IP Library › Granted Patent US 11,012,289
Granted Patent B2
US 11,012,289 · App. 16/507,899 · Granted May 18, 2021

Reinforced machine learning tool for anomaly detection

Inventors: Amarendu Singh (Mirzapur, IN); Venkatesh Iyengar (Bangalore, IN); Abhradeep Kundu (Chandannagar, IN); Harish Kumar Sampangi Rama (Bangalore, IN); Sudhakar Bommenahalli Ramamurthy (Bangalore, IN)
Assignee: SAP SE
H04L41/064G06K9/628G06K9/6223G06N3/0454G06N20/00H04L67/025
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,012,289
App. No.
16/507,899
Granted
May 18, 2021
Kind
B2
Abstract

In some embodiments, there may be provided a system. The system may be configured to receive web server data indicating a current state of a web server; determine, by a machine learning model and based on the web server data, whether the web server is in a first failure state; generate a first failure state indication for the web server in response to the determination, by the machine learning model, that the web server is in the first failure state; determine, by a forecaster and based on the web server data, whether the web server is in a second failure state; and generate a second failure state indication for the web server in response to the determination, by the forecaster, that the web server is in the second failure state.

Claims (42)

1. A system, comprising:

at least one data processor; and

at least one memory storing instructions which, when executed by the at least one data processor, result in operations comprising:

receiving web server data indicating a current state of a web server;

determining, by a machine learning model and based on the web server data, whether the web server is in a first failure state;

generating a first failure state indication for the web server in response to the determining, by the machine learning model, that the web server is in the first failure state;

determining, by a forecaster and based on the web server data, whether the web server is in a second failure state, wherein the forecaster comprises a regression model configured to receive a quantity of connections at the web server and to output an estimate of an amount of available memory at the web server;

generating a second failure state indication for the web server in response to the determining, by the forecaster, that the web server is in the second failure state;

aggregating the first failure state and the second failure state to determine whether the web server is a failure state; and

providing an alert when the aggregating determines the web server is in the failure state.

2. The system of claim 1 , wherein the determining whether the web server is in the first failure state comprises a first prediction of the first failure state; and wherein the determining whether the web server is in the second failure state comprises a second prediction of the first failure state.

3. The system of claim 1 , wherein the failure state comprises a state of the web server, wherein the state comprises the web server being in failure or predicted to fail.

4. The system of claim 1 , wherein the machine learning model comprises a K-means classifier.

5. The system of claim 1 , wherein the machine learning model comprises a neural network, a recurrent neural network, and/or a long short-term memory artificial recurrent neural network.

6. The system of claim 1 , wherein the web server data indicating the current state comprises real-time data.

7. The system of claim 6 , wherein the real-time data includes central processing unit load information for the web server, a quantity of reads at the web server, a quantity of writes at the web server, a quantity of active threads at the web server, a quantity of connections, and/or a current amount of available memory at the web server.

8. The system of claim 1 , wherein when the estimated amount of available memory differs, by a threshold amount, from a current amount of available memory at the web server, the second failure state indication is generated.

9. The system of claim 1 , wherein the aggregating includes filtering and combining, wherein the filtering includes filtering one or more first failure state indications and one or more second failure state indications, and wherein the combining includes combining the filtered one or more first failure state indications and the filtered one or more second failure state indications.

10. The system of claim 1 , wherein the forecaster is trained based on historical information including past information indicating a quantity of connections at the web server and a corresponding available memory at the server.

11. The system of claim 1 , wherein the machine learning model is trained based on historical information including past information indicating a central processing unit load information for the web server, a quantity of reads at the web server, a quantity of writes at the web server, a quantity of active threads at the web server, a quantity of connections, and/or a current amount of available memory at the web server.

12. A method, comprising:

receiving web server data indicating a current state of a web server;

determining, by a machine learning model and based on the web server data, whether the web server is in a first failure state;

generating a first failure state indication for the web server in response to the determining, by the machine learning model, that the web server is in the first failure state;

determining, by a forecaster and based on the web server data, whether the web server is in a second failure state, wherein the forecaster comprises a regression model configured to receive a quantity of connections at the web server and to output an estimate of an amount of available memory at the web server;

generating a second failure state indication for the web server in response to the determining, by the forecaster, that the web server is in the second failure state;

aggregating the first failure state and the second failure state to determine whether the web server is a failure state; and

providing an alert when the aggregating determines the web server is in the failure state.

13. The method of claim 12 , wherein the determining whether the web server is in the first failure state comprises a first prediction of the first failure state; and wherein the determining whether the web server is in the second failure state comprises a second prediction of the first failure state.

14. The method of claim 12 , wherein the failure state comprises a state of the web server, wherein the state comprises the web server being in failure or predicted to fail.

15. The method of claim 12 , wherein the machine learning model comprises a K-means classifier.

16. The method of claim 12 , wherein the machine learning model comprises a neural network, a recurrent neural network, and/or a long short-term memory artificial recurrent neural network.

17. The method of claim 12 , wherein the web server data indicating the current state comprises real-time data.

18. The method of claim 12 , wherein the real-time data includes central processing unit load information for the web server, a quantity of reads at the web server, a quantity of writes at the web server, a quantity of active threads at the web server, a quantity of connections, and/or a current amount of available memory at the web server.

19. A non-transitory computer-readable storage medium including program code, which when executed by at least one data processor, causes operations comprising:

receiving web server data indicating a current state of a web server;

determining, by a machine learning model and based on the web server data, whether the web server is in a first failure state;

generating a first failure state indication for the web server in response to the determining, by the machine learning model, that the web server is in the first failure state;

determining, by a forecaster and based on the web server data, whether the web server is in a second failure state, wherein the forecaster comprises a regression model configured to receive a quantity of connections at the web server and to output an estimate of an amount of available memory at the web server;

generating a second failure state indication for the web server in response to the determining, by the forecaster, that the web server is in the second failure state;

aggregating the first failure state and the second failure state to determine whether the web server is a failure state; and

providing an alert when the aggregating determines the web server is in the failure state.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2019
From: SINGH, AMARENDU; IYENGAR, VENKATESH; KUNDU, ABHRADEEP; SAMPANGI RAMA, HARISH KUMAR; RAMAMURTHY, SUDHAKAR BOMMENAHALLI
To: SAP SE
Reel/Frame 049717/0773 →
Continuity (1)
Related Publication 20210014102A1 · Jan 14, 2021