IP Library › Granted Patent US 10,705,940
Granted Patent B2
US 10,705,940 · App. 16/145,536 · Granted Jul 7, 2020

System operational analytics using normalized likelihood scores

Inventors: Shiri Gaber (Beer Sheva, IL); Ohad Arnon (Beir Nir, IL)
Assignee: EMC IP Holding Company LLC
G06F11/3452G06F11/3419G06F11/3476G06N20/00G06F2201/88
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,705,940
App. No.
16/145,536
Filed
Sep 28, 2018
Granted
Jul 7, 2020
Kind
B2
Art Unit
2114
USPC
714/45
Abstract

Techniques are provided for system operational analytics using normalized likelihood scores. In one embodiment, an exemplary method comprises: obtaining data from data sources associated with a monitored system; applying at least one function to the log data to obtain a plurality of time-series counters for a plurality of distinct features within the data; processing the plurality of time-series counters using at least one machine learning model to obtain a plurality of log likelihood values representing a behavior of the monitored system over time; determining a z-score for each of the plurality of log likelihood values over a predefined short-term time window; monitoring a distribution of the z-scores for the plurality of log likelihood values over a predefined long-term time window to map the z-scores to percentile values; and mapping the percentile values to a health score for the monitored system based on predefined percentile ranges and/or a transformation function.

Claims (40)

1. A method, comprising:

obtaining data from one or more data sources associated with a monitored system;

applying at least one function to the data to obtain a plurality of time-series counters for a plurality of distinct features within the data;

processing, using at least one processing device, the plurality of time-series counters using at least one machine learning model to obtain a plurality of log likelihood values representing a behavior of the monitored system over time;

determining, using the at least one processing device, a z-score for each of the plurality of log likelihood values over a predefined short-term time window;

monitoring, using the at least one processing device, a distribution of the z-scores for the plurality of log likelihood values over a predefined long-term time window to map the z-scores to percentile values; and

mapping, using the at least one processing device, the percentile values to a health score for the monitored system based on one or more of predefined percentile ranges and at least one transformation function.

2. The method of claim 1 , wherein the plurality of log likelihood values represents a probability of a specific behavior to occur out of a probability distribution behavior of the monitored system.

3. The method of claim 1 , wherein the z-scores for the plurality of log likelihood values over the predefined short-term time window determine a distance of a given log likelihood value from a mean of the plurality of log likelihood values divided by a standard deviation of the plurality of log likelihood values.

4. The method of claim 1 , wherein the z-scores for the plurality of log likelihood values over the predefined short-term time window determine a distance of a given log likelihood value from a median of the plurality of log likelihood values.

5. The method of claim 1 , wherein the z-scores for the plurality of log likelihood values over the predefined short-term time window evaluate a deviation of a given log likelihood value from a learned normal behavior of the monitored system during the predefined short-term time window.

6. The method of claim 1 , wherein the step of mapping the percentile values to the health score for the monitored system further comprises sorting the z-scores for the plurality of log likelihood values and selecting a percentage of the z-scores as corresponding to anomalous behavior based on the predefined percentile ranges.

7. The method of claim 1 , wherein one or more of the predefined short-term time window, the predefined long-term time window, and the predefined percentile ranges comprise one or more of a configured value, a policy-based value, and a default value.

8. A system, comprising:

a memory; and

at least one processing device, coupled to the memory, operative to implement the following steps:

obtaining data from one or more data sources associated with a monitored system;

applying at least one function to the data to obtain a plurality of time-series counters for a plurality of distinct features within the data;

processing the plurality of time-series counters using at least one machine learning model to obtain a plurality of log likelihood values representing a behavior of the monitored system over time;

determining a z-score for each of the plurality of log likelihood values over a predefined short-term time window;

monitoring a distribution of the z-scores for the plurality of log likelihood values over a predefined long-term time window to map the z-scores to percentile values; and

mapping the percentile values to a health score for the monitored system based on one or more of predefined percentile ranges and at least one transformation function.

9. The system of claim 8 , wherein the plurality of log likelihood values represents a probability of a specific behavior to occur out of a probability distribution behavior of the monitored system.

10. The system of claim 8 , wherein the z-scores for the plurality of log likelihood values over the predefined short-term time window determine a distance of a given log likelihood value from a mean of the plurality of log likelihood values divided by a standard deviation of the plurality of log likelihood values.

11. The system of claim 8 , wherein the z-scores for the plurality of log likelihood values over the predefined short-term time window determine a distance of a given log likelihood value from a median of the plurality of log likelihood values.

12. The system of claim 8 , wherein the z-scores for the plurality of log likelihood values over the predefined short-term time window evaluate a deviation of a given log likelihood value from a learned normal behavior of the monitored system during the predefined short-term time window.

13. The system of claim 8 , wherein the step of mapping the percentile values to the health score for the monitored system further comprises sorting the z-scores for the plurality of log likelihood values and selecting a percentage of the z-scores as corresponding to anomalous behavior based on the predefined percentile ranges.

14. The system of claim 8 , wherein one or more of the predefined short-term time window, the predefined long-term time window, and the predefined percentile ranges comprise one or more of a configured value, a policy-based value, and a default value.

15. A computer program product, comprising a non-transitory machine-readable storage medium having encoded therein executable code of one or more software programs, wherein the one or more software programs when executed by at least one processing device perform the following steps:

obtaining data from one or more data sources associated with a monitored system;

applying at least one function to the data to obtain a plurality of time-series counters for a plurality of distinct features within the data;

processing the plurality of time-series counters using at least one machine learning model to obtain a plurality of log likelihood values representing a behavior of the monitored system over time;

determining a z-score for each of the plurality of log likelihood values over a predefined short-term time window;

monitoring a distribution of the z-scores for the plurality of log likelihood values over a predefined long-term time window to map the z-scores to percentile values; and

mapping the percentile values to a health score for the monitored system based on one or more of predefined percentile ranges and at least one transformation function.

16. The computer program product of claim 15 , wherein the plurality of log likelihood values represents a probability of a specific behavior to occur out of a probability distribution behavior of the monitored system.

17. The computer program product of claim 15 , wherein the z-scores for the plurality of log likelihood values over the predefined short-term time window determine a distance of a given log likelihood value from a mean of the plurality of log likelihood values divided by a standard deviation of the plurality of log likelihood values.

18. The computer program product of claim 15 , wherein the z-scores for the plurality of log likelihood values over the predefined short-term time window determine a distance of a given log likelihood value from a median of the plurality of log likelihood values.

19. The computer program product of claim 15 , wherein the z-scores for the plurality of log likelihood values over the predefined short-term time window evaluate a deviation of a given log likelihood value from a learned normal behavior of the monitored system during the predefined short-term time window.

20. The computer program product of claim 15 , wherein the step of mapping the percentile values to the health score for the monitored system further comprises sorting the z-scores for the plurality of log likelihood values and selecting a percentage of the z-scores as corresponding to anomalous behavior based on the predefined percentile ranges.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2018
From: GABER, SHIRI; ARNON, OHAD
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 047003/0952 →
Continuity (1)
Related Publication 20200104233A1 · Apr 2, 2020