DETECTING OUTLIERS IN NETWORK TRAFFIC TIME SERIES
According to an aspect of the invention, a system and method is configured to detect time series outliers in network traffic.
1 . A computer-implemented method, comprising:
identifying, by computer, an outlier for a network traffic metric if observed network traffic is outside of a prediction interval during a time period; and
identifying an anomaly for the network traffic metric only when a count of outliers for the network traffic metric identified during the time period is greater than or equal to two, and exceeds an anomaly threshold for the network traffic metric.
2 . The computer-implemented method of claim 1 , further comprising merging identified anomalies for each of a plurality of network traffic metrics to identify a single event.
3 . The computer-implemented method of claim 2 , further comprising providing information about the network traffic to a user upon identification of the single event.
4 . The computer-implemented method of claim 1 , wherein prior to identifying the outlier, the method further comprising:
generating a forecast of network traffic using a model, the forecast being based on previously observed network traffic;
generating a prediction interval that extends above and below the forecast of the network traffic, the prediction interval being based on previously observed deviations from predicted network traffic; and
comparing observed network traffic to the prediction interval.
5 . The computer-implemented method of claim 4 , wherein the model includes at least a first and a second seasonality, and wherein the forecast is generated based on previously observed network traffic at first and second time periods associated with the first and the second seasonality.
6 . The computer-implemented method of claim 4 , wherein the model is a Holt-Winters model having daily and weekly seasonality.
7 . The computer-implemented method of claim 4 , wherein said generating the forecast of network traffic using the model includes:
generating the forecast based on at least two weeks of network traffic data; and
generating the prediction interval based on at least one week of network traffic data.
8 . A non-transitory computer-readable storage medium storing instructions that, when executed by a computer, cause the computer to perform a method comprising:
Identifying an outlier for a network traffic metric if observed network traffic is outside of a prediction interval during a time period; and
identifying an anomaly for the network traffic metric only when a count of outliers for the network traffic metric identified during the time period is greater than or equal to two, and exceeds an anomaly threshold for the network traffic metric.
9 . The non-transitory computer-readable storage medium of claim 8 , further comprising merging identified anomalies for each of a plurality of network traffic metrics to identify a single event.
10 . The non-transitory computer-readable storage medium of claim 9 , further comprising providing information about the network traffic to a user upon identification of the single event.
11 . The non-transitory computer-readable storage medium of claim 8 , wherein prior to identifying the outlier, the method further comprising:
generating a forecast of network traffic using a model, the forecast being based on previously observed network traffic;
generating a prediction interval that extends above and below the forecast of the network traffic, the prediction interval being based on previously observed deviations from predicted network traffic; and
comparing observed network traffic to the prediction interval.
12 . The non-transitory computer-readable storage medium of claim 11 , wherein the model includes at least a first and a second seasonality, and wherein the forecast is generated based on previously observed network traffic at first and second time periods associated with the first and the second seasonality.
13 . The non-transitory computer-readable storage medium of claim 11 , wherein the model is a Holt-Winters model having daily and weekly seasonality.
14 . The non-transitory computer-readable storage medium of claim 11 , wherein said generating the forecast of network traffic using the model includes:
generating the forecast based on at least two weeks of network traffic data; and
generating the prediction interval based on at least one week of network traffic data.
15 . An apparatus, comprising:
a processor; and
a storage medium storing instructions that, when executed by the processor, cause the apparatus to perform a method comprising:
identifying an outlier for a network traffic metric if observed network traffic is outside of a prediction interval during a time period; and
identifying an anomaly for the network traffic metric only when a count of outliers for the network traffic metric identified during the time period is greater than or equal to two, and exceeds an anomaly threshold for the network traffic metric.
16 . The apparatus of claim 15 , wherein the method further comprises merging identified anomalies for each of a plurality of network traffic metrics to identify a single event.
17 . The apparatus of claim 16 , wherein the method further comprises providing information about the network traffic to a user upon identification of the single event.
18 . The apparatus of claim 15 , wherein prior to identifying the outlier, the method further comprises:
generating a forecast of network traffic using a model, the forecast being based on previously observed network traffic;
generating a prediction interval that extends above and below the forecast of the network traffic, the prediction interval being based on previously observed deviations from predicted network traffic; and
comparing observed network traffic to the prediction interval.
19 . The apparatus of claim 18 , wherein the model includes at least a first and a second seasonality, and wherein the forecast is generated based on previously observed network traffic at first and second time periods associated with the first and the second seasonality.
20 . The apparatus of claim 18 , wherein said generating the forecast of network traffic using the model includes:
generating the forecast based on at least two weeks of network traffic data; and
generating the prediction interval based on at least one week of network traffic data.