IP Library › Granted Patent US 9,990,273
Granted Patent B2
US 9,990,273 · App. 15/230,077 · Granted Jun 5, 2018

Methods and systems for anomaly detection

Inventors: Ramkumar Ilangovan (Chennai, IN); Sayantan Das (Kolkata, IN); Shounak Kundu (Kolkata, IN); Swarup Chatterjee (Kolkata, IN)
Assignee: Tata Consultancy Services Limited
G06F11/3688G06F8/70G06F8/77G06F9/44G06F11/34G06F11/366G06F11/3612G06F11/3636G06F11/0715G06F11/0775
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,990,273
App. No.
15/230,077
Granted
Jun 5, 2018
Kind
B2
Abstract

This disclosure relates generally to anomaly detection, and more particularly to system and method for detecting anomalies. In one embodiment, the method includes executing at least one thread associated with the application. Executing the at least one thread results in invoking one or more methods associated with the at least one thread. During the execution metrics associated with the one or more methods are captured. The metrics are systematically arranged in a data structure to represent a plurality of thread-method pairs and the metrics corresponding to each of the plurality of thread-method pairs. One or more anomalies associated with the one or more methods are identified from the data structure based on a detection of at least one predetermined condition in the data structure. An anomaly of the one or more anomalies includes one of un-exited anomaly, an exception anomaly and a user-defined anomaly.

Claims (27)

1. A processor-implemented method for anomaly detection in an application, the method comprising

systematically executing at least one thread associated with the application, wherein executing the at least one thread results in invoking one or more methods associated with the at least one thread, wherein the at least one thread is systematically executed upon establishing a monitoring session with a server that runs the application;

periodically capturing, during the execution, metrics associated with the one or more methods during the monitoring session, wherein the metrics are generated during systematic execution of the application in runtime environment, wherein the metrics are periodically captured using a default auto-generated standard configuration;

systematically arranging the metrics in a data structure to represent a plurality of thread-method pairs and the metrics corresponding to each of the plurality of thread-method pairs; and

identifying, from the data structure, one or more anomalies associated with the one or more methods based on a detection of at least one predetermined condition associated with the metrics in the data structure, wherein an anomaly of the one or more anomalies comprises one of unexited anomaly, an exception anomaly and a user-defined anomaly.

2. The method of claim 1 , wherein the metrics associated with the one or more methods comprises method name, method invocation timestamp, method exit timestamp, method stack-trace, exception name, exception cause, and exception timestamp.

3. The method of claim 1 , wherein identifying the un-exited anomaly in the one or more methods comprises detecting absence of the method exit timestamp in the metrics associated with the one or more methods.

4. The method of claim 1 , wherein identifying the exception anomaly in the one or more methods comprises detecting exception name, exception cause, and exception timestamp in the metrics associated with the one or more methods.

5. The method of claim 1 , wherein the at least one predetermined condition is defined by a user to identify the user-defined anomaly in the method.

6. The method of claim 1 , wherein the application is a distributed application having multiple layers, the distributed application comprising one or more of at least one web interface, at least one database component and at least one application interface.

7. A system for anomaly detection in an application comprising:

at least one memory; and

one or more hardware processors, the at least one memory coupled to the one or more hardware processors wherein the one or more hardware processors are capable of executing programmed instructions stored in the at least one memory to:

systematically execute at least one thread associated with the application, wherein executing the at least one thread results in invoking one or more methods associated with the at least one thread, wherein the at least one thread is systematically executed upon establishing a monitoring session with a server that runs the application;

periodically capture, during the execution, metrics associated with the one or more methods during the monitoring session, wherein the metrics are generated during systematic execution of the application in runtime environment, wherein the metrics are periodically captured using a default auto-generated standard configuration;

systematically arrange the metrics in a data structure to represent a plurality of thread-method pairs and the metrics corresponding to each of the plurality of thread-method pairs; and

identify, from the data structure, one or more anomalies associated with the one or more methods based on a detection of at least one predetermined condition associated with the metrics in the data structure, wherein an anomaly of the one or more anomalies comprises one of un-exited anomaly and exception anomaly and a user-defined anomaly.

8. The system of claim 7 , wherein the metrics associated with the one or more methods comprises method name, method invocation timestamp, method exit timestamp, method stack-trace, exception name, exception cause, and exception timestamp.

9. The system of claim 7 , wherein the at least one processor is capable of executing programmed instructions to identify the un-exited anomaly in the one or more methods comprises detecting absence of the method exit timestamp in the metrics associated with the one or more methods.

10. The system of claim 7 , wherein at least one processor is capable of executing programmed instructions to identify the exception anomaly in the one or more methods comprises detecting exception name, exception cause, and exception timestamp in the metrics associated with the one or more methods.

11. The system of claim 7 , wherein the at least one predetermined condition is defined by a user to identify the user-defined anomaly in the method.

12. The system of claim 7 , wherein the application is a distributed application having multiple layers, the multiple layers comprising one or more of at least one web interface, at least one database component and at least one application interface.

13. A non-transitory computer-readable medium having embodied thereon a computer program for executing a method for anomaly detection, the method comprising:

systematically executing at least one thread associated with the application, wherein executing the at least one thread results in invoking one or more methods associated with the at least one thread, wherein the at least one thread is systematically executed upon establishing a monitoring session with a server that runs the application;

periodically capturing, during the execution, metrics associated with the one or more methods during the monitoring session, wherein the metrics are generated during systematic execution of the application in runtime environment, wherein the metrics are periodically captured using a default auto-generated standard configuration;

systematically arranging the metrics in a data structure to represent a plurality of thread-method pairs and the metrics corresponding to each of the plurality of thread-method pairs; and

identifying, from the data structure, one or more anomalies associated with the one or more methods based on a detection of at least one predetermined condition associated with the metrics in the data structure, wherein an anomaly of the one or more anomalies comprises one of unexited anomaly, an exception anomaly and a user-defined anomaly.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 17, 2016
From: ILANGOVAN, RAMKUMAR; DAS, SAYANTAN; KUNDU, SHOUNAK; CHATTERJEE, SWARUP
To: TATA CONSULTANCY SERVICES LIMITED
Reel/Frame 039469/0378 →
Priority Claims (1)
IN 201621009340 · Mar 17, 2016 · national
Continuity (1)
Related Publication 20170270038A1 · Sep 21, 2017