Dynamic Anomaly Detection Using Telemetry-Independent Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional anomaly detection algorithms in information handling systems lack flexibility to recognize trends that may not be apparent over a fixed and limited interval of time, leading to false positive alerts and cognitive overload.
Innovation Solution
The use of machine learning to develop dynamic anomaly detection algorithms trained with telemetry-independent-data (TID), which includes user-provided enterprise profile data and external factor data, to improve anomaly detection accuracy and reduce false positives.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional anomaly detection algorithms use fixed and limited historical data intervals, then the detection process is simple and fast, but the algorithms lack flexibility to recognize trends that may not be apparent over fixed intervals
Solution Approach 1:
The patent transforms the static, fixed time-window approach into a dynamic system that adapts to different anomaly types and data characteristics. The system dynamically selects between coincidence-based detection (for sudden anomalies) and sequence-based detection (for gradual trends), allowing the detection algorithm to flexibly adjust its behavior based on the specific anomaly pattern being detected.
Solution Approach 2:
The system changes the fundamental parameters of anomaly detection by introducing multiple detection dimensions: time coincidence parameters (for sudden anomalies), sequence coincidence parameters (for gradual anomalies), and user-defined parameters. This allows the system to detect anomalies across different time scales and patterns, from immediate spikes to long-term trends.
2Reliability
If conventional algorithms rely heavily on historical data within fixed intervals, then the detection process is computationally efficient, but false positive alerts increase due to inability to recognize broader trends
Solution Approach 1:
The patent segments the anomaly detection process into distinct modules: a coincidence detection module for sudden anomalies, a sequence detection module for gradual anomalies, and a user-defined parameter module. Each module handles specific types of anomalies independently, allowing the system to maintain computational efficiency while improving detection accuracy through specialized processing for different anomaly patterns.
Solution Approach 2:
The system introduces an intermediary layer that bridges simple historical data comparison and complex trend analysis. By using coincidence-based detection as an intermediary step, the system can quickly filter obvious anomalies while more sophisticated sequence-based detection handles subtle trends, reducing false positives without requiring the entire system to be highly complex.
3Loss of information
If conventional anomaly detection generates frequent alerts to ensure comprehensive monitoring, then detection coverage is high, but cognitive overload occurs due to false positive alerts
Solution Approach 1:
The system incorporates feedback mechanisms where user interactions with detected anomalies (confirming or rejecting alerts) are used to refine and retrain the detection models. This feedback loop allows the system to learn from false positives and improve over time, reducing unnecessary alerts while maintaining comprehensive monitoring coverage.
Solution Approach 2:
The system dynamically adjusts alert generation based on the confidence level and pattern recognition results. By using both coincidence-based and sequence-based detection, the system can differentiate between high-confidence sudden anomalies (worthy of immediate alerts) and lower-confidence gradual changes (that may require monitoring but not immediate alerting), thereby reducing cognitive load while maintaining detection coverage.
Data Source
AI summary
Disclosed information handling systems and methods employ machine learning to provide and support dynamic anomaly detection algorithms trained in accordance with telemetry independent data (TID) to improve anomaly detection accuracy and reduce alert fatigue associated with false-positive anomaly determinations. In at least some embodiments, TID may encompass user-provided data, including enterprise profile data indicative of attributes of the enterprise's business, and external factor data, indicating external events or conditions with the potential to impact many or all enterprises located in proximity to the event or condition.


