IP Library Granted Patent US 11,113,174
Granted Patent B1
US 11,113,174 · App. 16/833,102 · Granted Sep 7, 2021

Methods and systems that identify dimensions related to anomalies in system components of distributed computer systems using traces, metrics, and component-associated attribute values

Inventors: Dev Nag (Palo Alto, CA); Naira Movses Grigoryan (Yerevan, AM); Arnak Poghosyan (Yerevan, AM); Ashot Nshan Harutyunyan (Yerevan, AM)
Assignee: VMware, Inc.
G06F11/3466G06F11/3006G06F11/3034G06F11/3075
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,113,174
App. No.
16/833,102
Granted
Sep 7, 2021
Kind
B1
Abstract

The current document is directed to methods and systems that employ distributed-computer-system metrics collected by one or more distributed-computer-system metrics-collection services, call traces collected by one or more call-trace services, and attribute values for distributed-computer-system components to identify attribute dimensions related to anomalous behavior of distributed-computer-system components. In a described implementation, nodes correspond to particular types of system components and node instances are individual components of the component type corresponding to a node. Node instances are associated with attribute values and node are associated with attribute-value spaces defined by attribute dimensions. Using attribute values and call traces, attribute dimensions that are likely related to particular anomalous behaviors of distributed-computer-system components are determined by decision-tree-related analyses and are reported to one or more computational entities to facilitate resolution of the anomalous behaviors.

Claims (57)

1. A system that determines relevant attribute dimensions correlated with anomalous operational behaviors of components of a distributed computer system, the system comprising:

one or more processors;

one or more memories; and

computer instructions, stored in one or more of the one or more memories that, when executed by one or more of the one or more processors, control the system to

collect metric data comprising a series of timestamped metric values associated with each metric of multiple metrics, wherein each metric of the multiple metrics is associated with a component or component type of the distributed computer system,

identify components of the distributed computer system which exhibit anomalous operational behaviors using the collected metric data,

access collected call traces from a call-tracing service,

access attribute values for selected components of the distributed computer system,

employ decision-tree-based analyses to determine relevant attribute dimensions of component types that are correlated with the identified components of the distributed computer system which exhibit anomalous operational behaviors, and

transmit the determined relevant attribute dimensions of the component types to a computational entity to facilitate amelioration of the anomalous operational behaviors.

2. The system of claim 1 wherein the selected components of the distributed computer system are selected from among:

a distributed service-oriented application;

service nodes of the distributed service-oriented application;

service instances of the service nodes of the distributed service-oriented application;

servers;

mass-storage devices and appliances; and

networking components.

3. The system of claim 1 wherein the collected call traces each encodes a series of component types related to execution of a requested task or service.

4. The system of claim 3 wherein the collected call traces each encodes a series of service calls to service nodes within a distributed service-oriented application related to a service call made by a remote client to the distributed service-oriented application.

5. The system of claim 1 wherein the attribute values for the selected components of the distributed computer system are points within an attribute-value space, for which attributes are dimensions, that is associated with component types of the selected components of the distributed computer system.

6. The system of claim 5 wherein the attribute values for the selected components of the distributed computer system are collected from one or more of an attribute-value store and call traces that include component types of the identified components of the distributed computer system which exhibit anomalous operational behaviors.

7. The system of claim 6 wherein the decision-tree-based analyses determine the relevant attribute dimensions of the component types in which the attribute values for the selected components of the distributed computer system are localized, rather than distributed across the relevant attribute dimensions of the component types.

8. The system of claim 7 wherein the decision-tree-based analyses determine attributes and attribute values that partition the collected call traces into a subset that contains call traces that include components of the distributed computer system, and only call traces that include components of the distributed computer system which exhibit anomalous operational behaviors, and one or more additional subsets.

9. A method that determines relevant attribute dimensions correlated with anomalous operational behaviors of components of a distributed computer system, the method comprising:

collecting metric data comprising a series of timestamped metric values associated with each metric of multiple metrics, wherein each metric of the multiple metrics is associated with a component or component type of the distributed computer system;

identifying components of the distributed computer system which exhibit anomalous operational behaviors using the collected metric data;

accessing collected call traces from a call-tracing service;

accessing attribute values for selected components of the distributed computer system;

employing decision-tree-based analyses to determine relevant attribute dimensions of component types that are correlated with the identified components of the distributed computer system which exhibit anomalous operational behaviors; and

transmitting the determined relevant attribute dimensions of the component types to a computational entity to facilitate amelioration of the anomalous operational behaviors.

10. The method of claim 9 wherein the selected components of the distributed computer system are selected from among:

a distributed service-oriented application;

service nodes of the distributed service-oriented application;

service instances of the service nodes of the distributed service-oriented application;

servers;

mass-storage devices and appliances; and

networking components.

11. The method of claim 9 wherein the collected call traces each encodes a series of component types related to execution of a requested task or service.

12. The method of claim 11 wherein the collected call traces each encodes a series of service calls to service nodes within a distributed service-oriented application related to a service call made by a remote client to the distributed service-oriented application.

13. The method of claim 9 wherein the attribute values for the selected components of the distributed computer system are points within an attribute-value space, for which attributes are dimensions, that is associated with component types of the selected components of the distributed computer system.

14. The method of claim 9 wherein the attribute values for the selected components of the distributed computer system are collected from one or more of an attribute-value store and call traces that include component types of the identified components of the distributed computer system which exhibit anomalous operational behaviors.

15. The method of claim 14 wherein the decision-tree-based analyses determine the relevant attribute dimensions of the component types in which the attribute values for the selected components of the distributed computer system are localized, rather than distributed across the relevant attribute dimensions of the component types.

16. The method of claim 15 wherein the decision-tree-based analyses determine attributes and attribute values that partition the collected call traces into a subset that contains call traces that include components of the distributed computer system, and only call traces that include components of the distributed computer system which exhibit anomalous operational behaviors, and one or more additional subsets.

17. A physical data-storage device that stores computer instructions that, when executed by one or more processors of a system that includes one or more memories and one or more mass-storage devices, controls the system to determine relevant attribute dimensions correlated with anomalous operational behaviors of components of a distributed computer system by:

collecting metric data comprising a series of timestamped metric values associated with each metric of multiple metrics, wherein each metric of the multiple metrics is associated with a component or component type of the distributed computer system;

identifying components of the distributed computer system which exhibit anomalous operational behaviors using the collected metric data;

accessing collected call traces from a call-tracing service;

accessing attribute values for selected components of the distributed computer system;

employing decision-tree-based analyses to determine relevant attribute dimensions of component types that are correlated with the identified components of the distributed computer system which exhibit anomalous operational behaviors; and

transmitting the determined relevant attribute dimensions of the component types to a computational entity to facilitate amelioration of the anomalous operational behaviors.

18. The physical data-storage device of claim 17 wherein the selected components of the distributed computer system are selected from among:

a distributed service-oriented application;

service nodes of the distributed service-oriented application;

service instances of the service nodes of the distributed service-oriented application;

servers;

mass-storage devices and appliances; and

networking components.

Assignments (2)
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0314 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 27, 2020
From: NAG, DEV; GRIGORYAN, NAIRA MOVSES; POGHOSYAN, ARNAK; HARUTYUNYAN, ASHOT NSHAN
To: VMWARE, INC.
Reel/Frame 052249/0703 →