US2021089649A1PendingUtilityA1

Machine learning anomaly detection mechanism

Assignee: SALESFORCE COM INCPriority: Jan 30, 2019Filed: Dec 1, 2020Published: Mar 25, 2021
Est. expiryJan 30, 2039(~12.5 yrs left)· nominal 20-yr term from priority
G06F 21/554G06F 21/552G06F 2221/034G06N 20/00G06Q 30/01
53
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Techniques and structures to facilitate anomaly detection within a networking system, including retrieving performance metric messages generated at a server, transmitting a compute request including the performance metric messages to a database system to perform an anomaly detection computation, retrieving data resulting from the anomaly detection computation and publishing the data resulting from the anomaly detection computation, wherein the anomaly detection computation comprises executing a machine learning model to process the performance metric messages to determine whether anomalous usage of the system has been detected.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method to facilitate anomaly detection at a system, comprising:
 retrieving performance metric messages generated at a server;   transmitting a compute request including the performance metric messages to perform an anomaly detection computation, wherein the anomaly detection computation comprises executing a machine learning model to process the performance metric messages to determine whether anomalous usage of the system has been detected;   retrieving data resulting from the anomaly detection computation; and   publishing the data resulting from the anomaly detection computation.   
     
     
         2 . The method of  claim 1 , further comprising invoking a first task to retrieve the performance metric messages and transmit the compute request to the database system. 
     
     
         3 . The method of  claim 2 , wherein the performance metric messages are retrieved for each instance machine operation on the server. 
     
     
         4 . The method of  claim 2 , wherein the first task is invoked at a predetermined interval. 
     
     
         5 . The method of  claim 4 , further comprising invoking a second task to retrieve the data resulting from the anomaly detection computation. 
     
     
         6 . The method of  claim 5 , wherein the second task is invoked at a predetermined interval. 
     
     
         7 . The method of  claim 1 , wherein publishing the data comprises:
 publishing the data to a dashboard user interface; and   publishing the data to an incident database.   
     
     
         8 . The method of  claim 7 , further comprising further comprising displaying the data at the dashboard user interface. 
     
     
         9 . The method of  claim 1 , wherein the data comprises an anomaly score. 
     
     
         10 . A computing device comprising:
 one or more processors to retrieve performance metric messages generated at a server, transmit a compute request including the performance metric messages to perform an anomaly detection computation, retrieve data resulting from the anomaly detection computation and publish the data resulting from the anomaly detection computation, wherein the anomaly detection computation comprises executing a machine learning model to process the performance metric messages to determine whether anomalous usage of the system has been detected.   
     
     
         11 . The computing device of  claim 10 , wherein the one or more processors further invoke a first task to retrieve the performance metric messages and transmit the compute request to the database system. 
     
     
         12 . The computing device of  claim 10 , wherein the performance metric messages are retrieved for each instance machine operation on the server. 
     
     
         13 . The computing device of  claim 11 , wherein the first task is invoked at a predetermined interval. 
     
     
         14 . The computing device of  claim 13 , wherein the one or more processors further invoke a second task to retrieve the data resulting from the anomaly detection computation. 
     
     
         15 . The computing device of  claim 10 , wherein publishing the data comprises publishing the data to a dashboard user interface and publishing the data to an incident database. 
     
     
         16 . A non-transitory computer-readable medium having stored thereon instructions that, when executed by one or more processors, are configurable to cause the one or more processors to:
 retrieve performance metric messages generated at a server;   transmit a compute request including the performance metric messages to perform an anomaly detection computation, wherein the anomaly detection computation comprises executing a machine learning model to process the performance metric messages to determine whether anomalous usage of the system has been detected;   retrieve data resulting from the anomaly detection computation; and   publish the data resulting from the anomaly detection computation.   
     
     
         17 . The non-transitory computer-readable medium of  claim 16 , having stored thereon instructions that, when executed by one or more processors, are configurable to further cause the one or more processors to invoke a first task to retrieve the performance metric messages and transmit the compute request to the database system. 
     
     
         18 . The non-transitory computer-readable medium of  claim 17 , wherein the first task is invoked at a predetermined interval. 
     
     
         19 . The non-transitory computer-readable medium of  claim 18 , having stored thereon instructions that, when executed by one or more processors, are configurable to further cause the one or more processors to invoke a second task to retrieve the data resulting from the anomaly detection computation. 
     
     
         20 . The non-transitory computer-readable medium of  claim 16 , having stored thereon instructions that, when executed by one or more processors, are configurable to further cause the one or more processors to:
 publish the data to a dashboard user interface; and   publish the data to an incident database.

Join the waitlist — get patent alerts

Track US2021089649A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.