Composite Metrics for Data Center Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network monitoring and management systems in data centers face challenges in accurately detecting anomalies and predicting failures due to noisy and non-uniform network traffic data, often resulting in false alarms and untimely service calls, and lack comprehensive solutions for cyberthreat intelligence.

Innovation Solution

The implementation of a data-center management system that uses machine learning algorithms to define composite metrics by combining and weighting performance measures, detecting anomalous deviations, and deriving potential anomaly patterns, while also mapping software applications to hardware components to identify anomalous events and predict future failures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network monitoring systems analyze network data to identify threats, then malicious network threats can be detected, but false alarms occur due to noisy and non-uniform network traffic data

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidanomaly detection precision
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent combines multiple performance measures (CPU utilization, memory utilization, network traffic, disk I/O) into composite metrics that represent overall system health. This merging approach allows the system to distinguish between normal fluctuations in individual metrics and genuine anomalies, reducing false alarms while maintaining reliable threat detection.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system transforms raw performance measures into composite metrics through mathematical transformations and normalization. By changing the parameters from individual metric values to composite health scores, the system achieves more precise anomaly detection and reduces false positives caused by noisy individual metrics.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If composite metrics are used to detect anomalies, then false alarms are reduced, but the system complexity increases due to multiple performance measures and machine learning algorithms

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The machine learning model automatically learns from historical performance data and self-adjusts the weighting and composition of composite metrics without requiring manual configuration. This self-service capability reduces the operational complexity of managing multiple performance measures while maintaining high detection precision.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary analysis by establishing baseline composite metrics from historical data before actual anomaly detection begins. This preliminary action pre-configures the system's understanding of normal behavior patterns, simplifying subsequent real-time monitoring while maintaining high precision.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If machine learning algorithms automatically define composite metrics, then anomaly detection reliability improves, but the loss of information increases due to data aggregation and weighting

Engineering Contradiction:
Improveanomaly detection reliabilityVSAvoidperformance data information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system maintains local quality by preserving individual performance measure data alongside composite metrics. When anomalies are detected, the system can drill down into specific contributing metrics, ensuring no information is lost while still benefiting from the reliability of aggregated composite analysis.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The machine learning model incorporates feedback loops that continuously refine composite metric definitions based on detected anomalies and false positives. This feedback mechanism ensures that information aggregation does not lose critical details, as the system learns to preserve and emphasize important information patterns.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11966319B2Identifying anomalies in a data center using composite metrics and/or machine learning
Publication Date: 2024.04.23 MELLANOX TECHNOLOGIES LTD(IL)
  • US11966319B2 patent drawing
  • US11966319B2 patent drawing
  • US11966319B2 patent drawing

AI summary

A method for data-center management includes, in a data center including multiple components, monitoring a plurality of performance measures of the components. A set of composite metrics is automatically defined, each composite metric including a respective weighted combination of two or more performance measures from among the performance measures. Baseline values are established for the composite metrics. An anomalous deviation is detected of one or more of the composite metrics from the respective baseline values.