IP Library Granted Patent US 9,197,511
Granted Patent B2
US 9,197,511 · App. 13/651,176 · Granted Nov 24, 2015

Anomaly detection in network-site metrics using predictive modeling

Inventor: Craig M. Mathis (American Fork, UT)
Assignee: Adobe Systems Incorporated
H04L41/147H04L41/145H04L43/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,197,511
App. No.
13/651,176
Granted
Nov 24, 2015
Kind
B2
Abstract

Methods and apparatus for anomaly detection in network-site metrics using predictive modeling are described. A method comprises obtaining time-series data for a given time range, wherein the time-series data comprises values for a network-site analytics metric for each of a plurality of sequential time steps across the given time range. The method includes generating a predictive model for the network-site analytics metric based on at least a segment of the time-series data. The method includes using the predictive model to predict an expected value range for the network-site analytics metric for a next time step after the segment and, based on the expected value range, determining whether an actual value for the network-site analytics metric for the next time step is an anomalous value.

Claims (42)

1. A method, comprising:

performing, by one or more computing devices:

obtaining time-series data for a given time range, wherein the time-series data comprises values for a network-site analytics metric for each of a plurality of sequential time steps across the given time range;

generating a predictive model for the network-site analytics metric based on at least a segment of the time-series data, wherein the predictive model performs time series analysis by taking recognized cycles into consideration by applying a mathematical model that represents the recognized cycles;

using the predictive model to predict different expected value ranges based on different confidence levels for the network-site analytics metric for a next time step after the segment;

based on detection of actual values that are outside of the different expected value ranges for different numbers of consecutive occurrences, determining whether a particular actual value for the network-site analytics metric for the next time step is an anomalous value; and

indicating the particular actual value as the anomalous value in a report display for the network-site analytics metric.

2. The method of claim 1 , further comprising, in response to determining that the particular actual value for the network-site analytics metric for the next time step is the anomalous value, sending an alert to a user.

3. The method of claim 1 , wherein said determining whether the particular actual value for the network-site analytics metric for the next time step is the anomalous value comprises determining whether the particular actual value exceeds the different expected value ranges by a threshold amount.

4. The method of claim 1 , wherein said determining whether the particular actual value for the network-site analytics metric for the next time step is the anomalous value comprises determining whether the particular actual value is one of a plurality of actual values for the network-site analytics metric that exceed respective expected value ranges for consecutive time steps.

5. The method of claim 1 , wherein the network-site analytics metric is a metric selected from the group of site visits, page views, revenue, file download views, successful sign in count, returning user count, product registration count, impressions, click throughs, and conversions.

6. The method of claim 1 , wherein said generating the predictive model comprises using the segment of the time-series data as training data to generate a plurality of predictive models according to a plurality of different time-series forecasting techniques.

7. The method of claim 1 , further comprising updating the predictive model based on the particular actual value of the network-site analytics metric for the next time step.

8. The method of claim 7 , wherein said updating the predictive model comprises using an upper or lower value of a first expected value range of the different expected value ranges instead of the particular actual value to update the predictive model when the particular actual value exceeds the first expected value range.

9. The method of claim 1 , wherein performing the time series analysis by the predictive model predicts the expected value range so that:

abnormally high or low weekend volume are identified as anomalies; and

weekend volume changes that are more closely tied to regular cyclical changes are not identified as anomalies.

10. The method of claim 1 , wherein using the predictive model to predict the different expected value ranges based on the different confidence levels comprises:

predicting a first expected value range in accordance with a first confidence level;

predicting a second expected value range in accordance with a second confidence level that is different from the first confidence level; and

wherein determining, based on detection of actual values that are outside of the different expected value ranges for different numbers of consecutive occurrences, that the particular actual value for the network-site analytics metric for the next time step is the anomalous value comprises:

monitoring the actual values to detect anomalies based on a first number of consecutive actual values outside of the first expected value range; and

monitoring the actual values to detect anomalies based on a second number of consecutive actual values outside of the second expected value range, wherein the first number is different from the second number.

11. A system, comprising:

at least one processor; and

a memory comprising program instructions that when executed by the at least one processor implement:

obtaining time-series data for a given time range, wherein the time-series data comprises values for a network-site analytics metric for each of a plurality of sequential time steps across the given time range;

generating a predictive model for the network-site analytics metric based on at least a segment of the time-series data, wherein the predictive model performs time series analysis by taking recognized cycles into consideration by applying a mathematical model that represents the recognized cycles;

using the predictive model to predict different expected value ranges based on different confidence levels for the network-site analytics metric for a next time step after the segment;

based on detection of actual values that are outside of the different expected value ranges for different numbers of consecutive occurrences, determining whether a particular actual value for the network-site analytics metric for the next time step is an anomalous value; and

in response to determining that the particular actual value for the network-site analytics metric for the next time step is the anomalous value, sending an alert to a user.

12. The system of claim 11 , wherein said determining whether the particular actual value for the network-site analytics metric for the next time step is the anomalous value comprises determining whether the particular actual value exceeds the different expected value range by a threshold amount or determining whether the particular actual value is one of a plurality of actual values for the network-site analytics metric that exceed respective expected value ranges for consecutive time steps.

13. The system of claim 11 , wherein the program instructions when executed by the at least one processor further implement said obtaining, said generating, said using, said determining, and said sending for a plurality of different network-site analytics metrics having respective values in each of the plurality of sequential time steps across the given time range.

14. The system of claim 11 , wherein said generating the predictive model comprises using the segment of the time-series data as training data to generate the predictive model according to a time-series forecasting technique.

15. A non-transitory computer-readable storage medium storing program instructions that when executed by a computing device perform:

obtaining time-series data for a given time range, wherein the time-series data comprises values for a network-site analytics metric for each of a plurality of sequential time steps across the given time range;

generating a predictive model for the network-site analytics metric based on at least a segment of the time-series data, wherein the predictive model performs time series analysis by taking recognized cycles into consideration by applying a mathematical model that represents the recognized cycles;

using the predictive model to predict different expected value ranges based on different confidence levels for the network-site analytics metric for a next time step after the segment;

based on detection of actual values that are outside of the different expected value ranges for different numbers of consecutive occurrences, determining whether a particular actual value for the network-site analytics metric for the next time step is an anomalous value; and

indicating the particular actual value as the anomalous value in a report display for the network-site analytics metric.

16. The non-transitory computer-readable storage medium of claim 15 , wherein the program instructions when executed by a computing device further perform, in response to determining that the particular actual value for the network-site analytics metric for the next time step is the anomalous value, sending an alert to a user.

17. The non-transitory computer-readable storage medium of claim 15 , wherein the program instructions when executed by a computing device further perform updating the predictive model based on the particular actual value of the network-site analytics metric for the next time step or using an upper or lower value of a first expected value range of the different expected value ranges instead of the particular actual value to update the predictive model when the particular actual value exceeds the first expected value range.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2012
From: MATHIS, CRAIG M.
To: ADOBE SYSTEMS INCORPORATED
Reel/Frame 029128/0770 →
Continuity (1)
Related Publication 20140108640A1 · Apr 17, 2014