Anomaly Detection in Cloud Network Data Streams

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing platforms face challenges in managing network stability due to scale and heterogeneity, with existing methods relying on heavy computational loads and human review, which are inefficient in detecting anomalies in real-time.

Innovation Solution

A system and method for machine-driven, real-time discovery of aberrant states using a decision support system that processes data streams from network devices, builds historic models, predicts future values, and detects anomalies by determining variations exceeding a threshold, updating models accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If heavy computational loads and human review are used to detect anomalies, then measurement precision is improved, but productivity deteriorates

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidreal-time detection efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system employs machine learning models that automatically learn from historical data and autonomously detect anomalies without requiring human review. The models self-improve by continuously training on new data, enabling the system to maintain high detection accuracy while operating independently, thus resolving the contradiction between precision and productivity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual human review processes with automated machine learning algorithms. This substitution eliminates the need for human computational effort while maintaining or improving detection accuracy through sophisticated pattern recognition, thereby achieving both high precision and productivity simultaneously.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If machine learning models are trained on historical data, then adaptability is improved, but loss of time occurs during model building

Engineering Contradiction:
Improvemodel adaptability to different conditionsVSAvoidtime for building historic models
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously training machine learning models on historical data in advance, before anomalies need to be detected. This proactive approach ensures models are already adapted and ready for real-time detection, eliminating delays associated with last-minute model building while maintaining high adaptability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous model training and updating processes that operate continuously in the background. This ensures models remain adaptively tuned to current conditions without interrupting anomaly detection operations, thereby maintaining both adaptability and avoiding time loss through seamless continuous operation.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10438124B2Machine discovery of aberrant operating states
Publication Date: 2019.10.08 CENTURYLINK INTELLECTUAL PROPERTY LLC
  • US10438124B2 patent drawing
  • US10438124B2 patent drawing
  • US10438124B2 patent drawing

AI summary

Novel tools and techniques for the machine discovery of aberrant states are provided. A system includes a plurality of network devices, and a decision system in communication with the plurality of network devices. Each of the plurality of network devices may be configured to generate a respective data stream. The decision system may include a processor and a non-transitory computer readable medium including instructions executable by the processor to obtain, via the plurality of network devices, one or more data streams. The decision system may build a historic model of a data stream, and determine a predicted value of the data stream at a future time, based on the historic model. The decision system may be configured to determine whether an anomaly has occurred based on a variation between a current value of the data stream and the predicted value of the data stream.