Cloud Network Anomaly Detection via Dynamic Model Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern cloud environments face challenges in maintaining Service Level Objectives (SLOs) due to their complexity and dynamic nature, where static methods for detecting anomalous network events are insufficient for real-time monitoring.
Innovation Solution
The use of machine learning-based models for real-time network anomaly detection, involving the selection of multiple models to evaluate network states, provide actionable notifications, and adapt to changes in network patterns.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If static methods are used for detecting anomalous network events, then the detection method is simple and easy to implement, but the detection accuracy and real-time responsiveness are insufficient for complex cloud environments
Solution Approach 1:
The patent implements dynamic model selection where the system automatically chooses between different anomaly detection models (first model for normal operation, second model for pattern changes) based on real-time network conditions. This dynamic approach allows the system to adapt to changing network states, improving detection accuracy while managing complexity through conditional model switching rather than using a single complex model for all scenarios.
Solution Approach 2:
The system changes operational parameters by switching between different detection models based on network pattern parameters. When network patterns change (detected through monitoring), the system transitions from using a first model to a second model, effectively changing the detection approach parameter to match current network conditions, thereby improving accuracy without permanently increasing system complexity.
2Reliability
If multiple machine learning models are used to evaluate network states, then the detection accuracy and adaptability improve, but the computational overhead and processing time increase
Solution Approach 1:
The patent segments the anomaly detection task into two distinct phases handled by different models: (1) normal operation monitoring using a first model, and (2) pattern change detection using a second model. This segmentation allows each model to be optimized for its specific function, improving overall reliability while reducing time loss by avoiding the use of a single comprehensive model that would require processing all scenarios equally.
Solution Approach 2:
The system dynamically selects which model to apply based on real-time network conditions. The first model operates during normal conditions, and the second model is activated only when pattern changes are detected. This dynamic model selection reduces average processing time compared to continuously applying multiple models, while maintaining high reliability through appropriate model choice for each situation.
3Speed
If real-time monitoring of network parameters is implemented, then the responsiveness to anomalies improves, but the data processing load and system resource consumption increase
Solution Approach 1:
The monitoring system is segmented into different operational modes corresponding to different detection models. The first model handles normal real-time monitoring with lower processing requirements, while the second model is activated only during pattern changes. This segmentation reduces overall energy consumption by avoiding continuous high-intensity processing, while maintaining fast response speed through real-time monitoring capability in both modes.
Solution Approach 2:
The system employs periodic evaluation of network parameters at discrete or predetermined intervals rather than continuous monitoring. This periodic action reduces data processing load and energy consumption while maintaining effective real-time detection capability. The system evaluates network parameters periodically using the appropriate model based on current conditions, balancing speed and energy usage.
Data Source
AI summary
A cloud network is a complex environment in which hundreds and thousands of users or entities can each host, create, modify, and develop multiple virtual machines. Each virtual machine can have complex behavior unknown to the provider or maintainer of the cloud. Technologies disclosed include methods, systems, and apparatuses to monitor the complex environment to detect network anomalies using machine learning techniques. In addition, techniques to modify and adapt to user feedback are provided allowing the developed models to be tuned for specific use cases, virtual machine types, and users.


