Dynamic KPI Threshold Selection for Network Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network assurance systems face challenges in setting optimal thresholds for key performance indicators (KPIs) to effectively raise anomaly detection alarms without overwhelming administrators with false positives or missing important issues, especially in complex and dynamic network environments.

Innovation Solution

A network assurance service that maps time series of KPI values to unique values, sets a target alarm rate, and uses an optimization function to identify thresholds based on the comparison between the target alarm rate and the fraction of issues flagged as outliers, ensuring that only relevant anomalies are reported.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional fixed thresholds are used for KPI anomaly detection, then the system is simple to operate, but it produces many false positives or misses important issues in dynamic network environments

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidthreshold selection complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic threshold adjustment by continuously monitoring network conditions and automatically adapting KPI thresholds based on observed patterns and anomalies. This allows the system to respond to changing network environments without manual intervention, improving detection reliability while maintaining operational simplicity through automation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system dynamically changes threshold parameters based on network conditions, traffic patterns, and historical data. By adjusting threshold values adaptively rather than using fixed values, the system achieves better anomaly detection accuracy across varying network states without requiring complex manual configuration.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If manual threshold adjustment is implemented to improve detection accuracy, then anomaly detection precision improves, but the ease of operation decreases due to complex configuration requirements

Engineering Contradiction:
ImproveKPI threshold precisionVSAvoidthreshold configuration ease
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system performs self-service by automatically selecting and adjusting KPI thresholds based on network data and performance metrics. This eliminates the need for manual threshold configuration while maintaining high detection precision, as the system autonomously optimizes thresholds based on observed network behavior and anomaly patterns.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms where anomaly detection results and network performance data are continuously fed back to automatically adjust thresholds. This closed-loop approach enables the system to self-optimize threshold precision without manual intervention, maintaining high measurement precision while preserving ease of operation.

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple KPIs are monitored with individual thresholds, then detection coverage improves, but the number of false alarms increases

Engineering Contradiction:
Improveanomaly detection coverageVSAvoidfalse alarm rate
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent merges multiple KPI evaluations into a unified anomaly detection framework that considers correlations between different KPIs. By combining threshold evaluations and using aggregate scoring mechanisms, the system maintains comprehensive detection coverage across multiple KPIs while reducing false alarms through cross-KPI validation and pattern recognition.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11616682B2Threshold selection for KPI candidacy in root cause analysis of network issues
Publication Date: 2023.03.28 CISCO TECHNOLOGY INC
  • US11616682B2 patent drawing
  • US11616682B2 patent drawing
  • US11616682B2 patent drawing

AI summary

In one embodiment, a network assurance service that monitors a network maps time series of values of key performance indicator (KPIs) measured from the network to lists of unique values from the time series. The service sets a target alarm rate for anomaly detection alarms raised by the network assurance service. The service uses an optimization function to identify a set of thresholds for the KPIs. The optimization function is based on: a comparison between the target alarm rate and a fraction of network issues flagged by the service as outliers, KPI thresholds selected based on the lists of unique values from the time series, and a number of thresholds that the KPIs must cross for the service to raise an alarm. The service raises an anomaly detection alarm for the monitored network based on the identified set of thresholds for the KPIs.