IP Library Granted Patent US 12,244,469
Granted Patent B2
US 12,244,469 · App. 18/077,568 · Granted Mar 4, 2025

System and method for supervised event monitoring

Inventors: Hagit Grushka (Beer-Sheva, IL); Rachel Lemberg (Herzliya, IL); Yaniv Lavi (Tel Aviv, IL)
Assignee: Microsoft Technology Licensing, LLC
H04L41/16G06F11/3006G06F11/3447G06N20/00H04L41/5009G06F11/0709G06F11/3409G06F2201/81
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,244,469
App. No.
18/077,568
Filed
Dec 8, 2022
Granted
Mar 4, 2025
Kind
B2
Art Unit
2458
USPC
709/224
Abstract

A method, computer program product, and computing system for processing event data associated with a plurality of known operational impact events on a business service and operational data associated with the business service using a supervised machine learning model conditioned on an operational impact parameter associated with the business service. A detection threshold is generated using the supervised machine learning model.

Claims (51)

1. A computer-implemented method, executed on a computing device, comprising:

processing event data associated with a plurality of known operational impact events on a cloud computing service and operational data associated with the cloud computing service using a supervised machine learning model conditioned on an operational impact parameter associated with the cloud computing service, wherein the operational impact parameter is a parameter used for determining a lowest detection threshold to achieve a particular performance metric of the cloud computing service;

generating a detection threshold using the supervised machine learning model;

identifying a gap in coverage of the plurality of known operational impact events by:

identifying uncovered operational data and a plurality of uncovered known operational impact events, wherein the uncovered operational data and the plurality of uncovered known operational impact events are unreported when using the detection threshold;

updating a monitoring configuration associated with a business service based upon, at least in part, the gap in the coverage of the plurality of known operational impact events;

generating an updated detection threshold based upon, at least in part, the gap in the coverage of the plurality of known operational impact events; and

updating the supervised machine learning model with the operational data indicative of an operational impact event associated with the business service on a periodic basis to continually generate the updated detection threshold, wherein updating the supervised machine learning model continually generates the updated detection threshold by modifying the updated detection threshold to filter out noisy operational data associated with the cloud computing service that is not indicative of an operational impact event from detection of future operational impact events.

2. The computer-implemented method of claim 1 , wherein generating the detection threshold using the supervised machine learning model includes:

determining a number of false positive detections; and

generating a plurality of detection thresholds when the number of false positive detections exceeds a false positive detection threshold.

3. The computer-implemented method of claim 1 , further comprising:

determining the coverage of the plurality of known operational impact events using the detection threshold.

4. The computer-implemented method of claim 1 , further comprising:

detecting the operational impact event associated with the business service by determining that the operational data exceeds the detection threshold.

5. The computer-implemented method of claim 4 , wherein detecting the operational impact event includes processing the operational data associated with the business service with the detection threshold to identify operational data indicative of the operational impact event.

6. The computer-implemented method of claim 5 , wherein detecting the operational impact event includes processing the operational data associated with the business service with the detection threshold to identify operational data not indicative of the operational impact event.

7. A computing system comprising:

a processing system comprising a processor; and

a memory storing instructions that, when executed by the processing system, cause the system to perform operations comprising:

processing event data associated with a plurality of known operational impact events on a cloud computing service and operational data associated with the cloud computing service using a supervised machine learning model conditioned on an operational impact parameter associated with the cloud computing service, wherein the operational impact parameter is a parameter used for determining a lowest detection threshold to achieve a particular performance metric of the cloud computing service;

generating a detection threshold using the supervised machine learning model;

identifying a gap in coverage of the plurality of known operational impact events by:

identifying uncovered operational data and a plurality of uncovered known operational impact events, wherein the uncovered operational data and the plurality of uncovered known operational impact events are unreported when using the detection threshold;

updating a monitoring configuration associated with a business service based upon, at least in part, the gap in the coverage of the plurality of known operational impact events;

generating an updated detection threshold based upon, at least in part, the gap in the coverage of the plurality of known operational impact events; and

updating the supervised machine learning model with the operational data indicative of an operational impact event associated with the business service on a periodic basis to continually generate the updated detection threshold, wherein updating the supervised machine learning model continually generates the updated detection threshold by modifying the updated detection threshold to filter out noisy operational data associated with the cloud computing service that is not indicative of an operational impact event from detection of future operational impact events.

