Data-Agnostic Anomaly Detection via Normalcy Bounds

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anomaly detection techniques in complex systems are limited by their reliance on parametric methods, which assume known data distributions, and non-parametric methods are resource-intensive and complex, making them unsuitable for diverse data types and leading to false positives.

Innovation Solution

A data-agnostic computational system that aggregates data, performs quality assurance, and categorizes it using routines like parametric category detection, data density detection, and variability detection to establish normalcy bounds, enabling accurate anomaly detection in various complex systems without assuming data distributions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If parametric anomaly detection techniques are used, then detection accuracy is improved for specific data types, but applicability to diverse data types deteriorates

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidapplicability to diverse data types
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal anomaly detection system that automatically adapts to different data types through data-agnostic procedures. The system categorizes data into four types (periodic, non-periodic, high-variability, low-variability) and applies appropriate detection methods for each, enabling a single system to handle diverse data types effectively without requiring manual configuration or assumption of data distributions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If non-parametric anomaly detection techniques are used, then applicability to diverse data types is improved, but computational complexity and resource consumption increase

Engineering Contradiction:
Improveapplicability to diverse data typesVSAvoidalgorithm complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the anomaly detection process into distinct procedural branches based on data categorization. By dividing data into four categories and applying specialized detection procedures to each segment, the system achieves comprehensive coverage of diverse data types while maintaining computational efficiency through targeted rather than universal complex algorithms.

Inventive Principle:
Principle #1Segmentation

3Reliability

If traditional anomaly detection methods are used, then detection capability is improved, but false positive rate increases

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent dynamically adjusts detection parameters and procedures based on the categorized characteristics of the input data. By changing the detection approach according to data type (periodic, non-periodic, high-variability, low-variability), the system optimizes detection sensitivity for each data type, thereby reducing false positives while maintaining high anomaly detection capability.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10241887B2Data-agnostic anomaly detection
Publication Date: 2019.03.26 VMWARE INC
  • US10241887B2 patent drawing
  • US10241887B2 patent drawing
  • US10241887B2 patent drawing

AI summary

This disclosure presents computational systems and methods for detecting anomalies in data output from any type of monitoring tool. The data is aggregated and sent to an alerting system for abnormality detection via comparison with normalcy bounds. The anomaly detection methods are performed by construction of normalcy bounds of the data based on the past behavior of the data output from the monitoring tool. The methods use data quality assurance and data categorization processes that allow choosing a correct procedure for determination of the normalcy bounds. The methods are completely data agnostic, and as a result, can also be used to detect abnormalities in time series data associated with any complex system.