Prescriptive Analytics for Network Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing anomaly detection techniques in network environments are inefficient and do not scale well, especially in dynamic multi-tenant settings, making it difficult to identify and report significant information effectively.

Innovation Solution

The implementation of prescriptive analytics for network services, which involves collecting and analyzing data from various sources, including performance metrics and context data, using both offline and online analysis methods to detect anomalies and generate notifications with associated context, employing machine learning techniques to establish baseline metrics and anomaly detection rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If existing anomaly detection techniques are used in network environments, then anomaly detection can be performed, but the techniques are inefficient and do not scale well in dynamic multi-tenant settings

Engineering Contradiction:
Improveanomaly detection efficiencyVSAvoidscalability in dynamic multi-tenant environments
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent segments the anomaly detection system into multiple independent anomaly detection models, each trained on data from specific tenants or service types. This allows the system to scale by adding or removing individual models without affecting the entire system, directly addressing the scalability issue in dynamic multi-tenant environments while maintaining detection efficiency through specialized models.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically creates, updates, and removes anomaly detection models based on tenant onboarding, offboarding, and changing requirements. Models are retrained periodically or triggered by significant data changes, allowing the system to adapt to dynamic environments while maintaining high detection efficiency through up-to-date baseline metrics for each tenant.

Inventive Principle:
Principle #15Dynamics

2Quantity of substance

If large volumes of network data are collected for analysis, then comprehensive monitoring is achieved, but it becomes difficult to identify significant and relevant information

Engineering Contradiction:
Improvevolume of network data collectedVSAvoiddifficulty in identifying significant information
Core Design Contradiction:
Quantity of substanceVSLoss of information

Solution Approach 1:

The system extracts only the most relevant features and metrics from large volumes of network data during the model training phase. By identifying and extracting key performance indicators and anomaly patterns specific to each tenant, the system reduces the complexity of data analysis while maintaining comprehensive monitoring capabilities, making it easier to identify significant information without being overwhelmed by data volume.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces manual data analysis with automated machine learning models that continuously learn and adapt to normal behavior patterns. These models automatically identify significant deviations from baselines, substituting human analytical effort with automated algorithms that can process large data volumes efficiently and consistently, thereby preventing information loss in the identification of significant anomalies.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If anomaly detection models are trained on tenant data, then accurate detection for each tenant is achieved, but the process is computationally intensive and time-consuming

Engineering Contradiction:
Improveanomaly detection accuracy per tenantVSAvoidmodel training time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary model training during off-hours or when computational resources are available, creating baseline anomaly detection models before they are needed for production monitoring. This preliminary action allows the system to have pre-trained models ready for immediate use, reducing the time loss during critical monitoring periods while maintaining high detection accuracy through tenant-specific training data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements incremental or online learning approaches where models are periodically retrained with new data rather than complete retraining from scratch. By changing the training parameter strategy from full retraining to incremental updates, the system maintains high detection accuracy through continuous learning while significantly reducing the computational time and resources required compared to complete retraining cycles.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11757736B2Prescriptive analytics for network services
Publication Date: 2023.09.12 VMWARE INC
  • US11757736B2 patent drawing
  • US11757736B2 patent drawing
  • US11757736B2 patent drawing

AI summary

The disclosure provides an approach for prescriptive analytics for network services. Embodiments include receiving one or more rules for anomaly detection. Embodiments include receiving metric data of one or more services and collecting context data related to the metric data. Embodiments include determining a baseline for the metric data. Embodiments include detecting an anomaly based on analysis of the metric data in view of the baseline for the metric data and the one or more rules for anomaly detection. Embodiments include associating the anomaly with a subset of the context data that is related to the anomaly. Embodiments include determining a score for the anomaly based on the analysis and determining that a notification should be generated based on the score. Embodiments include providing the notification to a user interface for display. The notification comprises includes an indication of the anomaly and the subset of the context data.