IP Library › Granted Patent US 11,886,285
Granted Patent B2
US 11,886,285 · App. 17/843,198 · Granted Jan 30, 2024

Cross-correlation of metrics for anomaly root cause identification

Inventors: Maxwell Henry Poole (San Jose, CA); Satish Sambasivan (Cupertino, CA); Vivek Siva Kaushik (Pleasanton, CA)
Assignee: eBay Inc.
G06F11/0793G06F11/0706
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,886,285
App. No.
17/843,198
Granted
Jan 30, 2024
Kind
B2
Abstract

Technologies are disclosed herein for cross-correlating metrics for anomaly root cause detection. Primary and secondary metrics associated with an anomaly are cross-correlated by first using the derivative of an interpolant of data points of the primary metric to identify a time window for analysis. Impact scores for the secondary metrics can be then be generated by computing the standard deviation of a derivative of data points of the secondary metrics during the identified time window. The impact scores can be utilized to collect data relating to the secondary metrics most likely to have caused the anomaly. Remedial action can then be taken based upon the collected data in order to address the root cause of the anomaly.

Claims (36)

1. A method comprising:

retrieving a primary dataset and a plurality of secondary datasets, the primary dataset comprising data points for a primary metric, and the plurality of secondary datasets comprising data points for a plurality of secondary metrics;

identifying a time window based on the primary dataset;

computing an interpolant for data points in the time window for one or more of the plurality of secondary datasets, the interpolant corresponding to an anomaly impacting operation of one or more components of a computing system; and

performing, on the one or more components, a remedial action for the anomaly, the remedial action restoring the operation of the one or more components.

2. The method of claim 1 , further comprising computing an impact score for each of the plurality of secondary metrics based on the interpolant.

3. The method of claim 2 , wherein the impact score comprises a standard deviation of derivatives of the interpolant during the time window.

4. The method of claim 2 , further comprising selecting a set of secondary metrics from the plurality of secondary metrics based on respective impact scores.

5. The method of claim 1 , further comprising identifying a cause of the anomaly impacting operation of the one or more components.

6. The method of claim 5 , wherein the remedial action addresses the cause of the anomaly.

7. The method of claim 1 , wherein the remedial action includes one or more of restoring, rebooting, reconfiguring, or initializing the computing system.

8. The method of claim 1 , wherein the remedial action includes restoring, rebooting, initializing, or reconfiguring the one or more components.

9. The method of claim 1 , further comprising transmitting an alert to an associated administrator of the computing system.

10. The method of claim 1 , further comprising:

receiving an indication of the anomaly at the computing system; and

retrieving the primary dataset and the plurality of secondary datasets based on the indication.

11. A computing system, comprising:

one or more processors; and

a computer-readable storage medium having computer-executable instructions stored thereupon which, when executed by the one or more processors, cause the one or more processors to:

retrieve a primary dataset and a plurality of secondary datasets, the primary dataset comprising data points for a primary metric, and the plurality of secondary datasets comprising data points for a plurality of secondary metrics;

identify a time window based on the primary dataset;

compute an interpolant for data points in the time window for each of the plurality of secondary datasets, one or more of the interpolants corresponding to an anomaly impacting operation of one or more components of the computing system; and

perform, on the one or more components, a remedial action for the anomaly, the remedial action restoring the operation of the one or more components.

12. The computing system of claim 11 , further comprising computing an interpolant for the data points in the primary dataset by fitting a cubic polynomial through the data points for the primary metric.

13. The computing system of claim 11 , wherein the interpolant for the data points in the time window for each of the plurality of secondary datasets are computed by fitting a cubic polynomial through the data points for the plurality of secondary metrics.

14. The computing system of claim 11 , wherein identifying the time window comprises evaluating roots of a derivative of an interpolant for the data points in the primary dataset.

15. The computing system of claim 11 , wherein the data points for the primary metric and the data points for the plurality of secondary metrics are collected during a time period corresponding to the anomaly detected at the computing system.

16. The computing system of claim 11 , further comprising computing an impact score for each of the plurality of secondary metrics based on the interpolant for each of the plurality of secondary datasets.

17. A computer-readable storage medium having computer-executable instructions stored thereupon which, when executed by a processor, cause the processor to:

retrieve a primary dataset and a plurality of secondary datasets, the primary dataset comprising data points for a primary metric, and the plurality of secondary datasets comprising data points for a plurality of secondary metrics;

identify a time window based on the primary dataset;

compute a secondary interpolant for data points in the time window for each of the plurality of secondary datasets, one or more of the secondary interpolants corresponding to an anomaly impacting operation of one or more components of a computing system; and

perform, on the one or more components, a remedial action for the anomaly, the remedial action restoring the operation of the one or more components.

18. The computer-readable storage medium of claim 17 , wherein the time window is identified by evaluating roots of a derivative of an interpolant for the primary dataset.

19. The computer-readable storage medium of claim 17 , wherein the data points for the primary metric and the data points for the plurality of secondary metrics are collected during a time period corresponding to the anomaly detected at the computing system.

20. The computer-readable storage medium of claim 17 , wherein the remedial action includes restoring, rebooting, initializing, or reconfiguring the one or more components.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 17, 2022
From: POOLE, MAXWELL HENRY; SAMBASIVAN, SATISH; KAUSHIK, VIVEK SIVA
To: EBAY INC.
Reel/Frame 060237/0311 →
Continuity (3)
Continuation 16355042 · Mar 15, 2019
Related Publication 20220325392A1 · Oct 13, 2022
Related Publication 20230359519A9 · Nov 9, 2023