IP Library › Granted Patent US 11,016,834
Granted Patent B2
US 11,016,834 · App. 16/365,471 · Granted May 25, 2021

Hybrid and hierarchical outlier detection system and method for large scale data protection

Inventors: Mu Qiao (Belmont, CA); Ramani R. Routray (San Jose, CA); Quan Zhang (Detroit, MI)
Assignee: International Business Machines Corporation
G06F11/0751G06F11/0727G06F11/1448G06F11/1458G06F17/10G06F17/18G06K9/0053G06K9/0055G06K9/6247G06K9/6284G06K9/6292G06N3/00G06N7/00G06N7/005G06N20/20G06F2212/1032
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,016,834
App. No.
16/365,471
Granted
May 25, 2021
Kind
B2
Abstract

One embodiment provides a method comprising receiving metadata comprising univariate time series data for each variable of a multivariate time series. The method comprises, for each variable of the multivariate time series, applying a hybrid and hierarchical model selection process to select an anomaly detection model suitable for the variable based on corresponding univariate time series data for the variable and covariations and interactions between the variable and at least one other variable of the multivariate time series, and detecting an anomaly on the variable utilizing the anomaly detection model selected for the variable. Based on each anomaly detection model selected for each variable of the multivariate time series, the method further comprises performing ensemble learning to determine whether the multivariate time series is anomalous at a particular time point.

Claims (35)

1. A method for reducing a number of false positives in anomaly detection for large scale data protection, comprising:

estimating common trends indicative of covariance and interactions among a set of variables of a multivariate time series related to data backup jobs performed on one or more storage devices by applying a dimension reduction technique to the multivariate time series;

applying seasonal-trend decomposition to detect anomalies for each variable of the set of variables based on the common trends; and

preventing a failure in data protection of the data backup jobs by:

for each variable of the multivariate time series, selecting, from different anomaly detection models with different performance costs, an anomaly detection model suitable for the variable based on one or more characteristics exhibited by corresponding univariate time series data for the variable and covariations and interactions between the variable and at least one other variable of the multivariate time series;

performing ensemble learning based on each anomaly detection model selected for each variable of the multivariate time series to determine whether the multivariate time series is anomalous at a particular time point, wherein a variable of the set of variables has at least one vote in the ensemble learning if at least one anomaly is detected for the variable utilizing an anomaly detection model selected for the variable;

generating a report indicative of whether the multivariate time series is anomalous at the particular time point; and

providing the report to a backup monitoring system monitored by a service administrator managing the one or more storage devices and the data backup jobs.

2. The method of claim 1 , wherein each variable of the set of variables exhibits seasonality.

3. The method of claim 1 , wherein applying seasonal-trend decomposition to detect anomalies for each variable of the set of variables based on the common trends comprises applying seasonal-trend decomposition procedure based on loess.

4. The method of claim 1 , wherein applying seasonal-trend decomposition to detect anomalies for each variable of the set of variables based on the common trends comprises applying a combination of seasonal-trend decomposition procedure based on loess and dynamic factor analysis.

5. A system for reducing a number of false positives in anomaly detection for large scale data protection, comprising:

at least one processor; and

a non-transitory processor-readable memory device storing instructions that when executed by the at least one processor causes the at least one processor to perform operations including:

estimating common trends indicative of covariance and interactions among a set of variables of a multivariate time series related to data backup jobs performed on one or more storage devices by applying a dimension reduction technique to the multivariate time series;

applying seasonal-trend decomposition to detect anomalies for each variable of the set of variables based on the common trends; and

preventing a failure in data protection of the data backup jobs by:

for each variable of the multivariate time series, selecting, from different anomaly detection models with different performance costs, an anomaly detection model suitable for the variable based on one or more characteristics exhibited by corresponding univariate time series data for the variable and covariations and interactions between the variable and at least one other variable of the multivariate time series;

performing ensemble learning based on each anomaly detection model selected for each variable of the multivariate time series to determine whether the multivariate time series is anomalous at a particular time point, wherein a variable of the set of variables has at least one vote in the ensemble learning if at least one anomaly is detected for the variable utilizing an anomaly detection model selected for the variable;

generating a report indicative of whether the multivariate time series is anomalous at the particular time point; and

providing the report to a backup monitoring system monitored by a service administrator managing the one or more storage devices and the data backup jobs.

6. The system of claim 5 , wherein each variable of the set of variables exhibits seasonality.

7. The system of claim 5 , wherein applying seasonal-trend decomposition to detect anomalies for each variable of the set of variables based on the common trends comprises applying seasonal-trend decomposition procedure based on loess.

8. The system of claim 5 , wherein applying seasonal-trend decomposition to detect anomalies for each variable of the set of variables based on the common trends comprises applying a combination of seasonal-trend decomposition procedure based on loess and dynamic factor analysis.

9. A computer program product comprising a computer-readable hardware storage medium having program code embodied therewith, the program code being executable by a computer to implement a method comprising:

estimating common trends indicative of covariance and interactions among a set of variables of a multivariate time series related to data backup jobs performed on one or more storage devices by applying a dimension reduction technique to the multivariate time series;

applying seasonal-trend decomposition to detect anomalies for each variable of the set of variables based on the common trends; and

preventing a failure in data protection of the data backup jobs by:

for each variable of the multivariate time series, selecting, from different anomaly detection models with different performance costs, an anomaly detection model suitable for the variable based on one or more characteristics exhibited by corresponding univariate time series data for the variable and covariations and interactions between the variable and at least one other variable of the multivariate time series;

performing ensemble learning based on each anomaly detection model selected for each variable of the multivariate time series to determine whether the multivariate time series is anomalous at a particular time point, wherein a variable of the set of variables has at least one vote in the ensemble learning if at least one anomaly is detected for the variable utilizing an anomaly detection model selected for the variable;

generating a report indicative of whether the multivariate time series is anomalous at the particular time point; and

providing the report to a backup monitoring system monitored by a service administrator managing the one or more storage devices and the data backup jobs.

10. The computer program product of claim 9 , wherein each variable of the set of variables exhibits seasonality.

11. The computer program product of claim 9 , wherein applying seasonal-trend decomposition to detect anomalies for each variable of the set of variables based on the common trends comprises applying seasonal-trend decomposition procedure based on loess.

12. The computer program product of claim 9 , wherein applying seasonal-trend decomposition to detect anomalies for each variable of the set of variables based on the common trends comprises applying a combination of seasonal-trend decomposition procedure based on loess and dynamic factor analysis.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2019
From: QIAO, MU; ROUTRAY, RAMANI R.; ZHANG, QUAN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 048708/0558 →
Continuity (2)
Continuation 15397627 · Jan 3, 2017
Related Publication 20190220339A1 · Jul 18, 2019
Cited By (1)
US 12,613,986