IP Library Patent Application 11554980
Patent Application
App. No. 11/554,980

DISTRIBUTED DETECTION WITH DIAGNOSIS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/554,980
Abstract

Activity models are maintained on a plurality of computers on a network. When a user or a particular activity model at a computer discovers an error, it may query its own activity model to determine a possible source of the error. If it is determined to not be the likely source of the error, the activity model queries the activity models of those computers on the network that it depends on. These activity models may then query the activity models of the computers that their particular host computer depends on and so forth. Ultimately the results of these activity model queries may be used to diagnose the likely source of the error and may be presented to the requesting user as a report.

Claims (31)

1 . A method for distributed anomaly diagnosis, comprising:

detecting an anomaly at a first computer on a network;

querying an activity model at the first computer to determine the source of the anomaly;

determining a second computer that the first computer receives data from; and

querying an activity model of the second computer to determine the source of the anomaly; and

combining the results from the activity models to create a report indicating a probable cause of the anomaly.

2 . (canceled)

3 . The method of claim 1 , wherein the anomaly is detected by an activity model.

4 . The method of claim 1 , wherein the anomaly is detected by a user.

5 . The method of claim 1 , further comprising determining a third computer that the second computer receives data from, and querying an activity model of the third computer to determine the source of the problem.

6 . The method of claim 1 , wherein querying the activity model comprises collecting a window of input and output data from the computer, and querying the activity model with the window of input and output data.

7 . The method of claim 6 , wherein the input and output data comprises packets.

8 . The method of claim 1 , wherein determining a second computer that the first computer receives data from comprises querying the activity model to determine a computer that the first computer receives packets from.

9 . The method of claim 1 , wherein the detected anomaly is a service error, and the queried activity model comprises an activity model specific to the service associated with the error.

10 . A method for diagnosing system failures using an activity model, comprising:

maintaining a buffer of the most recent data send to and from a host computer;

detecting a system failure by the host computer; and

querying an activity model associated with the host computer using the buffer of data.

11 . The method of claim 10 , wherein the data comprises packet data.

12 . The method of claim 10 , wherein the host computer is part of a network of computers wherein each of the computers has an associated activity model and maintains a buffer of the most recent data received and sent from the computer, and further comprising:

determining the computers that the host computer is connected to; and

querying the activity models of the determined connected computers with their respective buffer of data.

13 . The method of claim 12 , wherein determining the computers that the host computer is connected to comprises determining the computers that the host computer sends or receives packets from.

14 . The method of claim 12 , wherein determining the computers that the host computer is connected to comprises querying the activity model to determine the computers that the host computer receives the most packets from.

15 . The method of claim 10 , wherein the system failure is associated with a particular service, and further comprising querying a service specific activity model associated with the host computer using the buffer of data.

16 . A method of determining the effect of a change in a computer system, comprising:

selecting a service to modify in a computer system;

querying an activity model associated with the computer system to determine other services and other computers that are dependent on the selected service; and

generating a report including the determined other services and other computers that are dependent on the selected service.

17 . The method of claim 16 , wherein the determined other computers have associated activity models, and further comprising querying the associated activity models of the determined other computers to determine other services and other computers that may be dependent on the selected service.

18 . The method of claim 16 , wherein the generated report includes the probability that a particular computer or service will be affected by the selected service modification.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2015
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034766/0509 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2007
From: BARHAM, PAUL; BLACK, RICHARD; GOLDSZMIDT, MOISES; ISAACS, REBECCA; MACCORMICK, JOHN; MORTIER, RICHARD
To: MICROSOFT CORPORATION
Reel/Frame 018798/0987 →