Anomaly detection mechanism evaluations
In one implementation, a device may obtain anomaly detection time series indicative of anomalies detected by a plurality of anomaly detectors for a network. The device may determine a degree of correlation over time between the anomaly detection time series. The device may make, based on the degree of correlation over time between the anomaly detection time series, a performance evaluation for a particular anomaly detector from among the plurality of anomaly detectors. The device may provide the performance evaluation to a user interface for review.
1 . A method, comprising:
obtaining, by a device, a plurality of anomaly detection time series indicative of anomalies detected by a plurality of anomaly detectors for a network, wherein each of the plurality of anomaly detectors provide a respective anomaly detection time series of the plurality of anomaly detection time series, and wherein the anomalies are associated with anomalous values of a path performance metric;
comparing, by the device, the plurality of anomaly detection time series to determine a degree of correlation over time between the plurality of anomaly detection time series;
making, by the device and based on the degree of correlation over time between the plurality of anomaly detection time series, a performance evaluation for an anomaly detector from among the plurality of anomaly detectors, wherein the anomaly detector uses a different anomaly detection model than at least one other anomaly detector in the plurality of anomaly detectors;
providing, by the device, the performance evaluation to a user interface for review.
2 . The method as in claim 1 , wherein the performance evaluation indicates good performance by the anomaly detector when the degree of correlation over time indicates a positive correlation between the anomaly detection time series.
3 . The method as in claim 1 , wherein the plurality of anomaly detectors generates the plurality of anomaly detection time series based on outputs of testing agents configured to perform testing in the network.
4 . The method as in claim 3 , wherein the plurality of anomaly detection time series are associated with the testing agents performing testing in the network with respect to a particular server.
5 . The method as in claim 3 , wherein the testing agents perform testing in the network by sending probing packets via the network.
6 . The method as in claim 1 , wherein the anomaly detector is executed by a router in the network.
7 . An apparatus, comprising:
one or more network interfaces;
a processor coupled to the one or more network interfaces and configured to execute one or more processes; and
a memory configured to store a process that is executable by the processor, the process when executed configured to:
obtain a plurality of anomaly detection time series indicative of anomalies detected by a plurality of anomaly detectors for a network, wherein each of the plurality of anomaly detectors provide a respective anomaly detection time series of the plurality of anomaly detection time series, and wherein the anomalies are associated with anomalous values of a path performance metric;
compare the plurality of anomaly detection time series to determine a degree of correlation over time between the plurality of anomaly detection time series;
make, based on the degree of correlation over time between the plurality of anomaly detection time series, a performance evaluation for an anomaly detector from among the plurality of anomaly detectors, wherein the anomaly detector uses a different anomaly detection model than at least one other anomaly detector in the plurality of anomaly detectors;
provide the performance evaluation to a user interface for review; and
update the anomaly detector based on the performance evaluation, including optimizing a model parameter of the anomaly detector based on the performance evaluation.
8 . The apparatus as in claim 7 , wherein the performance evaluation indicates good performance by the anomaly detector when the degree of correlation over time indicates a positive correlation between the anomaly detection time series.
9 . The apparatus as in claim 7 , wherein the plurality of anomaly detectors generates the plurality of anomaly detection time series based on outputs of testing agents configured to perform testing in the network.
10 . The apparatus as in claim 9 , wherein the plurality of anomaly detection time series are associated with the testing agents performing testing in the network with respect to a particular server.
11 . The apparatus as in claim 9 , wherein the testing agents perform testing in the network by sending probing packets via the network.
12 . The apparatus as in claim 9 , wherein the anomaly detector is executed by a router in the network.
13 . A tangible, non-transitory, computer-readable medium storing program instructions that cause a device to execute a process comprising:
obtaining a plurality of anomaly detection time series indicative of anomalies detected by a plurality of anomaly detectors for a network, wherein each of the plurality of anomaly detectors provide a respective anomaly detection time series of the plurality of anomaly detection time series, and wherein the anomalies are associated with anomalous values of a path performance metric;
comparing the plurality of anomaly detection time series to determine a degree of correlation over time between the plurality of anomaly detection time series;
making, based on the degree of correlation over time between the plurality of anomaly detection time series, a performance evaluation for an anomaly detector from among the plurality of anomaly detectors, wherein the anomaly detector uses a different anomaly detection model than at least one other anomaly detector in the plurality of anomaly detectors;
providing the performance evaluation to a user interface for review; and
updating the anomaly detector based on the performance evaluation, including optimizing a model parameter of the anomaly detector based on the performance evaluation.
14 . The tangible, non-transitory, computer-readable medium as in claim 13 , wherein the performance evaluation indicates good performance by the anomaly detector when the degree of correlation over time indicates a positive correlation between the anomaly detection time series.
15 . The tangible, non-transitory, computer-readable medium as in claim 13 , wherein the plurality of anomaly detectors generates the plurality of anomaly detection time series based on outputs of testing agents configured to perform testing in the network.
16 . The tangible, non-transitory, computer-readable medium as in claim 15 , wherein the plurality of anomaly detection time series are associated with the testing agents performing testing in the network with respect to a particular server.
17 . The tangible, non-transitory, computer-readable medium as in claim 15 , wherein the testing agents perform testing in the network by sending probing packets via the network.
18 . The tangible, non-transitory, computer-readable medium as in claim 13 , wherein the anomaly detector is executed by a router in the network.