guidance. This segmentation allows each component to focus on a specific aspect of the problem, improving detection precision while managing overall system complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary causality determination service that acts as a mediator between anomaly detection and remediation recommendation. This intermediary component analyzes the causal relationships between detected anomalies and potential root causes, bridging the gap between symptom detection and solution provision, thereby enhancing measurement precision without requiring the entire system to be fundamentally complex.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If comprehensive logging and monitoring are implemented to track account activity, then information completeness is improved, but data storage requirements and processing overhead increase

Engineering Contradiction:
Improveinformation completenessVSAvoiddata storage requirements
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The system extracts only the most relevant information from comprehensive logs and monitoring data using the anomaly detection service. Instead of storing and processing all account activity data, the service identifies and extracts unusual patterns and anomalies, thereby maintaining information completeness for detection purposes while significantly reducing the quantity of data that needs to be retained and processed.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by implementing monitoring and logging at selective levels. The system performs comprehensive analysis only when anomalies are detected, rather than continuously processing all data at full depth. This allows the system to maintain information completeness when needed while reducing average data processing overhead and storage requirements during normal operation.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11422882B1Systems, methods, and apparatuses for determining causality for anomalies and/or events
Publication Date: 2022.08.23 AMAZON TECH INC
  • US11422882B1 patent drawing
  • US11422882B1 patent drawing
  • US11422882B1 patent drawing

AI summary

Techniques for determining causality are described. An exemplary method includes receiving a request to determine a cause of an unhealthy system; receiving one or more of anomaly information and event information associated with the unhealthy system; evaluating the received one or more of the anomaly information and event information associated with the unhealthy system to determine there is a known causality between anomalies or events leading to the unhealthy system; and providing a causality indication for the known causality, the causality indication including an identification of a causality source and a causality target.