Metric Anomaly Detection Service for IoT Fleets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Monitoring for metric anomalies across high-scale data from numerous IoT edge devices is challenging due to the large number of devices, making it difficult to quickly identify and mitigate potential security risks, such as unauthorized communication.

Innovation Solution

Implementing a system that uses mandatory and optional values for anomaly detection, allowing clients to configure and monitor metric values efficiently, with the anomaly detection service determining anomalies based on predefined criteria, thereby enabling faster identification and notification of anomalies while consuming fewer computing resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anomaly detection methods are used across high-scale IoT device data, then comprehensive security monitoring is achieved, but the time required to identify anomalies and the computational resources consumed increase significantly

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoidanomaly identification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the anomaly detection process into two distinct phases: an offline learning phase where the system learns normal behavior patterns from historical data, and an online detection phase where anomalies are detected by comparing current metrics against learned patterns. This segmentation allows comprehensive monitoring while enabling fast real-time detection without reprocessing all historical data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary action by pre-processing historical metric data to establish baseline normal behavior patterns before actual anomaly detection is needed. The offline learning phase pre-computes expected metric ranges and relationships, so that during online operation, anomaly detection requires only simple comparisons rather than complex real-time analysis.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional anomaly detection methods are used across high-scale IoT device data, then comprehensive security monitoring is achieved, but the computational resources required increase significantly

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the anomaly detection process into an offline learning phase that consumes computational resources for pattern establishment, and an online detection phase that requires minimal resources for comparison operations. This segmentation shifts the heavy computational burden to an offline period, enabling resource-constrained IoT devices to perform comprehensive anomaly detection with minimal ongoing energy consumption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates a simplified representation or model of normal behavior patterns during the offline learning phase. Instead of storing and reprocessing all raw historical data, the system copies essential patterns into a compact format that enables fast comparison during online detection, significantly reducing computational resource requirements while maintaining detection accuracy.

Inventive Principle:
Principle #26Copying

3Reliability

If comprehensive monitoring of all edge devices is implemented, then security coverage is improved, but the complexity of the monitoring system increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the monitoring system into centralized components that handle heavy lifting (offline learning, pattern storage) and distributed edge components that perform simple comparisons. This segmentation allows comprehensive coverage across many devices while keeping individual device complexity low, as each edge device only needs to collect metrics and compare against pre-established patterns.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system enables edge devices to self-monitor by comparing their own metrics against learned normal patterns without requiring constant centralized analysis. Each device can independently detect anomalies in its own behavior, reducing the complexity of centralized monitoring infrastructure while maintaining comprehensive security coverage across all devices.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11777823B1Metric anomaly detection across high-scale data
Publication Date: 2023.10.03 AMAZON TECH INC
  • US11777823B1 patent drawing
  • US11777823B1 patent drawing
  • US11777823B1 patent drawing

AI summary

An anomaly detection service of a provider network may be used to efficiently monitor for metric anomalies across a large number of IoT devices using mandatory and optional values for metrics. A client may configure any number of mandatory and optional values for a metric to be collected from IoT devices of a fleet. The client may also configure one or more criteria to by used for evaluating the mandatory values (e.g., a threshold percentage such as 99%). When the service receives metric values for the metric, the service determines whether the values satisfy the criteria for the mandatory value. If not, then the service indicates an anomaly. The service may also determine if any values other than the mandatory and optional values are present. If not, then the service indicates an anomaly.