IP Library › Granted Patent US 12,725,027
Granted Patent B2
US 12,725,027 · App. 17/106,298 · Granted Sep 1, 2026

Proactive anomaly detection

Inventors: Hui Kang (Briarcliff Manor, NY); Xinyu Que (Yorktown Heights, NY); Yu Deng (Yorktown Heights, NY); Sinem Guven Kaya (New York, NY); Bruce D'Amora (New Milford, CT)
Assignee: International Business Machines Corporation
G06N3/08G06F11/302G06F11/3495G06F11/3466G06N3/044G06N3/045
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,725,027
App. No.
17/106,298
Granted
Sep 1, 2026
Kind
B2
Abstract

Embodiments of the present invention provide computer implemented methods, computer program products and computer systems. For example, embodiments of the present invention can, in response to receiving a request, collect trace data and specifications for a sequence of requests for normal behavior of a microservice application. Embodiments of the present invention can then generate request contextual features from the collected trace data and specification. Embodiments of the present invention can then train a neural network model based on the generated contextual features; and predicting anomalous behavior of the microservice application using the trained neural network model.

Claims (49)

1 . A computer-implemented method comprising:

in response to receiving a request, collecting trace data and specifications for a sequence of requests from an application comprising multiple microservices, wherein the collected trace data and specifications comprise respective trace data and specifications collected at each microservice instance of the multiple microservices;

identifying inter-request factors and intra-request factors from the collected trace data and specifications;

generating request contextual features comprising spatial and temporal dependences from the inter-request factors, the intra-request factors, and the collected trace data and specifications;

building and training a recurrent neural network model using the generated contextual features as inputs;

predicting anomalous behavior of a future request of the application based on spatial and temporal dependencies using the trained recurrent neural network model, wherein the anomalous behavior comprises a service level agreement violation, and wherein the predicting further comprises predicting a region of impacted users and an impact on a subset of requests, wherein the impact specifies a type of request that will fail;

generating, in response to prediction of the anomalous behavior, a proactive alert which comprises the region, the impact, and a reason for the prediction of the anomalous behavior; and

providing a system simulation for the predicted anomalous behavior of the future request;

wherein results of the system simulation comprise details of an end-to-end execution flow at each microservice instance of a microservice path of the future request comprising central processing unit usage, memory usage, disk usage, and network usage of the microservice application.

2 . The computer-implemented method of claim 1 , further comprising: generating visualizations associated with the predicted anomalous behavior.

3 . The computer-implemented method of claim 1 , further comprising: generating a root cause report for the predicted anomalous behavior.

4 . The computer-implemented method of claim 1 , wherein the trace data provides a hierarchal data structure that separates logs into individual requests.

5 . The computer-implemented method of claim 1 , wherein the request contextual features comprises:

a data structure that includes three level of information of a request: request-specification, microservice-path and function-path.

6 . The computer-implemented method of claim 1 , further comprising:

predicting a component of one or more services within a cloud infrastructure is responsible for the service level agreement violation using contextual data that includes traces that separate logs into individual requests.

7 . The computer-implemented method of claim 6 , further comprising:

identifying a respective service that caused a specific request of a group of received requests to fail.

8 . A computer program product comprising:

one or more computer readable storage media and program instructions stored on the one or more computer readable storage media, the program instructions comprising;

program instructions to, in response to receiving a request, collect trace data and specifications for a sequence of requests from an application comprising multiple microservices, wherein the collected trace data and specifications comprise respective trace data and specifications collected at each microservice instance of the multiple microservices;

program instructions to identify inter-request factors and intra-request factors from the collected trace data and specifications;

program instructions to generate request contextual features comprising spatial and temporal dependences from the inter-request factors, the intra-request factors, and the collected trace data and specifications;

program instructions to build and train a recurrent neural network model using the generated contextual features as inputs;

program instructions to predict anomalous behavior of a future request of the application based on spatial and temporal dependencies using the trained recurrent neural network model, wherein the anomalous behavior comprises a service level agreement violation, and wherein the predicting further comprises predicting a region of impacted users and an impact on a subset of requests, wherein the impact specifies a type of request that will fail;

program instructions to generate, in response to prediction of the anomalous behavior, a proactive alert which comprises the region, the impact, and a reason for the prediction of the anomalous behavior; and

program instructions to provide a system simulation for the predicted anomalous behavior of the future request; wherein results of the system simulation comprise details of an end-to-end execution flow at each microservice instance of a microservice path of the future request comprising central processing unit usage, memory usage, disk usage, and network usage of the microservice application.

