IP Library › Granted Patent US 11,580,135
Granted Patent B2
US 11,580,135 · App. 17/089,335 · Granted Feb 14, 2023

Anomaly detection for cloud applications

Inventors: Deng Feng Wan (Shanghai, CN); Yangchun Deng (Shanghai, CN); Hui Zhang (Shanghai, CN); Zuxing Wang (Shanghai, CN)
Assignee: SAP SE
G06F16/285G06F11/3006G06F11/3495H04L41/142H04L43/08H04L63/1408H04L63/1425H04L67/02H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,580,135
App. No.
17/089,335
Granted
Feb 14, 2023
Kind
B2
Abstract

Requests are received for handling by a cloud computing environment which are then executed by the cloud computing environment. While each request is executing, performance metrics associated with the request are monitored. A vector is subsequently generated that encapsulates information associated with the request including the text within the request and the corresponding monitored performance metrics. Each request is then assigned (after it has been executed) to either a normal request cluster or an abnormal request cluster based on which cluster has a nearest mean relative to the corresponding vector. In addition, data can be provided that characterizes requests assigned to the abnormal request cluster. Related apparatus, systems, techniques and articles are also described.

Claims (51)

1. A method for implementation by one or more computing devices comprising:

receiving, by a cloud computing environment, a plurality of requests for handling by the cloud computing environment, each of the requests encapsulating text;

executing each of the requests by the cloud computing environment;

monitoring performance metrics associated with the execution of each request;

generating, for each request, a first vector based on the text encapsulated within the request;

generating, for each request, a second vector based on the monitored performance metrics corresponding to the request;

generating, for each request, a third vector by combining the first and second vectors;

assigning each request to either a normal request cluster or an abnormal request cluster based on which cluster has a nearest mean relative to the corresponding third vector; and

providing data characterizing the requests assigned to the abnormal request cluster.

2. The method of claim 1 further comprising:

generating the normal request cluster and the abnormal request cluster using k-means clustering.

3. The method of claim 2 , wherein the nearest mean corresponds to a cluster having a least squared Euclidian distance.

4. The method of claim 3 , wherein the normal request cluster and the abnormal request cluster are generated based on logged historical requests received by the cloud computing environment.

5. The method of claim 4 , wherein the requests are of different types and, for each request type, there is a corresponding normal request cluster and a corresponding abnormal request cluster.

6. The method of claim 3 , wherein the k-means clustering defines the normal request cluster and the abnormal request cluster using combined vectors encapsulating information derived from logged historical requests with numeric performance metrics associated with the corresponding request.

7. The method of claim 6 further comprising: converting text from logged historical requests into numeric values using a word embedding algorithm.

8. The method of claim 7 , wherein the word embedding algorithm is word2vec.

9. The method of claim 8 further comprising:

selectively removing text within each logged historical request prior to generating the corresponding combined vector to optimize the k-means clustering.

10. The method of claim 8 further comprising:

normalizing each combined vector prior to generating the normal request cluster and the abnormal request cluster using k-means clustering.

11. The method of claim 8 further comprising: averaging multiple vectors for each historical request to generate an average vector, the average vector being combined with a numeric vector to result in the combined vector for each request.

12. The method of 4 , wherein the logged historical requests each identify a type of request, an amount of time to handle the request, an amount of time to handle a query associated with the request, processing resources used by the request, or memory used by the request.

13. The method of claim 1 , wherein the requests originate from a client computing device and are associated with execution of a cloud-based software application in a browser executing on the client computing device.

14. The method of claim 1 further comprising:

transmitting data to a remote computing system characterizing each request assigned to the abnormal request cluster.

15. The method of claim 1 , wherein the requests are hypertext transfer protocol (HTTP) requests.

16. The method of claim 1 further comprising:

executing or attempting to execute, by the cloud computing environment, requests assigned to the abnormal request cluster.

17. The method of claim 1 , wherein the providing data comprises: causing the data characterizing requests assigned to the abnormal request cluster to be displayed in an electronic visual display, storing the data characterizing requests assigned to the abnormal request cluster in physical persistence, or loading the data characterizing requests assigned to the abnormal request cluster in memory.

18. The method of claim 1 further comprising:

implementing at least one code patch in the cloud computing environment which causes a request previously assigned to the abnormal request cluster to be subsequently assigned to the normal request cluster when received again by the cloud computing environment.

19. A system comprising:

at least one data processor; and

memory storing instructions which, when executed by the at least one data processor, result in operations comprising:

receiving, by a cloud computing environment, a plurality of requests for handling by the cloud computing environment, each of the requests encapsulating text;

executing each of the requests by the cloud computing environment;

monitoring performance metrics associated with the execution of each request;

generating, for each request, a first vector based on the text encapsulated within the request;

generating, for each request, a second vector based on the monitored performance metrics corresponding to the request;

generating, for each request, a third vector by combining the first and second vectors;

assigning each request to either a normal request cluster or an abnormal request cluster based on which cluster has a nearest mean relative to the corresponding third vector; and

providing data characterizing the requests assigned to the abnormal request cluster.

20. A method for implementation by one or more computing devices comprising:

receiving, by a cloud computing environment, a plurality of requests for handling by the cloud computing environment, each of the requests encapsulating text;

executing each of the requests by the cloud computing environment;

logging monitoring performance metrics associated with the execution of each request in a log;

generating, for each request in the log, a first vector based on the text encapsulated within the request;

generating, for each request in the log, a second vector based on the monitored performance metrics corresponding to the request;

generating, for each request in the log, a third vector by combining the first and second vectors; and

generating, using k-means clustering as applied to the generated third vectors, a normal request cluster specifying a boundary for the third vectors and an abnormal request cluster corresponding to third vectors falling outside the specified boundary of the normal request cluster.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 4, 2020
From: WAN, DENG FENG; DENG, YANGCHUN; ZHANG, HUI; WANG, ZUXING
To: SAP SE
Reel/Frame 054276/0092 →
Continuity (1)
Related Publication 20220138227A1 · May 5, 2022
Cited By (1)
US 12,505,526