Multidimensional Time Series Anomaly Detection via Normalization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anomaly detection methods in server resource performance monitoring rely on static thresholds and isolated metric analysis, which fail to account for changes over time and contextual variations, leading to inaccurate and inefficient identification of operational anomalies.

Innovation Solution

A performance analysis platform that normalizes multidimensional time series data using techniques like Box-Cox normalization to identify normal distributions, calculates scores based on probability density functions, and takes actions when anomalies are detected, facilitating more accurate and contextual anomaly identification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If static thresholds and isolated metric analysis are used for anomaly detection, then the detection method is simple and fast, but the accuracy of anomaly identification deteriorates due to failure to account for changes over time and contextual variations

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoiddetection method complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies dynamics by transitioning from static anomaly detection thresholds to dynamic, adaptive thresholds that evolve over time. The system continuously learns from historical data and adjusts detection parameters based on changing patterns in server resource metrics, enabling accurate detection while adapting to temporal variations and contextual changes in the monitored environment.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements dimensionality change by moving from isolated metric analysis to multidimensional analysis that incorporates multiple metrics simultaneously across multiple dimensions (time, context, relationships). This holistic approach considers interdependencies between different server resource metrics and contextual factors, significantly improving anomaly detection accuracy through comprehensive pattern recognition.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If traditional anomaly detection methods are used, then processing resources are consumed continuously, but false positives increase reducing the effectiveness of anomaly identification

Engineering Contradiction:
Improveanomaly identification effectivenessVSAvoidprocessing resource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies preliminary action by performing data normalization and establishing baseline patterns before actual anomaly detection occurs. The system pre-processes historical data to create reference models and normalization parameters, so that during operational monitoring, anomaly detection can be performed more efficiently with reduced computational overhead and lower false positive rates.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If static threshold-based anomaly detection is used, then the system is simple to implement, but it cannot identify anomalies that deviate from normal patterns over time

Engineering Contradiction:
Improveanomaly detection adaptabilityVSAvoiddetection system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies dynamics by implementing adaptive thresholding mechanisms that automatically adjust detection criteria based on observed patterns in the data. The system dynamically modifies detection parameters in response to changing conditions, enabling it to identify anomalies that deviate from evolving normal patterns rather than relying on fixed thresholds.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements self-service through automated normalization and adaptive learning mechanisms that enable the system to improve its own performance over time. The detection system automatically adjusts to new patterns and contexts without requiring manual reconfiguration, continuously refining its anomaly detection capabilities based on accumulated operational data.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10944692B2Real-time analysis of multidimensional time series data to identify an operational anomaly
Publication Date: 2021.03.09 CAPITAL ONE SERVICES LLC
  • US10944692B2 patent drawing
  • US10944692B2 patent drawing
  • US10944692B2 patent drawing

AI summary

A device may receive data for a plurality of metrics from a set of server resources associated with hosting an application. The plurality of metrics may be related to a performance of the set of server resources. The data may be time series data. The device may normalize the data for the plurality of metrics across a set of points in time to form normalized data. The device may determine a score for the performance of the set of server resources associated with hosting the application at a particular point in time based on the normalized data. The score may be used to determine whether an anomaly is present in the performance of the set of server resources at the particular point in time. The device may perform an action to facilitate improvement of the performance of the set of server resources based on the score satisfying a threshold.