Metric Anomaly Detection Service for IoT Fleets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Monitoring for metric anomalies across high-scale data from numerous IoT edge devices is challenging due to the large number of devices, making it difficult to quickly identify and mitigate potential security risks, such as unauthorized communication.
Innovation Solution
Implementing a system that uses mandatory and optional values for anomaly detection, allowing clients to configure and monitor metric values efficiently, with the anomaly detection service determining anomalies based on predefined criteria, thereby enabling faster identification and notification of anomalies while consuming fewer computing resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional anomaly detection methods are used across high-scale IoT device data, then comprehensive security monitoring is achieved, but the time required to identify anomalies and the computational resources consumed increase significantly
Solution Approach 1:
The patent segments the anomaly detection process into two distinct phases: an offline learning phase where the system learns normal behavior patterns from historical data, and an online detection phase where anomalies are detected by comparing current metrics against learned patterns. This segmentation allows comprehensive monitoring while enabling fast real-time detection without reprocessing all historical data.
Solution Approach 2:
The system performs preliminary action by pre-processing historical metric data to establish baseline normal behavior patterns before actual anomaly detection is needed. The offline learning phase pre-computes expected metric ranges and relationships, so that during online operation, anomaly detection requires only simple comparisons rather than complex real-time analysis.
2Reliability
If traditional anomaly detection methods are used across high-scale IoT device data, then comprehensive security monitoring is achieved, but the computational resources required increase significantly
Solution Approach 1:
The patent segments the anomaly detection process into an offline learning phase that consumes computational resources for pattern establishment, and an online detection phase that requires minimal resources for comparison operations. This segmentation shifts the heavy computational burden to an offline period, enabling resource-constrained IoT devices to perform comprehensive anomaly detection with minimal ongoing energy consumption.
Solution Approach 2:
The system creates a simplified representation or model of normal behavior patterns during the offline learning phase. Instead of storing and reprocessing all raw historical data, the system copies essential patterns into a compact format that enables fast comparison during online detection, significantly reducing computational resource requirements while maintaining detection accuracy.
3Reliability
If comprehensive monitoring of all edge devices is implemented, then security coverage is improved, but the complexity of the monitoring system increases
Solution Approach 1:
The patent divides the monitoring system into centralized components that handle heavy lifting (offline learning, pattern storage) and distributed edge components that perform simple comparisons. This segmentation allows comprehensive coverage across many devices while keeping individual device complexity low, as each edge device only needs to collect metrics and compare against pre-established patterns.
Solution Approach 2:
The system enables edge devices to self-monitor by comparing their own metrics against learned normal patterns without requiring constant centralized analysis. Each device can independently detect anomalies in its own behavior, reducing the complexity of centralized monitoring infrastructure while maintaining comprehensive security coverage across all devices.
Data Source
AI summary
An anomaly detection service of a provider network may be used to efficiently monitor for metric anomalies across a large number of IoT devices using mandatory and optional values for metrics. A client may configure any number of mandatory and optional values for a metric to be collected from IoT devices of a fleet. The client may also configure one or more criteria to by used for evaluating the mandatory values (e.g., a threshold percentage such as 99%). When the service receives metric values for the metric, the service determines whether the values satisfy the criteria for the mandatory value. If not, then the service indicates an anomaly. The service may also determine if any values other than the mandatory and optional values are present. If not, then the service indicates an anomaly.


