IP Library › Granted Patent US 12,332,762
Granted Patent B2
US 12,332,762 · App. 18/598,448 · Granted Jun 17, 2025

Machine learning models for automated anomaly detection for application infrastructure components

Inventors: Michael D. Trapani (Victor, NY); Jeevan Kumar Goud Bandharapu (Lodi, NJ)
Assignee: Express Scripts Strategic Development, Inc.
G06F11/3409G06F11/0793G06F11/302G06F11/3055G06F11/3457G06F17/18G06N20/00H04L41/145H04L41/16H04L43/045H04L43/08H04L43/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,332,762
App. No.
18/598,448
Granted
Jun 17, 2025
Kind
B2
Abstract

A system for automated detection of anomalous performance of application infrastructure components includes memory hardware and processor hardware communicatively coupled together. The processor hardware is configured to train the at least one machine learning model using measured historical performance metrics of a first component of the application infrastructure components. The processor hardware is configured to use the at least one machine learning model to generate key performance indicators for the first component, based on a reporting window time period associated with measured performance metrics. The processor hardware is configured to, in response to the key performance indicators indicating a performance anomaly condition for the first component, automatically perform a self-healing operation associated with the key performance indicators. The self-healing operation includes automatically modifying operation of the first component, including at least one of restarting the first component, and starting a new instance of the first component.

Claims (87)

1. A computer system for automated detection of anomalous performance of application infrastructure components, the computer system comprising:

memory hardware configured to store at least one machine learning model and measured historical performance metrics for the application infrastructure components; and

processor hardware communicatively coupled to the memory hardware, wherein the processor hardware is configured to:

train the at least one machine learning model using the measured historical performance metrics of a first component of the application infrastructure components;

use the at least one machine learning model to generate key performance indicators for the first component, based on a reporting window time period associated with measured performance metrics; and

in response to the key performance indicators indicating a performance anomaly condition for the first component, automatically perform a self-healing operation associated with the key performance indicators,

wherein the self-healing operation includes automatically modifying operation of the first component, including at least one of:

restarting the first component, and

starting a new instance of the first component;

wherein the self-healing operation includes automatically generating an incident ticket request to monitor the operation of the first component.

2. The computer system of claim 1 , wherein:

the measured historical performance metrics include at least one of a component response time, a component volume, a component memory utilization, and a component processor utilization;

the key performance indicators include at least one of a component health status output and a component health score output;

the component health status output includes at least discrete values for a normal health status and a warning health status;

the warning health status is associated with the performance anomaly condition; and

the processor hardware is further configured to train the at least one machine learning model based on at least one of the component response time, the component volume, the component memory utilization, and the component processor utilization.

3. The computer system of claim 2 , wherein the processor hardware is further configured to:

determine whether health of the first component is consistent with historical behavior during the reporting window time period; and

in response to the health not being consistent with the historical behavior, generate the component health status output indicating the performance anomaly condition.

4. The computer system of claim 1 , wherein:

the processor hardware is further configured to generate a continuous numerical score using a plurality of input variables;

the continuous numerical score indicates an overall health rating for the first component;

the key performance indicators include at least a component health score output; and

the component health score output includes the continuous numerical score.

5. The computer system of claim 1 , wherein:

the processor hardware is further configured to:

evaluate a component group associated with the first component, to determine group-level key performance indicators; and

in response to the group-level key performance indicators indicating one or more performance anomaly conditions for the component group, automatically perform group self-healing operations associated with the group-level key performance indicators, and

the group self-healing operations include at least one of: (i) automatically modifying operation of the component group, and (ii) automatically generating a second ticket request to modify the operation of the component group.

6. The computer system of claim 1 , wherein the processor hardware is further configured to:

determine whether a group warning status has been set for a respective component of a plurality of component groups associated with a component type; and

in response to determining the group warning status has been set for the respective component of the plurality of component groups, automatically set a component type status indicator to a warning status.

7. A non-transitory computer-readable storage medium storing instructions configured to be executed by processor hardware, wherein the instructions include:

training at least one machine learning model using measured historical performance metrics of a first component of application infrastructure components;

using the at least one machine learning model to generate key performance indicators for the first component, based on a reporting window time period associated with measured performance metrics; and

in response to the key performance indicators indicating a performance anomaly condition for the first component, automatically performing a self-healing operation associated with the key performance indicators,

wherein the self-healing operation includes automatically modifying operation of the first component, including at least one of:

restarting the first component, and

starting a new instance of the first component;

wherein the self-healing operation includes automatically generating a ticket request to monitor the operation of the first component.

8. The non-transitory computer-readable storage medium of claim 7 , wherein:

the measured historical performance metrics include at least one of a component response time, a component volume, a component memory utilization, and a component processor utilization;

the key performance indicators include at least one of a component health status output and a component health score output;

the component health status output includes at least discrete values for a normal health status and a warning health status;

the warning health status is associated with the performance anomaly condition; and

the instructions further include training the at least one machine learning model based on at least one of the component response time, the component volume, the component memory utilization, and the component processor utilization.

9. The non-transitory computer-readable storage medium of claim 8 , wherein the instructions further include:

determining whether health of the first component is consistent with historical behavior during the reporting window time period; and

in response to the health not being consistent with the historical behavior, generating the component health status output indicating the performance anomaly condition.

