Network Anomaly Detection via Motif Clustering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network performance anomaly detection is manual and unable to react in real-time, requiring ultra-granular and accurate performance measurements to address rapid performance issues in high-speed networks effectively.
Innovation Solution
An automated anomaly detection system that uses a discrete window to extract motifs from network performance metrics, maintains abnormal and normal cluster centers, and classifies anomalies based on distance from these centers using a predetermined decision boundary.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If manual anomaly detection process is used, then system complexity is reduced, but detection speed and real-time response capability deteriorate
Solution Approach 1:
The patent replaces manual anomaly detection (mechanical human operation) with an automated system using machine learning models and algorithms. The system automatically collects performance data, processes it through trained models, and generates anomaly detections without human intervention, thereby dramatically increasing detection speed while accepting the trade-off of increased system complexity through automated infrastructure.
Solution Approach 2:
The system implements self-service anomaly detection by automatically monitoring its own network performance metrics, collecting data, processing it through embedded machine learning models, and generating anomaly alerts without requiring external manual analysis. This self-monitoring capability enables real-time detection while maintaining operational autonomy.
2Measurement precision
If automated anomaly detection system is implemented, then detection accuracy and real-time response improve, but system complexity increases
Solution Approach 1:
The system performs preliminary actions by pre-training machine learning models offline using historical network performance data before deployment. These pre-trained models capture normal and anomalous patterns in advance, enabling the system to quickly and accurately detect anomalies in real-time without requiring complex real-time training computations, thus improving measurement precision while managing system complexity.
Solution Approach 2:
The patent segments the anomaly detection task into distinct components: data collection module, model training module (using synthetic and real data), inference module, and alert generation module. This segmentation allows each component to be optimized independently, improving overall measurement accuracy while making the complex system more manageable and maintainable through modular architecture.
3Measurement precision
If ultra-granular performance measurements are collected, then anomaly detection accuracy improves, but data processing complexity and computational requirements increase
Solution Approach 1:
The system extracts only the most relevant features and metrics from ultra-granular performance measurements for anomaly detection. Instead of processing all raw data points, the machine learning models identify and extract key discriminative features that are most indicative of anomalies, thereby maintaining high detection accuracy while reducing computational processing requirements and power consumption.
Data Source
AI summary
A method for detecting anomalies in one or more network performance metrics stream for one or more monitored object comprising using a discrete window on the stream to extract a motif from said stream for a first of said network performance metric for a first of said monitored object. Maintaining an abnormal and a normal cluster center of historical time series for said first network performance metric for said first monitored object. Classifying said motif based on a distance between said new time series and said abnormal and said normal cluster center. Determining whether an anomaly for said motif occurred based on said distance and a predetermined decision boundary.


