The present invention relates to an agreement breach prediction system, an agreement breach prediction method and an agreement breach prediction program.
Service level agreements (hereafter, “SLAs”) that are concluded between customers and service providers such as ISPs, ASPs, SaaS providers and the like, have attracted attention in recent years. For instance, SLAs are agreements that guarantee, for example, the quality of a service that is provided to a customer by a service provider; for instance, the response time of the service does not exceed 3 seconds according to the agreements. It is important for service providers that have entered into SLAs to detect the occurrence of SLA breaches in advance, and deal with the breaches before they occur. Non-Patent Document 1 below (first chapter) discloses a technology for predicting the occurrence of SLA breaches.
In Non-Patent Document 1, there is calculated a probability Pr(x|Pi) of an SLA breach within a certain period of time, upon occurrence of an event Pi, on the basis of the number of times that an SLA breach occurs within a certain period of time after the occurrence of a given event Pi, and the occurrence of an SLA breach is predicted using that probability. If SLA breaches that occur within a certain period of time are few, the calculated probability Pr(x|Pi) in this method fluctuates significantly, and prediction accuracy decreases when SLA breaches increase or decrease by just one breach. In a conventional simple Bayesian filter, events are handled as discrete values, and the occurrence of an SLA breach is predicted on the basis of whether a threshold value is exceeded or not. Therefore, this precludes continuous handling of parameter values that denote service quality, and finely-tuned prediction of the occurrence of SLA breaches on the basis of breach probabilities that are dissimilar for each parameter value.
In order to solve the above-described problems, it is an object of the present invention to provide an agreement breach prediction system, an agreement breach prediction method and an agreement breach prediction program in which the prediction accuracy of service level agreement breaches can be improved.
The agreement breach prediction system of the present invention comprises a probability distribution calculation unit that, for each of events that occur in a target system of a service level agreement, calculates a probability distribution of a measured value of a service item included in the service level agreement, on the basis of event information relating to the event and of measured value information relating to the measured value; a probability calculation unit that refers to the probability distribution calculated by the probability distribution calculation unit and to an agreement threshold value of the service item, and that calculates, for each of the events, a probability that applies to a service level agreement breach and a probability that does not apply to the service level agreement breach; a probability density calculation unit that refers to the measured value information, and calculates a probability density of the measured value that applies to the service level agreement breach during a period of time from event occurrence until a predefined time has elapsed, and a probability density of the measured value that does not apply to the service level agreement breach during the period of time from the event occurrence until the predefined time has elapsed; and a breach occurrence probability calculation unit that, when the event occurs, calculates a probability that the agreement breach occurs within the predefined time after the occurrence of the event, by using the respective probabilities corresponding to the event and the respective probability densities corresponding to the measured values at a time of occurrence of the event.
The agreement breach prediction method of the present invention comprises a probability distribution calculation step of, for each of events that occur in a target system of a service level agreement, calculating a probability distribution of a measured value of a service item included in the service level agreement, on the basis of event information relating to the event and of measured value information relating to the measured value; a probability calculation step of referring to the probability distribution calculated in the probability distribution calculation step and to an agreement threshold value of the service item, and calculating, for each of the events, a probability that applies to a service level agreement breach and a probability that does not apply to the service level agreement breach; a probability density calculation step of referring to the measured value information, and calculating a probability density of the measured value that applies to the service level agreement breach during a period of time from event occurrence until a predefined time has elapsed, and a probability density of the measured value that does not apply to the service level agreement breach during the period of time from the event occurrence until the predefined time has elapsed; and a breach occurrence probability calculation step of, when the event occurs, calculating a probability that the agreement breach occurs within the predefined time after the occurrence of the event, by using the respective probabilities corresponding to the event and the respective probability densities corresponding to the measured values at a time of occurrence of the event.
The agreement breach prediction program of the present invention causes a computer to execute each step included in the abovementioned agreement breach prediction method.
The present invention allows enhancing prediction accuracy of service level agreement breaches.
Appropriate embodiments of the agreement breach prediction system, agreement breach prediction method and agreement breach prediction program according to the present invention are explained next with reference to accompanying drawings.
