Dynamic Anomaly Detection for IT Infrastructure Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current anomaly detection tools in IT infrastructures often report false anomalies due to qualitatively deficient statistical models, diverting attention from critical issues and wasting resources on less important metrics.
Innovation Solution
Implement dynamically changeable anomaly detection actions, including 'metrics only,' 'bounds,' 'anomaly scores,' 'anomaly alerts,' and 'IT alerts' options, which can be automatically selected based on metric priority and statistical model quality, utilizing machine learning to identify patterns and reduce unnecessary reporting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If anomaly detection tools report all statistical outliers, then comprehensive monitoring coverage is achieved, but false anomalies increase and resources are wasted on less important metrics
Solution Approach 1:
The patent applies local quality by assigning different anomaly detection actions to different metrics based on their priority levels. High-priority metrics receive comprehensive monitoring with anomaly scoring and alerting, while low-priority metrics receive simplified monitoring with fewer false alerts. This differentiated approach improves overall reliability by focusing resources on critical metrics while reducing false alarms on less important ones.
Solution Approach 2:
The system dynamically changes the anomaly detection parameters (such as threshold values, scoring weights, and alerting sensitivity) based on metric priority and statistical model quality. When model quality is low or metric priority is low, the system adjusts parameters to reduce false positive rates, thereby improving detection accuracy while minimizing false alerts.
2Loss of information
If comprehensive anomaly monitoring is implemented across all metrics, then complete visibility is achieved, but resource consumption increases
Solution Approach 1:
The patent segments the monitoring system into different tiers based on metric priority. High-priority metrics receive full anomaly detection processing including statistical modeling, outlier detection, and alerting. Low-priority metrics receive simplified monitoring with reduced processing. This segmentation maintains complete visibility across all metrics while optimizing resource allocation to focus computational power on critical infrastructure components.
Solution Approach 2:
The system applies partial action by implementing full anomaly detection capabilities only where necessary (high-priority metrics) rather than uniformly across all metrics. For low-priority metrics, the system applies minimal viable monitoring to maintain visibility while conserving computational resources. This approach ensures adequate coverage without excessive resource consumption on non-critical infrastructure elements.
3Measurement precision
If statistical models are continuously improved for better accuracy, then detection precision increases, but system complexity increases
Solution Approach 1:
The system dynamically adjusts the complexity of statistical models based on metric priority and available data quality. For high-priority metrics with sufficient historical data, the system employs sophisticated statistical models to achieve high detection precision. For low-priority metrics or cases with limited data, the system uses simpler models that are easier to maintain and less complex, thereby balancing precision requirements with system complexity constraints.
Data Source
AI summary
Systems and methods are provided for dynamic selection of anomaly detection options for particular metric data. Metric data corresponding to one or more configuration items of an information technology (IT) infrastructure is collected. A selected anomaly detection action option that applies to the metric data is identified. An action is performed using the metric data, based upon the selected anomaly detection action option. A dashboard graphical user interface (GUI) display results of the action.


