One way to get a copy of the paper would be to make a photocopy at a library or pay a service to do that.
Explanation is a problem, also for my work.
Broadly, for a first cut, pick a target system want to monitor. Then use variables that are for the target, the whole target, nothing but the target or some such. Then if get a detection, start diagnosis, looking for cause, with the target.
For two targets that interact, have detectors for each and then one more for variables from both of them.
Broadly, but crudely, have a hierarchy of detectors and then when start getting detections chase down the tree of the hierarchy, like the patient is sick so, look at the major measures and the major organs, etc. When find a suspicious organ, zoom in, drill down, etc. Finally discover the problem is a USB cable that is loose from vibrations from a cooling fan or some such??
In this tree, might want to have somewhat coordinated false alarm rates.
One motivation for my work was a cluster for transactions. One day one computer in the cluster got a little sick in the head and was throwing away all its incoming transactions. So, to the load leveling it looked not very busy and was getting nearly all the transactions and, thus, essentially ruined the work of the whole cluster. And that's not the only case of a cluster getting totally sick due to just one computer in the cluster getting sick. So, I was hoping that getting data from all the computers in the cluster would raise an alarm from the cluster and data from each of the computers in the cluster would essentially do the diagnosis of which computer in the cluster was sick.
Likely more could be done. E.g., might want to do some data scaling.
I don't yet have a big server farm, and I don't know anyone who does who cares enough about anomaly detection to use my work. Expert systems? At one time, yup. My work? Nope. If my startup does well, then, sure, I'll deploy my detector, lots of instances.
My startup isn't anomaly detection.
At one time, I wrote lots of VCs about my anomaly detection work, that it was from IBM's Watson lab, that it was published in Information Sciences, that I had work on fast algorithms, that I had good results on real data, etc. I got back just nothing.
I guessed that the target customers would be high end shops so that I would have to come in with a highly polished product, with lots of good data handling utility tools, some first class hand holding, etc., all of which would be expensive before the first sale. So, I gave up on the idea that I could do a startup from my anomaly work. There might be a way; if I ran a large, really serious server farm, I have at least a little project pursuing my work and/or related work. But, apparently mostly that's not the way server farm management works.
So, I picked another problem for a startup, one where I could get a good solution and bring it to good revenue with just my own efforts as sole, solo founder. I did that and am about to go for an alpha test.
Somehow anomaly detection just doesn't get people very interested.
Once I gave a talk, and some in the audience mentioned that could use my work for fraud detection in, say, credit cards. Well, maybe, but that audience had nothing to do with credit cards.
At one time there were some Soviets in England watching some government offices and keeping track of lights, comings, goings, etc. They guessed that if a war was on the way, this data would show anomalies and early warning. Yup, the Soviets saw the broad issue. I don't know if they used anything like my work or not.
So, maybe the secret is not just some good work in applied probability with some useful results but publicity, hype, fads, group think, a movement, etc., even if what are selling is just total nonsense.
My work is on the shelves of the research libraries. I did my part. If people want anomaly detection, there's some good work there. I've told the Sand Hill Road people, the Hacker News audience, several organizations, e.g., the main NASDAQ server farm at Trumbull, CT, etc.
My experience is that people will start to act, react, if they have a problem that, like a tight shoe, really hurts, and then start to work on the problem. If some early work has the shoe not pinch so much, then they will f'get about that work and that problem and concentrate on something else, even if there's lots of money to be made in better solutions to the original problem.
There is a time lag problem: A lot of the math is on the shelves of the libraries, but only much more recently has suitable computing been available. Only a tiny fraction of people in computing now, where the computing has the potential, know that old math that's been sitting there waiting on the computing.
E.g., when I first did my work on anomaly detection, some people said that a lot of computing would be needed. Well, yup. The response was so obvious I didn't have to make it: The needed computing was coming. Well, now, say, with solid state disks, big server farms, lots of system monitoring data gathering, etc., now the time is right for actual usage. But, nope, interest is really low!
The startup I'm pursuing now is much more promising. I don't have to get a few bureaucratic, cautious, conservative, CIOs all fired up. Instead I just have to please a lot of Internet users a little bit each, and that should be much easier.
The CIOs are running big server farms, and they are working. So, they don't have a shoe that pinches very much. So, they are not motivated to do anything new or different. Okay, lesson learned.