First Embodiment
The configuration of an agreement breach prediction system in a first embodiment will be explained first with reference to
The agreement breach prediction system 1 is physically made up of, for instance, a CPU (Central Processing Unit), a memory, an input-output interface, and a display. The memory includes, for instance, a ROM (Read Only Memory) and HDD (Hard Disk Drive) that store programs and data processed by the CPU, and a RAM (Random Access Memory) that is mainly used as a work area for control processing. These elements are connected to each other by way of a bus. The CPU executes a program that is stored in the ROM, processes messages received via the input-output interface, and processes data deployed in the RAM, to realize as a result the various below-described functions of the agreement breach prediction system 1.
The monitor unit 10, which monitors the state of a system to be managed 90, generates various logs, for instance, a learning event log L1, a learning SLA log L2, an inspection object event log L3 and an inspection object SLA log L4. The system to be managed 90 is a system that is used by the service provider to provide a service to a customer, and is the system to which the SLA applies. The monitor unit 10 outputs log information every certain period of time (for instance, every 10 seconds).
The learning event log L1 and the inspection object event log L3 are logs that record event information relating to an event that the system to be managed 90 executes.
The learning SLA log L2 and the inspection object SLA log L4 are logs that record SLA measured value information relating to a measured value of an SLA service item at the time of event occurrence. Herein, an SLA service item denotes a service item included in the SLA, for instance response time.
The learning event log L1 and the learning SLA log L2 are logs for analysis and learning that are used for generating beforehand a probability distribution table L6 and an SLA probability distribution table L9 to be referred to upon prediction of the occurrence of an SLA breach. The inspection object event log L3 and the inspection object SLA log L4 are logs for feeding, to the agreement breach prediction system 1, events to be inspected and SLA measured values, upon prediction of the occurrence of an SLA breach.
The SLA breach probability computation unit 20 illustrated in
The probability distribution calculation unit 21 refers to the learning event log L1, the learning SLA log L2 and the event category list L5, calculates a probability distribution of a measured value of an SLA service item at the time of event occurrence as recorded in the learning SLA log L2, for each event recorded in the learning event log L1, and stores the result in the probability distribution table L6. A normal distribution is used as the probability distribution in the present embodiment. The probability distribution calculation unit 21 calculates, as the probability distribution, a mean value and unbiased variance that allow uniquely identifying a normal distribution.
The event category list L5 is a list for determining the event category to which each event belongs.
The probability distribution table L6 stores, for each event, a mean value and an unbiased variance that define a normal distribution.
An explanation follows next on a procedure for the calculation of the normal distribution of an event Pi by the probability distribution calculation unit 21. The probability distribution calculation unit 21 refers to the learning event log L1 and the learning SLA log L2, works then out, for each time t at which the event Pi occurs, a worst value pworst(t) of the SLA measured value p that is measured during the period of time from a time t at which the event Pi occurs until δt seconds (predefined time) have elapsed therefrom, and calculates a mean value E and an unbiased variance V of the worst value pworst(t).
For instance, a mean value E(pworst|Pi) and an unbiased variance V(pworst|Pi) of the worst value pworst(t) at t1, . . . tn points in time where the event Pi occurs can be calculated as follows.
E(pworst|Pi)=(1/n)Σjpworst(tj) (1)
V(pworst|Pi)=(1/n)Σj{pworst(tj)−E(pworst|Pi)}2 (2)
The square root of the unbiased variance V is the deviation σ, and hence the normal distribution N{E(pworst|Pi), σ(pworst|Pi)} of the event Pi is uniquely determined. The “total” normal distribution N is N{E(pworst), σ(pworst)}.
The probability calculation unit 22 illustrated in
The SLA list L7 stores, for each SLA service item, a threshold value that constitutes an agreement condition of the SLA service item. In a case where, for instance, the SLA states that the response time of the service should not exceed 8 seconds, then 8 seconds, which is the agreement threshold value, is stored in the SLA list L7 mapped to information that identifies the response time, which is the SLA service item.
The breach probability table L8 stores probabilities relating to SLA breaches.
The procedure according to which the probability calculation unit 22 calculates the above-described probabilities is explained next. The probability calculation unit 22 calculates in the manner described further on, a probability distribution that is specified on the basis of the probability distribution table L6, a non-breach probability Pr(O) and a breach probability Pr(x) for the entire system, and a non-breach probability Pr(O|Pi) and a breach probability Pr(x|Pi) for each event Pi using an agreement threshold value v0, of the SLA list L7. The probability distribution at the time of occurrence of the event Pi is N(Ei, σi).