10. The non-transitory computer-readable storage medium of claim 7 , wherein:

the instructions further include generating a continuous numerical score using a plurality of input variables;

the continuous numerical score indicates an overall health rating for the first component;

the key performance indicators include at least a component health score output; and

the component health score output includes the continuous numerical score.

11. The non-transitory computer-readable storage medium of claim 7 , wherein:

the instructions further include:

evaluating a component group associated with the first component, to determine group-level key performance indicators; and

in response to the group-level key performance indicators indicating one or more performance anomaly conditions for the component group, automatically performing group self-healing operations associated with the group-level key performance indicators, and

the group self-healing operations include at least one of: (i) automatically modifying operation of the component group, and (ii) automatically generating a second ticket request to modify the operation of the component group.

12. The non-transitory computer-readable storage medium of claim 7 , wherein the instructions further include:

determining whether a group warning status has been set for a respective component of a plurality of component groups associated with a component type; and

in response to determining the group warning status has been set for the respective component of the plurality of component groups, automatically setting a component type status indicator to a warning status.

13. A method for automated detection of anomalous performance of application infrastructure components, the method comprising:

training at least one machine learning model using measured historical performance metrics of a first component of the application infrastructure components;

using the at least one machine learning model to generate key performance indicators for the first component, based on a reporting window time period associated with measured performance metrics; and

in response to the key performance indicators indicating a performance anomaly condition for the first component, automatically performing a self-healing operation associated with the key performance indicators,

wherein the self-healing operation includes automatically modifying operation of the first component, including at least one of:

restarting the first component, and

starting a new instance of the first component;

wherein the self-healing operation includes automatically generating a ticket request to monitor the operation of the first component.

14. The method of claim 13 , wherein:

the measured historical performance metrics include at least one of a component response time, a component volume, a component memory utilization, and a component processor utilization;

the key performance indicators include at least one of a component health status output and a component health score output;

the component health status output includes at least discrete values for a normal health status and a warning health status;

the warning health status is associated with the performance anomaly condition; and

the method further comprising training the at least one machine learning model based on at least one of the component response time, the component volume, the component memory utilization, and the component processor utilization.

15. The method of claim 14 , further comprising:

determining whether health of the first component is consistent with historical behavior during the reporting window time period; and

in response to the health not being consistent with the historical behavior, generating the component health status output indicating the performance anomaly condition.

16. The method of claim 13 , further comprising generating a continuous numerical score using a plurality of input variables, wherein:

the continuous numerical score indicates an overall health rating for the first component;

the key performance indicators include at least a component health score output; and

the component health score output includes the continuous numerical score.

17. The method of claim 13 , further comprising:

evaluating a component group associated with the first component, to determine group-level key performance indicators; and

in response to the group-level key performance indicators indicating one or more performance anomaly conditions for the component group, automatically performing group self-healing operations associated with the group-level key performance indicators,

wherein the group self-healing operations include at least one of: (i) automatically modifying operation of the component group, and (ii) automatically generating a second ticket request to modify the operation of the component group.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 7, 2024
From: TRAPANI, MICHAEL D.; BANDHARAPU, JEEVAN KUMAR GOUD
To: EXPRESS SCRIPTS STRATEGIC DEVELOPMENT, INC.
Reel/Frame 066684/0956 →
Continuity (3)
Continuation 17888104 · Aug 15, 2022
Continuation 17126250 · Dec 18, 2020
Related Publication 20240211369A1 · Jun 27, 2024
References Cited (23)
US 9534928B2 · Taft · 2017 [cited by examiner]
US 9886338B1 · Khokhar · 2018 [cited by applicant]
US 10193741B2 · Zafer · 2019 [cited by applicant]
US 10200267B2 · Zafer · 2019 [cited by applicant]
US 10635565B2 · Dang · 2020 [cited by applicant]
US 10917419B2 · Crotinger · 2021 [cited by applicant]
US 11277420B2 · Côté et al. · 2022 [cited by applicant]
US 20070266149A1 · Cobb · 2007 [cited by applicant]
US 20130282710A1 · Raghavan · 2013 [cited by applicant]
US 20170017760A1 · Freese · 2017 [cited by applicant]
US 20170134237A1 · Yang · 2017 [cited by examiner]
US 20190042981A1 · Bendfeldt · 2019 [cited by applicant]
US 20190044825A1 · Vijayakumar · 2019 [cited by applicant]
US 20190095478A1 · Tankersley · 2019 [cited by applicant]
US 20190260794A1 · Woodford · 2019 [cited by applicant]
US 20190394283A1 · Morrison · 2019 [cited by applicant]
US 20200104774A1 · Sun · 2020 [cited by applicant]
US 20200117739A1 · Bulut · 2020 [cited by applicant]
US 20200174867A1 · Mo · 2020 [cited by applicant]
US 20200387833A1 · Kursun · 2020 [cited by applicant]
US 20210360077A1 · Bandari · 2021 [cited by applicant]
US 20220038348A1 · Mayor · 2022 [cited by examiner]
CN 106953747A · 2017 [cited by applicant]