IP Library › Granted Patent US 12,524,229
Granted Patent B2
US 12,524,229 · App. 18/483,675 · Granted Jan 13, 2026

Systems and methods for risk awareness using machine learning techniques

Inventors: Per Karlsson (Saint Johns, FL); Benjamin Wellmann (Boca Raton, FL); Sheel Saket (Wheeling, IL); Vida Lashkari (Atlanta, GA)
Assignee: Fidelity Information Services, LLC
G06F8/71G06F11/327G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,524,229
App. No.
18/483,675
Granted
Jan 13, 2026
Kind
B2
Abstract

A method for training and using a machine-learning based model to reduce and troubleshoot incidents in a system may include receiving first metadata regarding a previous modification, extracting a first feature from the received first metadata, receiving second metadata regarding a previous incident, extracting a second feature from the received second metadata, training the machine-learning based model to learn an association between the previous modification and the previous incident, based on the extracted first feature and the extracted second feature, and using the machine-learning based model to determine a risk level for a proposed modification to a system.

Claims (54)

1 . A method comprising, performing by one or more processors, operations including:

determining a risk level for a proposed modification to code of a software component of a system, the determining a risk level for the proposed modification including:

receiving metadata regarding the proposed modification to the system;

extracting a feature from the received metadata, the extracted feature corresponding to a feature of a trained machine-learning based model for determining the risk level for the proposed modification based on a learned association between the extracted feature and an incident occurring in the system; and

automatically determining the risk level for the proposed modification based on the extracted feature, by using the trained machine-learning based model, wherein the trained machine-learning based model is a multi-class classification machine learning model, wherein the automatically determining the risk level for the proposed modification comprises implementing dynamic thresholds that vary by application or code repository;

determining whether the proposed modification to code of the software component of the system is to a critical code segment or a non-critical code segment, and

performing one or more of:

performing a first action when the proposed modification to the code is determined to be to a non-critical code segment and the determined risk level is above a non-critical code predetermined threshold, or

performing a second action when the proposed modification to the code is determined to be to a critical code segment and the determined risk level is above a critical code predetermined threshold.

2 . The method of claim 1 , wherein:

the first action includes providing a suggested action for reducing a risk level for the proposed modification, and

the second action includes blocking the proposed modification from being implemented.

3 . The method of claim 1 , wherein the operations further include:

providing an alert identifying the determined risk level for the proposed modification to the system.

4 . The method of claim 1 , wherein the trained machine-learning based model was trained based on a first feature extracted from metadata regarding a previous modification to the system and a second feature extracted from metadata regarding a previous incident related to the previous modification occurring in the system, based on the learned association between the extracted feature and the incident occurring in the system.

5 . The method of claim 1 , wherein the operations further include:

providing the determined risk level as a score from 0 to 100.

6 . The method of claim 1 , wherein the system includes at least one of an intake system, a development system, a release system, a deployment system, or an incident reporting system.

7 . The method of claim 1 , wherein the operations are performed by using one or more Application Programming Interface (API) interactions.

8 . The method of claim 1 , wherein the trained machine-learning based model is trained on clusters created by an unsupervised machine learning system, wherein the clusters are based on received metadata including incident descriptions, resolution notes, issue tracking tickets, and code repository commit messages.

9 . The method of claim 1 , wherein the operations further include:

determining, using a classification model, a code change or resolution based on a received incident journey.

10 . A non-transitory computer readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform the method of claim 1 .

11 . A method for determining a risk level for a proposed modification to code of a software component of a system, the method comprising, performing by one or more processors, operations including:

determining a risk level for the proposed modification; the determining a risk level for the proposed modification including:

receiving metadata regarding the proposed modification to the system;

extracting a feature from the received metadata, the extracted feature corresponding to a feature of a trained machine-learning based model for determining the risk level for the proposed modification based on a learned association between the extracted feature and an incident occurring in the system; and

automatically determining the risk level for the proposed modification based on the extracted feature, by using the trained machine-learning based model, wherein the trained machine-learning based model is a multi-class classification machine learning model, wherein the automatically determining the risk level for the proposed modification comprises implementing dynamic thresholds that vary by application or code repository;

determining whether the code is a critical code segment or a non-critical code segment; and

performing one or more of:

providing a suggested action for reducing the determined risk level for the proposed modification when the code is determined to be a non-critical code segment and the determined risk level is above a non-critical code predetermined threshold, or

blocking the proposed modification from being implemented when the code is determined to be a critical code segment and the determined risk level is above a critical code predetermined threshold.

12 . The method of claim 11 , wherein the operations further include:

providing an alert identifying the determined risk level for the proposed modification to the system.

13 . The method of claim 11 , wherein the trained machine-learning based model was trained based on a first feature extracted from metadata regarding a previous modification to the system and a second feature extracted from metadata regarding a previous incident related to the previous modification occurring in the system, based on the learned association between the extracted feature and the incident occurring in the system.

14 . The method of claim 11 , wherein the operations further include:

providing the determined risk level as a score from 0 to 100.