Pr(O)=Pr{pworst<v0|N(E,σ)) (3)
Pr(x)=Pr{pworst≧v0|N(E,σ)) (4)
Pr(O|Pi)=Pr{pworst<v0|N(Ei,σ)) (5)
Pr(x|Pi)=Pr{pworst≧v0|N(Ei,σ)) (6)
The probability calculation unit 22 calculates Pr(Pi|O) and Pr(Pi|x) using Pr(O|Pi) and Pr(x|Pi) calculated in Expression (5) and Expression (6), in the manner described below.
Pr(Pi|O)={Pr(O|Pi)×NPi}/{Pr(O)×Nall} (7)
Pr(Pi|x)={Pr(x|Pi)×NPi}/{Pr(x)×Nall} (7)
In Expression (7) and Expression (8), NPi is the number of times that the event Pi occurs, and Nall is the number of occurrences of all events.
The probability calculation unit 22 stores, in the breach probability table L8, the Pr(O), Pr(x), Pr(Pi|O) and Pr(Pi|x) calculated according to Expression (3), Expression (4), Expression (7) and Expression (8) above.
A specific example of the probabilities as calculated by the probability calculation unit 22 is explained next with reference to
[Expression 1]
Pr(x|a)=∫8∞f(a)dp (9)
The breach probability Pr(x|a) of event a illustrated in
Since that the number of occurrences of the event a is 41, the expected value of the number of number of breaches of the event a is 41×Pr(x|a)=41×0.21=8.56 times. The expected value of the number of breach occurrences in the entire system is 229×Pr(x)=229×0.21=48.19 times, since the number of event occurrences for the entire system is 229. Accordingly, there holds Pr(a|x)=8.56/48.19=0.17. Likewise, there holds Pr(a|O)=32.44/179.80=0.18.
The SLA distribution calculation unit 23 illustrated in
The SLA probability distribution table L9 stores the mean value and the unbiased variance that specify the normal distribution of an SLA measured value for instances that apply to an SLA breach, and for instances that do not apply to an SLA breach, during a period of time from event occurrence until δt seconds have elapsed.
An explanation follows next on the procedure according to which the SLA distribution calculation unit 23 calculates the mean value and the unbiased variance, which are a normal distribution. For instance, a mean value EO and an unbiased variance VO of the SLA measured value p(t) can be calculated as described below, wherein points in time at which no SLA breach occurs until δt seconds have elapsed are t1, . . . , tn, and p(t) is the SLA measured value.
EO=(1/n)Σjp(tj) (10)
VO=(1/n)Σj{p(tj)−E}2 (11)
The square root of the unbiased variance VO yields a deviation σO Therefore, a normal distribution N{EO, σO} is uniquely determined, and a probability density f(p|O) is likewise uniquely determined. A normal distribution N{Ex, σx} and a probability density f(p|x) can be calculated in the same manner.
The breach occurrence probability calculation unit 24 illustrated in
The event probability retrieval unit 241 detects, on the basis of the breach probability table L8, various probabilities corresponding to the events included in the inspection object event log L3. In a case where, for instance, event Pi and event Pj occur simultaneously, the event probability retrieval unit 241 detects Pr(Pi|O), Pr(Pj|O), Pr(O), Pr(Pi|x), Pr(Pj|x) and Pr(x) from the breach probability table L8.
The SLA probability calculation unit 242 reads a value v of the SLA measured value p(t) at a current point in time t, from the inspection object SLA log L4, and calculates probability densities f(p(t)=v|O) and f(p(t)=v|x) by referring to the SLA probability distribution table L9. Specifically, for instance, in the case of the SLA probability distribution table L9 illustrated in
The compound probability integrating unit 243 calculates a probability Pr(x|p(t)=v,P) of an SLA breach at a time where the value of the SLA measured value p(t) at the current time t is v, and one or a plurality of events P occurs, using the various probabilities detected by the event probability retrieval unit 241 and the probability densities calculated by the SLA probability calculation unit 242.
