{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T10:23:30Z","timestamp":1782987810618,"version":"3.54.5"},"reference-count":28,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2009,11,1]],"date-time":"2009-11-01T00:00:00Z","timestamp":1257033600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000144","name":"Division of Computer and Network Systems","doi-asserted-by":"publisher","award":["CSR-0720699CCF-0811417"],"award-info":[{"award-number":["CSR-0720699CCF-0811417"]}],"id":[{"id":"10.13039\/100000144","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Comput. Syst."],"published-print":{"date-parts":[[2009,11]]},"abstract":"<jats:p>Automated tools for understanding application behavior and its changes during the application lifecycle are essential for many performance analysis and debugging tasks. Application performance issues have an immediate impact on customer experience and satisfaction. A sudden slowdown of enterprise-wide application can effect a large population of customers, lead to delayed projects, and ultimately can result in company financial loss. Significantly shortened time between new software releases further exacerbates the problem of thoroughly evaluating the performance of an updated application. Our thesis is that online performance modeling should be a part of routine application monitoring. Early, informative warnings on significant changes in application performance should help service providers to timely identify and prevent performance problems and their negative impact on the service. We propose a novel framework for automated anomaly detection and application change analysis. It is based on integration of two complementary techniques: (i) a regression-based transaction model that reflects a resource consumption model of the application, and (ii) an application performance signature that provides a compact model of runtime behavior of the application. The proposed integrated framework provides a simple and powerful solution for anomaly detection and analysis of essential performance changes in application behavior. An additional benefit of the proposed approach is its simplicity: It is not intrusive and is based on monitoring data that is typically available in enterprise production environments. The introduced solution further enables the automation of capacity planning and resource provisioning tasks of multitier applications in rapidly evolving IT environments.<\/jats:p>","DOI":"10.1145\/1629087.1629089","type":"journal-article","created":{"date-parts":[[2009,11,24]],"date-time":"2009-11-24T15:21:01Z","timestamp":1259076061000},"page":"1-32","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":71,"title":["Automated anomaly detection and performance modeling of enterprise applications"],"prefix":"10.1145","volume":"27","author":[{"given":"Ludmila","family":"Cherkasova","sequence":"first","affiliation":[{"name":"Hewlett-Packard Labs, Palo Alto, CA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kivanc","family":"Ozonat","sequence":"additional","affiliation":[{"name":"Hewlett-Packard Labs, Palo Alto, CA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ningfang","family":"Mi","sequence":"additional","affiliation":[{"name":"Northeastern University, Boston, MA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Julie","family":"Symons","sequence":"additional","affiliation":[{"name":"Hewlett-Packard, Cupertino, CA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Evgenia","family":"Smirni","sequence":"additional","affiliation":[{"name":"College of William and Mary, Williamsburg, VA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2009,11,27]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945454"},{"key":"e_1_2_1_2_1","unstructured":"Arlitt M. and Farkas K. 2005. The case for data assurance. HP laboratories rep. No. HPL-2005-38. http:\/\/www.hpl.hp.com\/techreports\/2005\/HPL-2005-38.html.  Arlitt M. and Farkas K. 2005. The case for data assurance. HP laboratories rep. No. HPL-2005-38. http:\/\/www.hpl.hp.com\/techreports\/2005\/HPL-2005-38.html."},{"key":"e_1_2_1_3_1","volume-title":"Proceedings of the 6th Symposium on Operating Systems Design and Implementation (OSDI'04)","author":"Barham P.","unstructured":"Barham , P. , Donnelly , A. , Isaacs , R. , and Mortier , R . 