IP Library › Granted Patent US 11,556,815
Granted Patent B1
US 11,556,815 · App. 16/824,175 · Granted Jan 17, 2023

Systems and methods for using machine learning for managing application incidents

Inventors: Jennifer Ann Stave (Minneapolis, MN); Jiaju Liu (Phoenix, AZ); Saara Raja (Waxhaw, NC)
Assignee: Wells Fargo Bank, N.A.
G06N5/04G06F16/2456G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,556,815
App. No.
16/824,175
Granted
Jan 17, 2023
Kind
B1
Abstract

Disclosed herein are systems and methods for using machine learning for managing application incidents. An embodiment takes the form of a method that includes receiving extracted data pertaining to one or more applications, Model-input data is generated from the extracted data. Model-output data is generated at least in part by processing the generated model-input data with one or more machine-learning models trained to make one or more application-incident predictions. Based at least in part on the model-output data, an application-incident-likely determination is made that a likelihood of an occurrence of an application incident exceeds an application-incident-likelihood threshold, where the application incident corresponds to a given application of the one or more applications. Responsive to making the application-incident-likely determination, one or more alerts of the likelihood of the occurrence of the application incident are output.

Claims (63)

1. A method comprising:

receiving extracted data pertaining to one or more applications;

generating model-input data from the extracted data;

generating model-output data at least in part by processing the generated model-input data with a plurality of machine-learning models each independently trained to make one or more application-incident predictions, wherein the plurality of machine-learning models comprises a plurality of incident-type-specific machine-learning models comprising:

a first machine-learning model that is trained to make application-incident predictions with respect to a first type of application incident; and

a second machine-learning model that is trained to make application-incident predictions with respect to a second type of application incident,

the first type of application incident and the second type of application incident being different from one another;

making, based at least in part on the model-output data, an application-incident-likely determination that a likelihood of an occurrence of an application incident exceeds an application-incident-likelihood threshold, the application incident corresponding to a given application of the one or more applications; and

responsive to making the application-incident-likely determination, outputting one or more alerts of the likelihood of the occurrence of the application incident.

2. The method of claim 1 , wherein:

the model-input data is structured according to a set of one or more features;

generating the model-input data from the extracted data comprises transforming at least a portion of the extracted data into being structured according to the set of one or more features; and

processing the generated model-input data with the one or more machine-learning models comprises processing the set of one or more features with the one or more machine-learning models.

3. The method of claim 2 , wherein:

receiving the extracted data comprises receiving the extracted data as a plurality of datasets respectively extracted from a plurality of different data stores; and

transforming at least a portion of the extracted data into being structured according to the set of one or more features comprises one or more of:

conducting at least one normalization function with respect to the at east a portion of the extracted data;

conducting at east one join operation with respect to the at least a portion of the extracted data;

conducting at east one metric calculation with respect to the at least a portion of the extracted data; and

conducting at least one data-quality check with respect to the at least a portion of the extracted data.

4. The method of claim 1 , wherein:

a data-shaping platform generates the model-input data from the extracted data;

a machine-learning platform generates the model-output data at least in part by processing the generated model-input data with the plurality of machine-learning models; and

the method further comprises conveying the model-input data from the data-shaping platform to the machine-learning platform using data-movement software.

5. The method of claim 1 , wherein the plurality of machine-learning models comprises one or more gradient boosting machine (GBM) models.

6. The method of claim 1 , wherein the first type of application incident comprises an application-patching-related incident.

7. The method of claim 1 , wherein the first type of application incident comprises an application-access-related incident.

8. The method of claim 1 , wherein the first type of application incident comprises an application-configuration-related incident.

9. The method of claim 1 , wherein the first type of application incident comprises an application-server-relationship-related incident.

10. The method of claim 1 , wherein the plurality of machine-learning models further comprises:

a third machine-learning model that is trained to make application-incident predictions with respect to a first application of the one or more applications; and

a fourth machine-learning model that is trained to make application-incident predictions with respect to a second application of the one or more applications,

the first application and the second application being different from one another.

11. The method of claim 1 , wherein the application-incident-likely determination is that the likelihood of an occurrence of an application incident within a predetermined amount of time exceeds the application-incident-likelihood threshold.

12. The method of claim 1 , wherein:

the model-output data indicates the likelihood of the occurrence of the application incident; and

making the application-incident-likely determination based at least in part on the model-output data comprises comparing the indicated likelihood to the application-incident-likelihood threshold.

13. The method of claim 1 , wherein:

the model-output data comprises an indication that the likelihood of the occurrence of the application incident exceeds the application-incident-likelihood threshold; and

making the application-incident-likely determination based at least in part on the model-output data comprises making the application-incident-likely determination based at least in part on the indication.

14. The method of claim 1 , further comprising presenting the one or more alerts via one or more user interfaces.

15. The method of claim 1 , wherein outputting one or more alerts comprises outputting the one or more alerts to one or more of data storage, a computing device, and a networked server.

16. The method of claim 1 , further comprising outputting the model-output data to an administrative interface.

17. A system comprising:

at least one processor; and

one or more non-transitory computer readable storage media containing instructions executable by the at least one processor for causing the at least one processor to perform operations comprising:

receiving extracted data pertaining to one or more applications;

generating model-input data from the extracted data;

generating model-output data at least in part by processing the generated model-input data with a plurality of machine-learning models each independently trained to make one or more application-incident predictions wherein the plurality of machine-learning models comprises a plurality of incident-type-specific machine-learning models comprising:

a first machine-learning model that is trained to make application-incident predictions with respect to a first type of application incident; and

a second machine-learning model that is trained to make application-incident predictions with respect to a second type of application incident,

the first type of application incident and the second type of application incident being different from one another;

making, based at least in part on the model-output data, an application-incident-likely determination that a likelihood of an occurrence of an application incident exceeds an application-incident-likelihood threshold, the application incident corresponding to a given application of the one or more applications; and

responsive to making the application-incident-likely determination, outputting one or more alerts of the likelihood of the occurrence of the application incident.

18. One or more non-transitory computer readable storage media containing instructions executable by at least one processor for causing the at least one processor to perform operations comprising:

receiving extracted data pertaining to one or more applications;

generating model-input data from the extracted data;

generating model-output data at least in part by processing the generated model-input data with a plurality of machine-learning models each independently trained to make one or more application-incident predictions, wherein the plurality of machine-learning models comprises a plurality of incident-type-specific machine-learning models comprising:

a first machine-learning model that is trained to make application-incident predictions with respect to a first type of application incident; and

a second machine-learning model that is trained to make application-incident predictions with respect to a second type of application incident,

the first type of application incident and the second type of application incident being different from one another:

making, based at least in part on the model-output data, an application-incident-likely determination that a likelihood of an occurrence of an application incident exceeds an application-incident-likelihood threshold, the application incident corresponding to a given application of the one or more applications; and

responsive to making the application-incident-likely determination, outputting one or more alerts of the likelihood of the occurrence of the application incident.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2020
From: STAVE, JENNIFER ANN; LIU, JIAJU; RAJA, SAARA
To: WELLS FARGO BANK, N.A.
Reel/Frame 052326/0935 →
Cited By (4)
US 12,536,452 US 12,619,918 US 12,659,342 US 12,737,281