Network Anomaly Detection via Automatic Metric Type Learning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network management systems require extensive manual configuration and tuning of key performance indicators (KPIs), which is time-consuming, prone to human error, and costly, and often necessitates vendor updates for changes in KPIs, leading to false and missed alerts.

Innovation Solution

A network management system comprising a collecting engine, evaluation engine, modeling engine, and listening engine that automatically determines metric types, applies properties, and monitors for anomalies, reducing the need for metadata packs and threshold definitions, and utilizing predictive analytics to learn metric features and reduce false alarms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual configuration and tuning of KPIs is performed, then detection precision is improved, but loss of time and operational expenses increase

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidconfiguration time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system automatically discovers metric types, learns baseline behaviors, and configures anomaly detection parameters without human intervention. The modeling engine autonomously analyzes collected metrics, determines their types, and establishes detection rules, eliminating the need for manual administrator configuration while maintaining high detection precision.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary metric collection and analysis during an onboarding period to automatically learn baseline behaviors and establish detection thresholds before production use. This preliminary learning phase enables the system to be pre-configured with accurate detection parameters, eliminating subsequent manual tuning requirements.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If manual configuration and tuning of KPIs is performed, then detection precision is improved, but operational expenses increase

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidoperational efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system autonomously performs metric type determination, baseline learning, and anomaly detection configuration without requiring skilled administrators. The modeling engine automatically analyzes metrics, learns normal behaviors, and configures detection rules, eliminating expensive manual configuration while maintaining high detection precision.

Inventive Principle:
Principle #25Self-service

3Reliability

If extensive configuration and tuning is performed, then false alerts are reduced, but device complexity increases

Engineering Contradiction:
Improvealert accuracyVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically determines metric types, learns baseline behaviors, and configures detection parameters without human intervention. The modeling engine autonomously analyzes collected metrics, identifies patterns, and establishes accurate detection rules, eliminating complex manual configuration while maintaining high alert accuracy through self-learning.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously learns from collected metrics and adjusts its detection models based on observed patterns and anomalies. This feedback mechanism enables the system to automatically refine its understanding of normal versus abnormal behavior, improving alert accuracy without requiring manual configuration adjustments.

Inventive Principle:
Principle #23Feedback

4Adaptability or versatility

If manual configuration is performed, then adaptability to specific needs is improved, but ease of operation worsens

Engineering Contradiction:
Improvecustomization capabilityVSAvoidconfiguration ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system automatically adapts to each customer's specific network environment by collecting metrics, determining metric types, and learning baseline behaviors unique to that environment. The modeling engine autonomously configures detection rules tailored to the specific infrastructure, eliminating the need for administrators to manually customize configurations while maintaining full adaptability to customer needs.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10225155B2Network anomaly detection
Publication Date: 2019.03.05 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10225155B2 patent drawing
  • US10225155B2 patent drawing
  • US10225155B2 patent drawing

AI summary

Mechanisms for anomaly detection in a network management system are provided. The mechanisms collect metric data from a plurality of network devices and determine metric types for the metric data using metric type reference data. The mechanisms determine and apply properties from the metric type reference data to metrics of the determined metric types. The mechanisms monitor subsequent metric data for anomalies that do not conform to the applied properties.