Dynamic Anomaly Detection for IT Infrastructure Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anomaly detection tools in IT infrastructures often report false anomalies due to qualitatively deficient statistical models, diverting attention from critical issues and wasting resources on less important metrics.

Innovation Solution

Implement dynamically changeable anomaly detection actions, including 'metrics only,' 'bounds,' 'anomaly scores,' 'anomaly alerts,' and 'IT alerts' options, which can be automatically selected based on metric priority and statistical model quality, utilizing machine learning to identify patterns and reduce unnecessary reporting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If anomaly detection tools report all statistical outliers, then comprehensive monitoring coverage is achieved, but false anomalies increase and resources are wasted on less important metrics

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidfalse alerts
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent applies local quality by assigning different anomaly detection actions to different metrics based on their priority levels. High-priority metrics receive comprehensive monitoring with anomaly scoring and alerting, while low-priority metrics receive simplified monitoring with fewer false alerts. This differentiated approach improves overall reliability by focusing resources on critical metrics while reducing false alarms on less important ones.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically changes the anomaly detection parameters (such as threshold values, scoring weights, and alerting sensitivity) based on metric priority and statistical model quality. When model quality is low or metric priority is low, the system adjusts parameters to reduce false positive rates, thereby improving detection accuracy while minimizing false alerts.

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If comprehensive anomaly monitoring is implemented across all metrics, then complete visibility is achieved, but resource consumption increases

Engineering Contradiction:
Improvemonitoring coverageVSAvoidcomputational resources
Core Design Contradiction:
Loss of informationVSLoss of energy

Solution Approach 1:

The patent segments the monitoring system into different tiers based on metric priority. High-priority metrics receive full anomaly detection processing including statistical modeling, outlier detection, and alerting. Low-priority metrics receive simplified monitoring with reduced processing. This segmentation maintains complete visibility across all metrics while optimizing resource allocation to focus computational power on critical infrastructure components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies partial action by implementing full anomaly detection capabilities only where necessary (high-priority metrics) rather than uniformly across all metrics. For low-priority metrics, the system applies minimal viable monitoring to maintain visibility while conserving computational resources. This approach ensures adequate coverage without excessive resource consumption on non-critical infrastructure elements.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If statistical models are continuously improved for better accuracy, then detection precision increases, but system complexity increases

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system dynamically adjusts the complexity of statistical models based on metric priority and available data quality. For high-priority metrics with sufficient historical data, the system employs sophisticated statistical models to achieve high detection precision. For low-priority metrics or cases with limited data, the system uses simpler models that are easier to maintain and less complex, thereby balancing precision requirements with system complexity constraints.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12254423B2Dynamic anomaly reporting
Publication Date: 2025.03.18 SERVICENOW INC
  • US12254423B2 patent drawing
  • US12254423B2 patent drawing
  • US12254423B2 patent drawing

AI summary

Systems and methods are provided for dynamic selection of anomaly detection options for particular metric data. Metric data corresponding to one or more configuration items of an information technology (IT) infrastructure is collected. A selected anomaly detection action option that applies to the metric data is identified. An action is performed using the metric data, based upon the selected anomaly detection action option. A dashboard graphical user interface (GUI) display results of the action.