9 . The computer program product of claim 8 , wherein the program instructions stored on the one or more computer readable storage media further comprise;

program instructions to generate visualizations associated with the predicted anomalous behavior.

10 . The computer program product of claim 8 , wherein the program instructions stored on the one or more computer readable storage media further comprise:

program instructions to generate a root cause report for the predicted anomalous behavior.

11 . The computer program product of claim 8 , wherein the trace data provides a hierarchal data structure that separates logs into individual requests.

12 . The computer program product of claim 8 , wherein the request contextual features comprise:

a data structure that includes three level of information of a request: request-specification, microservice-path and function-path.

13 . A computer system comprising:

one or more computer processors;

one or more computer readable storage media; and

program instructions stored on the one or more computer readable storage media for execution by at least one of the one or more computer processors, the program instructions comprising:

program instructions to, in response to receiving a request, collect trace data and specifications for a sequence of requests from an application comprising multiple microservices, wherein the collected trace data and specifications comprise respective trace data and specifications collected at each microservice instance of the multiple microservices;

program instructions to identify inter-request factors and intra-request factors from the collected trace data and specifications;

program instructions to generate request contextual features comprising spatial and temporal dependences from the inter-request factors, the intra-request factors, and the collected trace data and specifications;

program instructions to build and train a recurrent neural network model using the generated contextual features as inputs;

program instructions to predict anomalous behavior of a future request of the application based on spatial and temporal dependencies using the trained recurrent neural network model, wherein the anomalous behavior comprises a service level agreement violation, and wherein the predicting further comprises predicting a region of impacted users and an impact on a subset of requests, wherein the impact specifies a type of request that will fail;

program instructions to generate, in response to prediction of the anomalous behavior, a proactive alert which comprises the region, the impact, and a reason for the prediction of the anomalous behavior; and

program instructions to provide a system simulation for the predicted anomalous behavior of the future request; wherein results of the system simulation comprise details of an end-to-end execution flow at each microservice instance of a microservice path of the future request comprising central processing unit usage, memory usage, disk usage, and network usage of the microservice application.

14 . The computer system of claim 13 , wherein the program instructions stored on the one or more computer readable storage media further comprise:

program instructions to generate visualizations associated with the predicted anomalous behavior.

15 . The computer system of claim 13 , wherein the program instructions stored on the one or more computer readable storage media further comprise:

