IP Library › Granted Patent US 12,393,476
Granted Patent B2
US 12,393,476 · App. 18/447,512 · Granted Aug 19, 2025

Early detection of information technology (IT) failures using multimodal correlation and prediction

Inventors: Naga A. Ayachitula (Dobbs Ferry, NY); Rohit Khandekar (Jersey City, NJ); Upendra Sharma (Hartsdale, NY)
Assignee: Kyndryl, Inc.
G06F11/004G06N5/022G06F2201/81
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,393,476
App. No.
18/447,512
Granted
Aug 19, 2025
Kind
B2
Abstract

Embodiments relate to early detection of information technology (IT) failures in a computing system. A technique is executed by one or more processors and includes receiving multiple IT records including past and recent historical data, extracting first and second time series sections from the past and recent historical data, respectively, training a failure detection model to correlate metric patterns in the first time series sections with at least one of other metric patterns and previous IT failures and, in response to the training, using the failure detection model to predict at least one of upcoming metric patterns and upcoming IT failures from metric patterns in the second time series sections.

Claims (37)

1. A computer-implemented method for early detection of information technology (IT) failures in a computing system, the computer-implemented method being executed by one or more processors and comprising:

receiving multiple IT records comprising past and recent historical data;

extracting first and second time series sections from the past and recent historical data, respectively;

training a failure detection model to correlate metric patterns in the first time series sections with at least one of other metric patterns and previous IT failures;

in response to the training, using the failure detection model to predict at least one of upcoming metric patterns and upcoming IT failures from metric patterns in the second time series sections; and

in response to a detection of the at least one of the metric patterns and the upcoming IT failures, automatically reducing central processing unit (CPU) usage, memory usage, workload, input/output (I/O) flow of the computing system to avoid the at least one of the metric patterns and the upcoming IT failures of computing system.

2. The computer-implemented method according to claim 1 , further comprising identifying one or more of the multiple IT records with the recent historical data as non-actionable.

3. The computer-implemented method according to claim 2 , wherein the identifying comprises correlating the metric patterns of the second time series data with temporal phenomena.

4. The computer-implemented method according to claim 2 , wherein the identifying comprises correlating the metric patterns of the second time series data with changes in the computing system.

5. The computer-implemented method according to claim 1 , wherein the metric patterns in the first time series sections correlate with the at least one of the other metric patterns and the previous IT failures in an event values of the metric patterns provide statistically significant information about values of the at least one of the other metric patterns and the previous IT failures.

6. The computer-implemented method according to claim 1 , wherein the metric patterns comprise memory utilization spikes and central processing unit (CPU) spikes.

7. The computer-implemented method according to claim 6 , wherein the memory utilization spikes are correlated with and precede the CPU spikes.

8. A system comprising:

a memory having computer readable instructions; and

one or more processors for executing the computer readable instructions, the computer readable instructions controlling the one or more processors to perform operations for early detection of information technology (IT) failures in a computing system comprising:

receiving multiple IT records comprising past and recent historical data;

extracting first and second time series sections from the past and recent historical data, respectively;

training a failure detection model to correlate metric patterns in the first time series sections with at least one of other metric patterns and previous IT failures;

in response to the training, using the failure detection model to predict at least one of upcoming metric patterns and upcoming IT failures from metric patterns in the second time series sections; and

in response to a detection of the at least one of the metric patterns and the upcoming IT failures, automatically reducing central processing unit (CPU) usage, memory usage, workload, input/output (I/O) flow of the computing system to avoid the at least one of the metric patterns and the upcoming IT failures of computing system.

9. The system according to claim 8 , wherein the operations further comprise identifying one or more of the multiple IT records with the recent historical data as non-actionable.

10. The system according to claim 9 , wherein the identifying comprises correlating the metric patterns of the second time series data with temporal phenomena.

11. The system according to claim 9 , wherein the identifying comprises correlating the metric patterns of the second time series data with changes in the computing system.

12. The system according to claim 8 , wherein the metric patterns in the first time series sections correlate with the at least one of the other metric patterns and the previous IT failures in an event values of the metric patterns provide statistically significant information about values of the at least one of the other metric patterns and the previous IT failures.

13. The system according to claim 8 , wherein the metric patterns comprise memory utilization spikes and central processing unit (CPU) spikes.

14. The system method according to claim 13 , wherein the memory utilization spikes are correlated with and precede the CPU spikes.

15. A computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by one or more processors to cause the one or more processors to perform operations for early detection of information technology (IT) failures in a computing system comprising:

receiving multiple IT records comprising past and recent historical data;

extracting first and second time series sections from the past and recent historical data, respectively;

training a failure detection model to correlate metric patterns in the first time series sections with at least one of other metric patterns and previous IT failures;

in response to the training, using the failure detection model to predict at least one of upcoming metric patterns and upcoming IT failures from metric patterns in the second time series sections; and

in response to a detection of the at least one of the metric patterns and the upcoming IT failures, automatically reducing central processing unit (CPU) usage, memory usage, workload, input/output (I/O) flow of the computing system to avoid the at least one of the metric patterns and the upcoming IT failures of computing system.

16. The computer program product according to claim 15 , further comprising identifying one or more of the multiple IT records with the recent historical data as non-actionable.

17. The computer program product according to claim 16 , wherein the identifying comprises correlating the metric patterns of the second time series data with temporal phenomena.

18. The computer program product according to claim 16 , wherein the identifying comprises correlating the metric patterns of the second time series data with changes in the computing system.

19. The computer program product according to claim 15 , wherein the metric patterns in the first time series sections correlate with the at least one of the other metric patterns and the previous IT failures in an event values of the metric patterns provide statistically significant information about values of the at least one of the other metric patterns and the previous IT failures.

20. The computer program product according to claim 15 , wherein the metric patterns comprise memory utilization spikes and central processing unit (CPU) spikes and the memory utilization spikes are correlated with and precede the CPU spikes.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2023
From: AYACHITULA, NAGA A.; KHANDEKAR, ROHIT; SHARMA, UPENDRA
To: KYNDRYL, INC.
Reel/Frame 064551/0564 →
Continuity (1)
Related Publication 20250053469A1 · Feb 13, 2025
References Cited (2)
US 20200210538A1 · Wang · 2020 [cited by examiner]
US 20210203157A1 · Visweswariah · 2021 [cited by examiner]