IP Library Granted Patent US 11,657,063
Granted Patent B2
US 11,657,063 · App. 15/476,694 · Granted May 23, 2023

Behavioral analytics in information technology infrasturcture incident management systems

Inventors: Raul Pavon (Houston, TX); Beth Carpenter (Houston, TX); Gwendolyn Curlee (Houston, TX)
Assignee: BMC Software, Inc.
G06F16/258G06F16/2462G06F16/36G06F40/205H04L41/142
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,657,063
App. No.
15/476,694
Granted
May 23, 2023
Kind
B2
Abstract

A computer system for behavioral analytics of native Information Technology Service Management (ITSM) incident handling data includes a processor, a memory, a de-normalized target data source for behavioral analysis, a transformation processor, and a statistical processor. The transformation processor reads an identified portion of the ITSM data and creates new normalized fields for the de-normalized target data source by parsing selected text fields from the portion of ITSM data. The created new normalized fields include a working group field and an associated support level field. The transformation processor further creates new de-normalized aggregation fields for the incipient de-normalized target data source based on the newly created normalized fields. The newly created de-normalized aggregation fields include fields characterizing incident handling behavior. A statistical processor further processes target data for behavioral analytics. The transformation processor populates the target data source's de-normalized data fields with aggregated incident handling data and behavioral characterizations.

Claims (65)

1. A method for identifying aggregated wasted time across a plurality of incidents handled by a plurality of incident handlers in Information Technology (IT) incident handling, the method comprising:

identifying a volume of native IT Service Management (ITSM) data, the ITSM data including incident activity entries characterizing the IT incident handling for each incident of the plurality of incidents and each corresponding incident handler of the plurality of incident handlers;

creating a target data set that is reduced in size from the volume of native ITSM data, including adding at least one field for aggregated wasted time to the target data set, and including, for each incident of the plurality of incidents:

identifying time periods occurring between pairs of the incident activity entries, wherein each time period of the time periods is stored together with a plurality of incident activity characterizations, the plurality of incident activity characterizations including at least one status;

dividing at least one time period of the plurality of time periods into a first time division and a second time division, and aggregating, based on the at least one status, at least two time periods of the time periods into at least a first aggregated time period that includes the first time division, and a second aggregated time period that includes the second time division and a portion of the second time period;

classifying the first aggregated time period as wasted time;

classifying the second aggregated time period as work time or wait time;

adding the first aggregated time period to the at least one field for the aggregated wasted time to the target data set; and

providing the target data set to remote applications and systems via a web service client interface, including providing access to the at least one field for the aggregated wasted time across the plurality of incidents and the plurality of incident handlers.

2. The method of claim 1 , wherein the plurality of incident activity characterizations each include at least one of a priority, an activity status, an assigned group, and assigned individual, and an assigned group costing category.

3. The method of claim 1 , wherein aggregating the at least two time periods includes selecting the at least two time periods for aggregation based on the corresponding incident activity characterizations of the at least two time periods.

4. The method of claim 1 , wherein classifying the first aggregated time period as wasted time comprises:

classifying the second time division as work time or wait time;

classifying the portion of the second time period as work time or wait time;

classifying the second aggregated time period as total work time or total wait time;

classifying a remaining portion of the second time period as wasted time; and

aggregating the first time division and the remaining portion of the second time period to determine the wasted time.

5. The method of claim 4 , further comprising:

classifying the second aggregated time period as acceptable work time or acceptable wait time.

6. The method of claim 1 , wherein classifying the first aggregated time period as wasted time comprises:

classifying the first aggregated time period as wasted time based on a combination of a first incident activity characterization and a second incident activity characterization of the at least two time periods.

7. A computer system for identifying aggregated wasted time across a plurality of incidents handled by a plurality of incident handlers in Information Technology (IT) incident handling, the computer system comprising:

a memory; and

a transformation processor coupled to a statistical processor, the transformation processor in conjunction with the statistical processor configured to:

identify a volume of native IT Service Management (ITSM) data, the ITSM data including incident activity entries characterizing the IT incident handling for each incident of the plurality of incidents and each corresponding incident handler of the plurality of incident handlers;

create a target data set that is reduced in size from the volume of native ITSM data, including adding at least one field for aggregated wasted time to the target data set, and including, for each incident of the plurality of incidents:

identify time periods occurring between pairs of the incident activity entries, wherein each time period of the time periods is stored together with a plurality of incident activity characterizations, the plurality of incident activity characterizations including at least one status;

divide at least one time period of the plurality of time periods into a first time division and a second time division, and aggregating, based on the at least one status, at least two time periods of the time periods into at least a first aggregated time period that includes the first time division, and a second aggregated time period that includes the second time division and a portion of the second time period;

classify the first aggregated time period as wasted time;

classify the second aggregated time period as work time or wait time;

add the first aggregated time period to the at least one field for the aggregated wasted time to the target data set; and

provide the target data set to remote applications and systems via a web service client interface, including providing access to the at least one field for the aggregated wasted time across the plurality of incidents and the plurality of incident handlers.