program instructions to generate a root cause report for the predicted anomalous behavior.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2020
From: KANG, HUI; QUE, XINYU; DENG, YU; GUVEN KAYA, SINEM; D'AMORA, BRUCE
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 054486/0169 →
Continuity (1)
Related Publication 20220172037A1 · Jun 2, 2022
References Cited (42)
US 7933794B2 · Adi · 2011 [cited by applicant]
US 8041797B2 · Childress · 2011 [cited by applicant]
US 10009234B2 · Blondeau · 2018 [cited by applicant]
US 10068301B2 · Kogut-O'Connell · 2018 [cited by applicant]
US 10521811B2 · Rai · 2019 [cited by applicant]
US 10574657B1 · Govil · 2020 [cited by examiner]
US 11843505B1 · Cruise · 2023 [cited by examiner]
US 20090018813A1 · Kothari · 2009 [cited by applicant]
US 20140149175A1 · Abbott · 2014 [cited by applicant]
US 20140223427A1 · Bootland et al. · 2014 [cited by applicant]
US 20160140474A1 · Vekker · 2016 [cited by applicant]
US 20170091781A1 · Puvvala · 2017 [cited by applicant]
US 20180270125A1 · Jain et al. · 2018 [cited by applicant]
US 20190028496A1 · Fenoglio et al. · 2019 [cited by applicant]
US 20200043008A1 · Hrabik · 2020 [cited by examiner]
US 20200174774A1 · Natarajan · 2020 [cited by applicant]
US 20200287923A1 · Raghavendra et al. · 2020 [cited by applicant]
US 20200313979A1 · Kumaran · 2020 [cited by examiner]
US 20210152584A1 · Chakravarty · 2021 [cited by examiner]
US 20230370491A1 · Crabtree · 2023 [cited by examiner]
CN 109067619A · 2018 [cited by applicant]
CN 110362494A · 2019 [cited by applicant]
CN 110825589A · 2020 [cited by applicant]
CN 111459760A · 2020 [cited by applicant]
CN 111913789A · 2020 [cited by applicant]
WO 2020050920A1 · 2020 [cited by applicant]
WO 2022111154A1 · 2022 [cited by applicant]
Guan, Zijie, Jinjin Lin, and Pengfei Chen. “On anomaly detection and root cause analysis of microservice systems.” Service-Oriented Computing—ICSOC 2018 Workshops: ADMS, ASOCA, ISYyCC, CIoTS, DDBS, and NLS4IoT, Hangzhou… [cited by examiner]
Nedelkoski, Sasho, Jorge Cardoso, and Odej Kao. “Anomaly detection from system tracing data using multimodal deep learning.” 2019 IEEE 12th International Conference on Cloud Computing (Cloud). IEEE, 2019. (Year: 2019). [cited by examiner]
Chen, Hongyang, Pengfei Chen, and Guangba Yu. “A framework of virtual war room and matrix sketch-based streaming anomaly detection for microservice systems.” IEEE Access 8 (2020): 43413-43426. (Year: 2020). [cited by examiner]
Anand, Vaastav, et al. “Aggregate-driven trace visualizations for performance debugging.” arXiv preprint arXiv:2010.13681 (2020). (Year: 2020). [cited by examiner]
Vakilinia, Shahin, et al. “Automated enforcement of SLA for cloud services.” 2018 IEEE 11th International Conference on Cloud Computing (Cloud). IEEE, 2018. (Year: 2018). [cited by examiner]
Nedelkoski, Sasho, Jorge Cardoso, and Odej Kao. “Anomaly detection and classification using distributed tracing and deep learning.” 2019 19th IEEE/ACM international symposium on cluster, cloud and grid computing (CCGRID… [cited by examiner]
Masouros, Dimosthenis, Sotirios Xydis, and Dimitrios Soudris. “Rusty: Runtime interference-aware predictive monitoring for modern multi-tenant systems.” IEEE Transactions on Parallel and Distributed Systems 32.1 (2020):… [cited by examiner]
Qiu, Haoran, et al. “{FIRM}: An intelligent fine-grained resource management framework for {SLO-Oriented} microservices.” 14th USENIX symposium on operating systems design and implementation (OSDI 20). 2020. (Year: 2020… [cited by examiner]
“Patent Cooperation Treaty PCT Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, or the Declaration”, Applicant's file reference EIE210796PC… [cited by applicant]
Jayathilaka et al., “Performance Monitoring and Root Cause Analysis for Cloud-hosted Web Applications”, © 2017 International World Wide Web Conference Committee (IW3C2), 10 pages, <:http://dx.doi.org/10.1145/3038912.305… [cited by applicant]
Weng et al., “Root Cause Analysis of Anomalies of Multitier Services in Public Clouds”, Conference Paper . Jun. 2017, DOI: 10.1109/IWQoS.2017.7969155, 7 pages. [cited by applicant]
Ouyang et al., “Reducing Late-Timing Failure at Scale: Straggler Root-Cause Analysis in Cloud Datacenters.” Submitted on May 17, 2016, 3 pages, <https://hal.archives-ouvertes.fr/hal-01316515>. [cited by applicant]
Nedelkoski et al., “Anomaly Detection and Classification using Distributed Tracing and Deep Learning, ” 2019 19th IEEE/ACM International Symposium on Cluster, Cloud and Grid Computing (CCGRID), DOI 10.1109/CCGRID.2019.0… [cited by applicant]
Gan et al., “Leveraging Deep Learning to Improve the Performance Predictability of Cloud Microservices”, arXiv:1905.00968v1 [cs.DC] May 2, 2019, 15 pages. [cited by applicant]
Japan Patent Office, “Notice of Reasons for Refusal,” Feb. 4, 2025, 8 Pages, JP Application No. 2023-532550. [cited by applicant]