15 . The method of claim 11 , wherein the system includes at least one of an intake system, a development system, a release system, a deployment system, or an incident reporting system.

16 . The method of claim 11 , wherein the operations are performed by using one or more Application Programming Interface (API) interactions.

17 . A non-transitory computer readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform the method of claim 11 .

18 . A computer-implemented system for determining a risk level for a proposed modification to code of a software component of a system, the computer-implemented system comprising:

a memory to store instructions; and

a processor to execute the stored instructions to perform operations including:

determining a risk level for the proposed modification; the determining a risk level for the proposed modification including:

receiving metadata regarding the proposed modification to the system;

extracting a feature from the received metadata, the extracted feature corresponding to a feature of a trained machine-learning based model for determining the risk level for the proposed modification based on a learned association between the extracted feature and an incident occurring in the system; and

automatically determining the risk level for the proposed modification based on the extracted feature, by using the trained machine-learning based model, wherein the trained machine-learning based model is a multi-class classification machine learning model, wherein the automatically determining the risk level for the proposed modification comprises implementing dynamic thresholds that vary by application or code repository;

determining whether the code is a critical code segment or a non-critical code segment; and

performing one or more of:

providing a suggested action for reducing the determined risk level for the proposed modification when the code is determined to be a non-critical code segment and the determined risk level is above a non-critical code predetermined threshold, or

blocking the proposed modification from being implemented when the code is determined to be a critical code segment and the determined risk level is above a critical code predetermined threshold.

19 . The computer-implemented system of claim 18 , wherein the trained machine-learning based model was trained based on a first feature extracted from metadata regarding a previous modification to the system and a second feature extracted from metadata regarding a previous incident related to the previous modification occurring in the system, based on the learned association between the extracted feature and the incident occurring in the system.

20 . The computer-implemented system of claim 18 , wherein the operations further include:

providing the determined risk level as a score from 0 to 100.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 10, 2023
From: KARLSSON, PER; WELLMANN, BENJAMIN; SAKET, SHEEL; LASHKARI, VIDA
To: FIDELITY INFORMATION SERVICES, LLC
Reel/Frame 065169/0701 →
Continuity (2)
Continuation 17448561 · Sep 23, 2021
Related Publication 20240045671A1 · Feb 8, 2024
References Cited (34)
US 9176729B2 · Mockus · 2015 [cited by examiner]
US 9268665B2 · Barrow · 2016 [cited by examiner]
US 9921948B2 · Zieder · 2018 [cited by examiner]
US 10157052B2 · Eberlein · 2018 [cited by examiner]
US 10482000B2 · Vikjord · 2019 [cited by examiner]
US 10547507B2 · Guven · 2020 [cited by examiner]
US 10866848B2 · Bridges et al. · 2020 [cited by applicant]
US 11151499B2 · Guven · 2021 [cited by examiner]
US 11221908B1 · Batta · 2022 [cited by examiner]
US 11360959B2 · Pourmohammad · 2022 [cited by examiner]
US 11710570B2 · Brook · 2023 [cited by examiner]
US 11809859B2 · Espinha · 2023 [cited by examiner]
US 11816476B2 · Karlsson · 2023 [cited by examiner]
US 20140053135A1 · Bird · 2014 [cited by examiner]
US 20150100940A1 · Mockus · 2015 [cited by examiner]
US 20160239402A1 · Zieder · 2016 [cited by examiner]
US 20180275970A1 · Woulfe et al. · 2018 [cited by applicant]
US 20180276105A1 · Srinivasan · 2018 [cited by examiner]
US 20180293158A1 · Baughman · 2018 [cited by examiner]
US 20180314517A1 · Iwanir · 2018 [cited by examiner]
US 20180373578A1 · Bridges · 2018 [cited by examiner]
US 20190079850A1 · Zhang et al. · 2019 [cited by applicant]
US 20190138512A1 · Pourmohammad · 2019 [cited by examiner]
US 20190227787A1 · Kumar et al. · 2019 [cited by applicant]
US 20190287029A1 · Sobran · 2019 [cited by examiner]
US 20200349133A1 · Dwarampudi et al. · 2020 [cited by applicant]
US 20200382365A1 · Verma · 2020 [cited by applicant]
US 20210141718A1 · Sandhu · 2021 [cited by examiner]
US 20210157577A1 · Sobran · 2021 [cited by examiner]
US 20210342207A1 · Oliveri · 2021 [cited by examiner]
US 20220156134A1 · Lehmann et al. · 2022 [cited by applicant]
US 20220308862A1 · Espinha et al. · 2022 [cited by applicant]
Chief Information Officer: “DoD Enterprise DevSecOps Reference Design Department of Defense (DoD) Chief Information Officer”, Aug. 12, 2019 (Aug. 12, 2019), pp. 1-89, XP055887783, Retrieved from the Internet: URL: https… [cited by applicant]
International Search Report issued in International Application No. PCT/US2022/076718 dated Dec. 22, 2022 (15 pages). [cited by applicant]