8. The computing system of claim 7 , wherein the operations further comprise:

generating the detection threshold using the supervised machine learning model.

9. The computing system of claim 8 , wherein generating the detection threshold by processing event data associated with the plurality of known operational impact events on the business service and operational data associated with the business service using the supervised machine learning model includes:

determining a number of false positive detections; and

generating a plurality of detection thresholds when the number of false positive detections exceeds a false positive detection threshold.

10. The computing system of claim 8 , wherein the operations further comprise:

determining the coverage of the plurality of known operational impact events using the detection threshold.

11. The computing system of claim 7 , wherein detecting the operational impact event includes processing subsequent operational data associated with the cloud computing service with the detection threshold to identify operational data indicative of the operational impact event.

12. The computing system of claim 11 , wherein detecting the operational impact event includes processing the operational data associated with the cloud computing service with the detection threshold to identify operational data not indicative of the operational impact event.

13. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

generating a detection threshold by processing a plurality of event data associated with a plurality of known operational impact events of a cloud computing service, respectively, and service level indicator (SLI) data associated with the cloud computing service using a supervised machine learning model conditioned on an operational impact parameter associated with the cloud computing service, wherein the operational impact parameter is a parameter used for determining a lowest detection threshold to achieve a particular performance metric of the cloud computing service;

identifying a gap in coverage of the plurality of known operational impact events by:

identifying uncovered operational data and a plurality of uncovered known operational impact events, wherein the uncovered operational data and the plurality of uncovered known operational impact events are unreported when using the detection threshold;

updating the SLI data associated with the cloud computing service based upon, at least in part, the gap in the coverage of the plurality of known operational impact events;

generating an updated detection threshold based upon, at least in part, the gap in the coverage of the plurality of known operational impact events;

updating the supervised machine learning model with the SLI data indicative of an operational impact event associated with the cloud computing service on a periodic basis to continually generate the updated detection threshold, wherein updating the supervised machine learning model continually generates the updated detection threshold by modifying the updated detection threshold to filter out noisy operational data associated with the cloud computing service that is not indicative of an operational impact event from detection of future operational impact events; and

detecting the operational impact event by determining that the operational data exceeds the detection threshold.

14. The computer program product of claim 13 , wherein processing the plurality of event data and the SLI data associated with the cloud computing service using the supervised machine learning model includes:

determining a number of false positive detections; and

generating a plurality of detection thresholds when the number of false positive detections exceeds a false positive detection threshold.

15. The computer program product of claim 13 , wherein the operations further comprise:

determining the coverage of the plurality of operational impact events using the detection threshold.

16. The computer program product of claim 13 , wherein detecting the operational impact event includes processing the SLI data associated with the operational impact service with the detection threshold to identify SLI data indicative of the operational impact event.

17. The computer program product of claim 16 , wherein detecting the operational impact event includes processing the SLI data associated with the cloud computing service with the detection threshold to identify SLI data not indicative of the operational impact event.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2022
From: LEMBERG, RACHEL; GRUSHKA, HAGIT; LAVI, YANIV
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 062027/0362 →
Continuity (1)
Related Publication 20240195702A1 · Jun 13, 2024
References Cited (13)
US 10931692B1 · Mota · 2021 [cited by examiner]
US 11582628B2 · Chen · 2023 [cited by examiner]
US 20150067857A1 · Symons · 2015 [cited by examiner]
US 20200005096A1 · Calmon · 2020 [cited by examiner]
US 20210203673A1 · dos Santos · 2021 [cited by examiner]
US 20210337393A1 · Wainer · 2021 [cited by examiner]
US 20220066906A1 · Kumar · 2022 [cited by examiner]
US 20220103592A1 · Semel · 2022 [cited by examiner]
US 20220350317A1 · Tanaka · 2022 [cited by examiner]
US 20220413983A1 · Mathew · 2022 [cited by examiner]
US 20240037224A1 · Norgate · 2024 [cited by examiner]
WO 2022000398A1 · 2022 [cited by applicant]
International Search Report and Written Opinion received for PCT Application No. PCT/US23/036829, Mar. 5, 2024, 16 pages. [cited by applicant]