Multivariate Path-Based Anomaly Prediction for Distributed Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large-scale distributed applications generate vast amounts of metrics data, making it computationally challenging to detect anomalies and predict future patterns, as monitoring agents collect thousands of measurements per hour, leading to noise and ineffective results due to the volume of patterns detected.

Innovation Solution

A multivariate path-based anomaly detection service that performs topology-based feature selection, multivariate clustering analysis, and path analysis to identify known and unknown anomalies, generating prediction events for proactive measures and root cause analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If monitoring agents collect thousands of measurements per hour from distributed application components, then the volume of detected patterns increases, but the results become ineffective due to noise and computational challenges

Engineering Contradiction:
Improvevolume of metrics dataVSAvoideffectiveness of anomaly detection
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent segments the execution path into distinct components and identifies specific metrics for each component. Instead of analyzing all metrics from all components uniformly, the system divides the monitoring task by transaction type and execution path segment, focusing analysis on relevant portions of the system. This segmentation reduces noise by excluding irrelevant metrics while maintaining comprehensive coverage of critical areas.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts and selects only the most relevant metrics from the vast available data based on execution path topology. The system identifies and extracts specific blame metrics associated with particular execution path segments, removing unnecessary data from the analysis. This extraction process converts the raw large-volume data into a focused set of meaningful indicators for anomaly detection.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If all metrics from all components are monitored, then comprehensive coverage is achieved, but computational complexity increases making anomaly detection challenging

Engineering Contradiction:
Improvecomprehensive metric coverageVSAvoidcomputational complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by tailoring the set of monitored metrics to each specific execution path segment and transaction type. Different components and path segments have different relevant metrics identified and monitored. This approach maintains comprehensive coverage of all critical areas while reducing overall computational complexity by not uniformly monitoring all possible metrics across all components.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent performs preliminary analysis to establish execution paths and identify relevant metrics before actual anomaly detection occurs. The system pre-processes the data by mapping metrics to execution path segments and transaction types in advance, creating a structured framework that simplifies subsequent real-time anomaly detection. This preliminary action reduces computational burden during active monitoring.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If traditional anomaly detection methods are used on large volumes of metrics data, then all patterns are detected, but noise increases leading to ineffective results

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidnoise in detected patterns
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The patent introduces execution path topology as an intermediary framework that mediates between raw metrics data and anomaly detection analysis. This intermediary structure organizes metrics according to their relationship with specific execution paths and transaction types, filtering out noise before analysis. The topology-based approach acts as a mediator that preserves meaningful patterns while eliminating spurious correlations from the vast available data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10628289B2Multivariate path-based anomaly prediction
Publication Date: 2020.04.21 CA TECH INC
  • US10628289B2 patent drawing
  • US10628289B2 patent drawing
  • US10628289B2 patent drawing

AI summary

A multivariate path-based anomaly detection and prediction service (“anomaly detector”) can generate a prediction event for consumption by the APM manager that indicates a likelihood of an anomaly occurring based on path analysis of multivariate values after topology-based feature selection. To predict that a set of metrics will travel to a cluster that represents anomalous application behavior, the anomaly detector analyzes a set of multivariate date slices that are not within a cluster to determine whether dimensionally reduced representations of the set of multivariate data slices fit a path as described by a function.