Multidimensional Time Series Anomaly Detection via Normalization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current anomaly detection methods in server resource performance monitoring rely on static thresholds and isolated metric analysis, which fail to account for changes over time and contextual variations, leading to inaccurate and inefficient identification of operational anomalies.
Innovation Solution
A performance analysis platform that normalizes multidimensional time series data using techniques like Box-Cox normalization to identify normal distributions, calculates scores based on probability density functions, and takes actions when anomalies are detected, facilitating more accurate and contextual anomaly identification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If static thresholds and isolated metric analysis are used for anomaly detection, then the detection method is simple and fast, but the accuracy of anomaly identification deteriorates due to failure to account for changes over time and contextual variations
Solution Approach 1:
The patent applies dynamics by transitioning from static anomaly detection thresholds to dynamic, adaptive thresholds that evolve over time. The system continuously learns from historical data and adjusts detection parameters based on changing patterns in server resource metrics, enabling accurate detection while adapting to temporal variations and contextual changes in the monitored environment.
Solution Approach 2:
The patent implements dimensionality change by moving from isolated metric analysis to multidimensional analysis that incorporates multiple metrics simultaneously across multiple dimensions (time, context, relationships). This holistic approach considers interdependencies between different server resource metrics and contextual factors, significantly improving anomaly detection accuracy through comprehensive pattern recognition.
2Reliability
If traditional anomaly detection methods are used, then processing resources are consumed continuously, but false positives increase reducing the effectiveness of anomaly identification
Solution Approach 1:
The patent applies preliminary action by performing data normalization and establishing baseline patterns before actual anomaly detection occurs. The system pre-processes historical data to create reference models and normalization parameters, so that during operational monitoring, anomaly detection can be performed more efficiently with reduced computational overhead and lower false positive rates.
3Adaptability or versatility
If static threshold-based anomaly detection is used, then the system is simple to implement, but it cannot identify anomalies that deviate from normal patterns over time
Solution Approach 1:
The patent applies dynamics by implementing adaptive thresholding mechanisms that automatically adjust detection criteria based on observed patterns in the data. The system dynamically modifies detection parameters in response to changing conditions, enabling it to identify anomalies that deviate from evolving normal patterns rather than relying on fixed thresholds.
Solution Approach 2:
The patent implements self-service through automated normalization and adaptive learning mechanisms that enable the system to improve its own performance over time. The detection system automatically adjusts to new patterns and contexts without requiring manual reconfiguration, continuously refining its anomaly detection capabilities based on accumulated operational data.
Data Source
AI summary
A device may receive data for a plurality of metrics from a set of server resources associated with hosting an application. The plurality of metrics may be related to a performance of the set of server resources. The data may be time series data. The device may normalize the data for the plurality of metrics across a set of points in time to form normalized data. The device may determine a score for the performance of the set of server resources associated with hosting the application at a particular point in time based on the normalized data. The score may be used to determine whether an anomaly is present in the performance of the set of server resources at the particular point in time. The device may perform an action to facilitate improvement of the performance of the set of server resources based on the score satisfying a threshold.