2004. Using Magpie for request extraction and workload modelling . In Proceedings of the 6th Symposium on Operating Systems Design and Implementation (OSDI'04) . Barham, P., Donnelly, A., Isaacs, R., and Mortier, R. 2004. Using Magpie for request extraction and workload modelling. In Proceedings of the 6th Symposium on Operating Systems Design and Implementation (OSDI'04)."},{"key":"e_1_2_1_4_1","unstructured":"BMC. ProactiveNet. http:\/\/www.bmc.com\/.  BMC. ProactiveNet. http:\/\/www.bmc.com\/."},{"key":"e_1_2_1_5_1","unstructured":"CA Willy Introscope. http:\/\/www.ca.com\/us\/application-management-solution.aspx.  CA Willy Introscope. http:\/\/www.ca.com\/us\/application-management-solution.aspx."},{"key":"e_1_2_1_6_1","volume-title":"Proceedings of the 1st International Conference on Networked Systems Design and Implementation (NSDI'04)","author":"Chen M.","unstructured":"Chen , M. , Accardi , A. , Kiciman , E. , Lloyd , J. , Patterson , D. , Fox , A. , and Brewer , E . 2004. Path-based failure and evolution management . In Proceedings of the 1st International Conference on Networked Systems Design and Implementation (NSDI'04) . Chen, M., Accardi, A., Kiciman, E., Lloyd, J., Patterson, D., Fox, A., and Brewer, E. 2004. Path-based failure and evolution management. In Proceedings of the 1st International Conference on Networked Systems Design and Implementation (NSDI'04)."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/945846.945849"},{"key":"e_1_2_1_8_1","volume-title":"Proceedings of the 6th International Symposium on Computers and Communications (ISCC'01)","author":"Cherkasova L.","unstructured":"Cherkasova , L. and Karlsson , M . 2001. Dynamics and evolution of Web sites: Analysis, metrics and design issues . In Proceedings of the 6th International Symposium on Computers and Communications (ISCC'01) . Cherkasova, L. and Karlsson, M. 2001. Dynamics and evolution of Web sites: Analysis, metrics and design issues. In Proceedings of the 6th International Symposium on Computers and Communications (ISCC'01)."},{"key":"e_1_2_1_9_1","unstructured":"Chou T. 2004. The End of Software: Transforming Your Business for the On Demand Future. Sams.  Chou T. 2004. The End of Software: Transforming Your Business for the On Demand Future. Sams."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095810.1095821"},{"key":"e_1_2_1_11_1","volume-title":"Proceedings of USENIX Symposium on Internet Technologies and Systems.","author":"Douglis F.","unstructured":"Douglis , F. , Feldmann , A. , and Krishnamurthy , B . 1997. Rate of change and other metrics: A live study of the World Wide Web . In Proceedings of USENIX Symposium on Internet Technologies and Systems. Douglis, F., Feldmann, A., and Krishnamurthy, B. 1997. Rate of change and other metrics: A live study of the World Wide Web. In Proceedings of USENIX Symposium on Internet Technologies and Systems."},{"key":"e_1_2_1_12_1","doi-asserted-by":"crossref","unstructured":"Draper N. R. and Smith H. 1998. Applied Regression Analysis. John Wiley&amp;Sons.  Draper N. R. and Smith H. 1998. Applied Regression Analysis. John Wiley&amp;Sons.","DOI":"10.1002\/9781118625590"},{"key":"e_1_2_1_13_1","unstructured":"IBM Corporation. Tivoli Web management solutions. http:\/\/www.tivoli.com\/products\/demos\/twsm.html.  IBM Corporation. Tivoli Web management solutions. http:\/\/www.tivoli.com\/products\/demos\/twsm.html."},{"key":"e_1_2_1_14_1","unstructured":"Menasce D. Almeida V. and Dowdy L. 1994. Capacity Planning and Performance Modeling: From Mainframes to Client-Server Systems. Prentice Hall.   Menasce D. Almeida V. and Dowdy L. 1994. Capacity Planning and Performance Modeling: From Mainframes to Client-Server Systems. Prentice Hall."},{"key":"e_1_2_1_15_1","unstructured":"Mercury Diagnostics. http:\/\/www.mercury.com\/us\/products\/diagnostics\/.  Mercury Diagnostics. http:\/\/www.mercury.com\/us\/products\/diagnostics\/."},{"key":"e_1_2_1_16_1","unstructured":"Mercury Real User Monitor. http:\/\/www.mercury.com\/us\/products\/business-availability-center\/end-use%r-management\/real-user-monitor\/.  