Network Anomaly Detection via Automatic Metric Type Learning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network management systems require extensive manual configuration and tuning of key performance indicators (KPIs), which is time-consuming, prone to human error, and costly, and often necessitates vendor updates for changes in KPIs, leading to false and missed alerts.
Innovation Solution
A network management system comprising a collecting engine, evaluation engine, modeling engine, and listening engine that automatically determines metric types, applies properties, and monitors for anomalies, reducing the need for metadata packs and threshold definitions, and utilizing predictive analytics to learn metric features and reduce false alarms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual configuration and tuning of KPIs is performed, then detection precision is improved, but loss of time and operational expenses increase
Solution Approach 1:
The system automatically discovers metric types, learns baseline behaviors, and configures anomaly detection parameters without human intervention. The modeling engine autonomously analyzes collected metrics, determines their types, and establishes detection rules, eliminating the need for manual administrator configuration while maintaining high detection precision.
Solution Approach 2:
The system performs preliminary metric collection and analysis during an onboarding period to automatically learn baseline behaviors and establish detection thresholds before production use. This preliminary learning phase enables the system to be pre-configured with accurate detection parameters, eliminating subsequent manual tuning requirements.
2Measurement precision
If manual configuration and tuning of KPIs is performed, then detection precision is improved, but operational expenses increase
Solution Approach 1:
The system autonomously performs metric type determination, baseline learning, and anomaly detection configuration without requiring skilled administrators. The modeling engine automatically analyzes metrics, learns normal behaviors, and configures detection rules, eliminating expensive manual configuration while maintaining high detection precision.
3Reliability
If extensive configuration and tuning is performed, then false alerts are reduced, but device complexity increases
Solution Approach 1:
The system automatically determines metric types, learns baseline behaviors, and configures detection parameters without human intervention. The modeling engine autonomously analyzes collected metrics, identifies patterns, and establishes accurate detection rules, eliminating complex manual configuration while maintaining high alert accuracy through self-learning.
Solution Approach 2:
The system continuously learns from collected metrics and adjusts its detection models based on observed patterns and anomalies. This feedback mechanism enables the system to automatically refine its understanding of normal versus abnormal behavior, improving alert accuracy without requiring manual configuration adjustments.
4Adaptability or versatility
If manual configuration is performed, then adaptability to specific needs is improved, but ease of operation worsens
Solution Approach 1:
The system automatically adapts to each customer's specific network environment by collecting metrics, determining metric types, and learning baseline behaviors unique to that environment. The modeling engine autonomously configures detection rules tailored to the specific infrastructure, eliminating the need for administrators to manually customize configurations while maintaining full adaptability to customer needs.
Data Source
AI summary
Mechanisms for anomaly detection in a network management system are provided. The mechanisms collect metric data from a plurality of network devices and determine metric types for the metric data using metric type reference data. The mechanisms determine and apply properties from the metric type reference data to metrics of the determined metric types. The mechanisms monitor subsequent metric data for anomalies that do not conform to the applied properties.


