IP Library Granted Patent US 9,582,344
Granted Patent B2
US 9,582,344 · App. 14/604,830 · Granted Feb 28, 2017

Predicting anomalies and incidents in a computer application

Inventors: Wei Ye Chen (Beijing, CN); Juhnyoung Lee (Yorktown Heights, NY); Feng Li (Beijing, CN); Qi Cheng Li (Beijing, CN); Shao Chun Li (Beijing, CN); Rong Liu (Beijing, CN); Li Jun Mei (Beijing, CN); Wei Sun (Beijing, CN)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F11/0706G06F11/008G06F11/34G06F11/3452G06F11/3466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,582,344
App. No.
14/604,830
Granted
Feb 28, 2017
Kind
B2
Abstract

A method for predicting anomalies in a computer application includes during runtime of the computer application, detecting traffic metrics and incident tickets associated with the computer application, the incident ticket indicating an incident might occur in the computer application; calculating a threshold based on absolute values of second order differences associated with the traffic metrics, wherein the threshold is such that when the absolute value of the second order difference associated with the traffic metrics exceeds the threshold, a recall rate R recall that the computer application is recalled is maximized; obtaining predicted metrics of the computer application in a next time period based on the traffic metrics; and in response to an absolute value of a second order difference associated with the predicted metrics exceeding the threshold, predicting potential anomalies of the computer application in the next time period.

Claims (52)

1. An apparatus for predicting anomalies in a computer application, the apparatus comprising a processor configured to execute a plurality of software modules, the modules comprising:

a detecting module configured to, during runtime of the computer application, detect traffic metrics and incident tickets associated with the computer application, the incident ticket indicating an incident might occur in the computer application;

a calculating module configured to calculate a threshold based on absolute values of second order differences associated with the traffic metrics, wherein the threshold is such that when the absolute value of the second order difference associated with the traffic metrics exceeds the threshold, a recall rate R recall that the computer application is recalled is maximized, the recall rate R recall describing a ratio of the number of incident tickets causing the computer application to be recalled to the total number of the incident tickets;

an obtaining module configured to obtain predicted metrics of the computer application in a next time period based on the traffic metrics; and

a predicting module configured to, in response to an absolute value of a second order difference associated with the predicted metrics exceeding the threshold, predict potential anomalies of the computer application in the next time period.

2. The apparatus according to claim 1 , wherein the threshold is such that when the absolute value of the second order difference associated with the traffic metrics exceeds the threshold, a precision rate R precision that the computer application is recalled is maximized, the precision rate R precision describing a ratio of the number of anomalies causing the computer application to be recalled to the number of all anomalies of the computer application.

3. The apparatus according to claim 2 , wherein the calculating module comprises:

an aggregating module configured to aggregate the traffic metrics according to a predetermined time window interval so as to form standard metrics; and

a threshold calculating module configured to calculate the threshold based on absolute values of second order differences associated with the standard metrics.

4. The apparatus according to claim 3 , wherein the traffic metrics comprise at least any one type of: CPU usage rate, memory usage rate, workload, network connection and data transmission rate.

5. The apparatus according to claim 4 , further comprising:

a normalizing module configured to, before calculating the threshold based on the absolute values of the second order differences associated with the standard metrics, normalize the standard metrics with respect to the at least any one type of the traffic metrics.

6. The apparatus according to claim 5 , wherein an absolute of a second order difference associated with the standard metrics in a time window i−1 is calculated based on an equation below: |2x i −x i−1 −x i+1 |, where x i−1 , x i , x i+1 represent standard metrics with respect to three neighboring time windows.

7. The apparatus according to claim 2 , wherein the calculating module comprises:

a F β calculating module configured to calculate

F

β

=

(

1

+

β

2

)

·

R

precision

·

R

recall

β

2

·

R

precision

+

R

recall

,

where β is a weighting factor describing a weight between the recall rate R recall and the precision rate R precision ; and

a setting module configured to set a value maximizing F β as the threshold.

8. The apparatus according to claim 6 , wherein the absolute value of the second order difference associated with the predicted metrics is calculated based on:

aggregating the predicted metrics according to the predetermined time window interval so as to form standard predicted metrics y i+1 with respect to a time window i+1; and

calculating an absolute value of a second order difference associated with the standard predicted metrics y i+1 based on |2x i −x i−1 −y i+1 |.

9. The apparatus according to claim 8 , wherein the predicting module comprises:

a first predicting module configured to, with respect to at least one predetermined type among the types, predict the potential anomalies in response to an absolute value of a second order difference associated with predicted metrics of the at least one predetermined type exceeding the threshold; and

a second predicting module configured to, with respect to at least one part of types among the plurality of types, predict the potential anomalies in response to an absolute value of a second order difference associated with predicted metrics of the at least one part of types exceeding the threshold.

10. An apparatus for predicting incidents in a computer application, comprising a processor configured to execute a plurality of software modules, the modules comprising:

a detecting module configured to, during runtime of the computer application, detect anomalies and incident tickets associated with the computer application;

a building module configured to build an incident prediction model based on the anomalies and the incident tickets, the incident prediction model describing an association rule among the anomalies and the incident tickets;

an anomaly predicting module comprising modules as recited in claim 1 and configured to predict potential anomalies of the computer application in a next time period; and

an incident predicting module configured to predict potential incidents of the computer application in the next time period based on the incident prediction model and the potential anomalies.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2015
From: CHEN, WEI YE; LEE, JUHNYOUNG; LI, FENG; LI, QI CHENG; LI, SHAO CHUN; LIU, RONG; MEI, LI JUN; SUN, WEI
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 034808/0850 →
Priority Claims (1)
CN 2014 1 0041267 · Jan 28, 2014 · national
Continuity (1)
Related Publication 20150212869A1 · Jul 30, 2015