Dynamic Time Window Anomaly Detection for IT Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The vast amount of time-series data collected in IT networks makes it difficult to manage and synthesize, leading to challenges in identifying anomalies that could indicate issues with devices or components, and existing anomaly detection methods may result in false reporting due to changing data patterns.

Innovation Solution

A system that classifies time-series data using qualitative classifications, generates a statistical model based on historical data, and assigns an anomalous score to outliers, with a dynamically adjustable time window for increased accuracy in anomaly detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anomaly detection methods are used on vast time-series data, then anomaly detection capability is provided, but false reporting increases due to changing data patterns

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements a dynamic time window that automatically adjusts its size based on the characteristics of the time-series data being analyzed. When data patterns are stable, a smaller window is used for precise anomaly detection. When patterns change or seasonal variations occur, the window expands to capture more context, preventing false positives while maintaining detection sensitivity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of the time window size dynamically based on data characteristics. By adjusting this parameter in response to changing data patterns, the system adapts to different operational conditions, reducing false reporting while maintaining reliable anomaly detection across varying scenarios.

Inventive Principle:
Principle #35Parameter changes

2Ease of manufacture

If a fixed time window is used for anomaly scoring, then processing simplicity is maintained, but detection accuracy decreases when data patterns change

Engineering Contradiction:
Improveprocessing simplicityVSAvoidanomaly detection accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The system transitions from a static fixed time window to a dynamic time window that automatically adjusts its size. This dynamic adaptation allows the system to maintain processing simplicity through automated rules while significantly improving measurement precision when data patterns change, as the window size responds to actual data characteristics rather than remaining constant.

Inventive Principle:
Principle #15Dynamics

3Reliability

If more historical data is used for anomaly detection, then detection robustness improves, but data management and synthesis difficulty increases

Engineering Contradiction:
Improvedetection robustnessVSAvoiddata management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the historical time-series data into manageable portions using a time window of optimized size. Rather than attempting to analyze all historical data simultaneously, the system divides the data into relevant segments within the dynamic time window, making data management and synthesis tractable while retaining sufficient historical context for robust anomaly detection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses a partial view of historical data through the time window mechanism, selecting only the necessary portion of historical data required for reliable detection. This partial action approach avoids the complexity of managing entire historical datasets while capturing sufficient information for robust anomaly identification.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3467661B1Systems and methods for robust anomaly detection
Publication Date: 2024.04.24 SERVICENOW INC
  • EP3467661B1 patent drawingFigure 1
  • EP3467661B1 patent drawingFigure 2
  • EP3467661B1 patent drawingFigure 3

AI summary

A system, includes: a distributed cache that stores state information for a plurality of configuration items (CIs). Management, instrumentation, and discovery (MID) servers form a cluster, each of the MID servers including one or more processors that receive, from the distributed cache, a subset of the state information associated with assigned CIs and perform a statistical analysis on the subset of the state information.