8. The computer system of claim 7 , wherein the plurality of incident activity characterizations each include at least one of a priority, an activity status, an assigned group, and assigned individual, and an assigned group costing category.

9. The computer system of claim 7 , wherein aggregating the at least two time periods includes selecting the at least two time periods for aggregation based on the corresponding incident activity characterizations of the at least two time periods.

10. The computer system of claim 7 , wherein classifying the first aggregated time period as wasted time comprises:

classifying the second time division as work time or wait time;

classifying the portion of the second time period as work time or wait time;

classifying the second aggregated time period as total work time or total wait time;

classifying a remaining portion of the second time period as wasted time; and

aggregating the first time division and the remaining portion of the second time period to determine the wasted time.

11. The computer system of claim 10 , further comprising:

classifying the second aggregated time period as acceptable work time or acceptable wait time.

12. The computer system of claim 7 , wherein classifying the first aggregated time period as wasted time comprises:

classifying the first aggregated time period as wasted time based on a combination of a first incident activity characterization and a second incident activity characterization of the at least two time periods.

13. A computer program product for identifying aggregated wasted time across a plurality of incidents handled by a plurality of incident handlers in Information Technology (IT) incident handling, including instructions recorded on a non-transitory computer-readable storage medium and configured to cause at least one processor to:

identify a volume of native IT Service Management (ITSM) data, the ITSM data including incident activity entries characterizing the IT incident handling for each incident of the plurality of incidents and each corresponding incident handler of the plurality of incident handlers;

create a target data set that is reduced in size from the volume of native ITSM data, including adding at least one field for aggregated wasted time to the target data set, and including, for each incident of the plurality of incidents:

identify time periods occurring between pairs of the incident activity entries, wherein each time period of the time periods is stored together with a plurality of incident activity characterizations, the plurality of incident activity characterizations including at least one status;

divide at least one time period of the plurality of time periods into a first time division and a second time division, and aggregating, based on the at least one status, at least two time periods of the time periods into at least a first aggregated time period that includes the first time division, and a second aggregated time period that includes the second time division and a portion of the second time period;

classify the first aggregated time period as wasted time;

classify the second aggregated time period as work time or wait time;

add the first aggregated time period to the at least one field for the aggregated wasted time to the target data set; and

provide the target data set to remote applications and systems via a web service client interface, including providing access to the at least one field for the aggregated wasted time across the plurality of incidents and the plurality of incident handlers.

14. The computer program product of claim 13 , wherein the plurality of incident activity characterizations each include includes at least one of a priority, an activity status, an assigned group, and assigned individual, and an assigned group costing category.

15. The computer program product of claim 13 , wherein aggregating the at least two time periods includes selecting the at least two time periods for aggregation based on the corresponding incident activity characterizations of the at least two time periods.

16. The computer program product of claim 13 , wherein classifying the first aggregated time period as wasted time comprises:

classifying the second time division as work time or wait time;

classifying the portion of the second time period as work time or wait time;

classifying the second aggregated time period as total work time or total wait time;

classifying a remaining portion of the second time period as wasted time; and

aggregating the first time division and the remaining portion of the second time period to determine the wasted time.

17. The computer program product of claim 16 , further comprising:

classifying the second aggregated time period as acceptable work time or acceptable wait time.

18. The computer program product of claim 13 , wherein classifying the first aggregated time period as wasted time comprises:

classifying the first aggregated time period as wasted time based on a combination of a first incident activity characterization and a second incident activity characterization of the at least two time periods.

Assignments (14)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 7, 2025
From: BMC SOFTWARE, INC.
To: BMC HELIX, INC.
Reel/Frame 070442/0197 →
GRANT OF FIRST LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 13, 2024
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 069352/0628 →
GRANT OF SECOND LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 13, 2024
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 069352/0568 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052854/0139) Recorded Aug 6, 2024
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 068339/0617 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052844/0646) Recorded Aug 6, 2024
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 068339/0408 →
OMNIBUS ASSIGNMENT OF SECURITY INTERESTS IN PATENT COLLATERAL Recorded Mar 4, 2024
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS RESIGNING COLLATERAL AGENT
To: GOLDMAN SACHS BANK USA, AS SUCCESSOR COLLATERAL AGENT
Reel/Frame 066729/0889 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 1, 2024
From: ALTER DOMUS (US) LLC
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 066567/0283 →
GRANT OF SECOND LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Sep 30, 2021
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 057683/0582 →
SECURITY INTEREST Recorded Jun 4, 2020
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052854/0139 →
SECURITY INTEREST Recorded Jun 4, 2020
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052844/0646 →
RELEASE OF PATENTS Recorded Oct 5, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.; BMC ACQUISITION L.L.C.
Reel/Frame 047198/0468 →
SECURITY INTEREST Recorded Oct 2, 2018
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047185/0744 →
SECURITY INTEREST Recorded Aug 10, 2017
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 043514/0845 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2017
From: PAVON, RAUL; CARPENTER, BETH; CURLEE, GWENDOLYN
To: BMC SOFTWARE, INC.
Reel/Frame 042603/0738 →
Continuity (1)
Related Publication 20180285433A1 · Oct 4, 2018