Mercury Real User Monitor. http:\/\/www.mercury.com\/us\/products\/business-availability-center\/end-use%r-management\/real-user-monitor\/."},{"key":"e_1_2_1_17_1","volume-title":"Proceedings of the Network Operations and Management Symposium (NOMS'08)","author":"Mi N.","unstructured":"Mi , N. , Cherkasova , L. , Ozonat , K. , Symons , J. , and Smirni , E . 2008. Analysis of application performance and its change via representative application signatures . In Proceedings of the Network Operations and Management Symposium (NOMS'08) . Mi, N., Cherkasova, L., Ozonat, K., Symons, J., and Smirni, E. 2008. Analysis of application performance and its change via representative application signatures. In Proceedings of the Network Operations and Management Symposium (NOMS'08)."},{"key":"e_1_2_1_18_1","unstructured":"NetQoS Inc. http:\/\/www.netqos.com.  NetQoS Inc. http:\/\/www.netqos.com."},{"key":"e_1_2_1_19_1","unstructured":"Netuitive Inc. http:\/\/www.netuitive.com\/.  Netuitive Inc. http:\/\/www.netuitive.com\/."},{"key":"e_1_2_1_20_1","unstructured":"Nimsoft Co. http:\/\/www.nimsoft.com\/solutions\/.  Nimsoft Co. http:\/\/www.nimsoft.com\/solutions\/."},{"key":"e_1_2_1_21_1","unstructured":"Quest Software Inc. Performasure. http:\/\/http:\/\/www.quest.com\/performasure.  Quest Software Inc. Performasure. http:\/\/http:\/\/www.quest.com\/performasure."},{"key":"e_1_2_1_22_1","volume-title":"Proceedings of the 3rd USENIX Symposium on Internet Technologies and Systems (USITS).","author":"Rajamony R.","unstructured":"Rajamony , R. and Elnozahy , M . 2001. Measuring client-perceived response times on the WWW . In Proceedings of the 3rd USENIX Symposium on Internet Technologies and Systems (USITS). Rajamony, R. and Elnozahy, M. 2001. Measuring client-perceived response times on the WWW. In Proceedings of the 3rd USENIX Symposium on Internet Technologies and Systems (USITS)."},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/1272996.1273002"},{"key":"e_1_2_1_24_1","unstructured":"Symantec I3. Application performance management. http:\/\/www.symantec.com\/business\/products\/.  Symantec I 3 . Application performance management. http:\/\/www.symantec.com\/business\/products\/."},{"key":"e_1_2_1_25_1","unstructured":"TPC-W Benchmark. http:\/\/www.tpc.org.  TPC-W Benchmark. http:\/\/www.tpc.org."},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1064212.1064252"},{"key":"e_1_2_1_27_1","volume-title":"Proceedings of the 8th ACM\/IFIP\/USENIX International Middleware Conference (Middleware'07)","author":"Zhang Q.","unstructured":"Zhang , Q. , Cherkasova , L. , Mathews , G. , Greene , W. , and Smirni , E . 2007a. R-Capriccio: A capacity planning and anomaly detection tool for enterprise services with live workloads . In Proceedings of the 8th ACM\/IFIP\/USENIX International Middleware Conference (Middleware'07) . Zhang, Q., Cherkasova, L., Mathews, G., Greene, W., and Smirni, E. 2007a. R-Capriccio: A capacity planning and anomaly detection tool for enterprise services with live workloads. In Proceedings of the 8th ACM\/IFIP\/USENIX International Middleware Conference (Middleware'07)."},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICAC.2007.1"}],"container-title":["ACM Transactions on Computer Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1629087.1629089","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1629087.1629089","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T20:22:19Z","timestamp":1750278139000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1629087.1629089"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,11]]},"references-count":28,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2009,11]]}},"alternative-id":["10.1145\/1629087.1629089"],"URL":"https:\/\/doi.org\/10.1145\/1629087.1629089","relation":{},"ISSN":["0734-2071","1557-7333"],"issn-type":[{"value":"0734-2071","type":"print"},{"value":"1557-7333","type":"electronic"}],"subject":[],"published":{"date-parts":[[2009,11]]},"assertion":[{"value":"2008-11-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2009-05-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2009-11-27","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}