In a case where, for instance, there occur the event Pi, the event Pj, and an event for which the value of the SLA measured value p(t) falls between v to v+δv (for instance, event p), then an SLA breach probability Pr(x|Pi, Pj, p) can be calculated as described below, according to the known Bayes' theorem and lim_(δv−>0)Pr(p)/δv=f(p).
Expression (12) is an expression where both event Pi and event Pj occur; however, the portions “Pj” may be omitted from the various terms in Expression (12), in cases where, for instance, only the event Pi occurs.
Specifically, in a case where, for instance, event a and event b occur within 5 minutes, which is a given time interval, and the value of the SLA measured value p(t) at that time is “6”, then there is worked out a probability Pr(x|Pa, Pb, p=6) of an SLA breach within 5 minutes. The computation in this case can be carried out as described below using Expression (12).
Herein, Pr(Pa|x)=“0.17”, Pr(Pb|x)=“0.24”, f(p=6|x)=“0.0158”, Pr(x)=“0.21”, Pr(Pa|O)=“0.18”, Pr(Pb|O)=“0.26”, f(p=6|O)=“0.0769” and Pr(O)=“0.79”, as examples of the numerical values of the breach probability table L8 of
The present embodiment assumes the following premises.
Premise 1: pr(x|P1, . . . , Pn) are identical regardless of time t.
Premise 2: events P1, . . . , Pn are stochastically independent, in conditional probability having SLA breach negative (O) or SLA breach affirmative (x) as a condition. Accordingly, there hold Pr(Pm, Pn|O)=Pr(Pm|O)Pr(Pn|O) and Pr(Pm, Pn|x)=Pr(Pm|x)Pr(Pn|x).
Premise 3: the probability density of the value of SLA measured value p(t) obeys a specific probability distribution, and the type of the probability distribution (for instance, normal distribution) is known beforehand. In a simple Bayesian filter, as is known, premise 2 often holds approximately.
Premise 4: the event Pi, and presence of the value of the SLA measured value p(t) from v to δv, are stochastically independent, in conditional probability having SLA breach negative (O) or SLA breach affirmative (x) as a condition. Accordingly, there hold Pr(Pi, v≦p(t)<v+δt|O)=Pr(Pi|O)Pr(v≦p(t)<v+δt|O) and Pr(Pi, v≦p(t)<v+δ|x)=Pr(Pi|x)Pr(v≧p(t)<v+δt|x).
Premise 5: the probability density of the value of the SLA measured value p(t) obeys a specific probability distribution, and the type of the probability distribution (for instance, normal distribution), is known beforehand, in conditional probability having SLA breach negative (O) or SLA breach affirmative (x) as a condition.
The operation of the agreement breach prediction system 1 of the first embodiment will be explained next with reference to
Firstly, the probability distribution calculation unit 21 refers to the learning event log L1, the learning SLA log L2 and the event category list L5, and for each event recorded in the learning event log L1, calculates a probability distribution of the measured value of the SLA service item that is recorded in the learning SLA log L2, and stores the result in the probability distribution table L6 (step S101).
Next, the probability calculation unit 22 refers to the probability distribution table L6 and the SLA list L7 updated in step S101, and, for each event, calculates a probability that applies to an SLA breach, and a probability that does not apply to an SLA breach, and stores the results in the breach probability table L8 (step S102).
The SLA distribution calculation unit 23 refers to the learning SLA log L2, calculates a probability distribution corresponding to an SLA measured value that applies to an SLA breach, during a period of time from event occurrence until δt seconds have elapsed, and a probability distribution corresponding to an SLA measured value that does not apply to an SLA breach, during a period of time from event occurrence until δt seconds have elapsed, and stores the results in the SLA probability distribution table L9 (step S103).
The process in step S101 and step S102 may be executed in parallel to the process of step S103, or any one of the processes may be executed first, and the other processes thereafter. The processes from step S101 to step S103 are preparatory processes that are executed before operation of the system. The processes from step S104 onwards are operation processes that are carried out during operation of the system.
Next, during system operation, the event probability retrieval unit 241 detects, on the basis of the breach probability table L8, various probabilities corresponding to the events included in the inspection object event log L3 (step S104).
The SLA probability calculation unit 242 reads a value v of the SLA measured value p(t) at a current time t, from the inspection object SLA log L4, and calculates the probability densities f(p(t)=v|O) and f(p(t)=v|x) by referring to the SLA probability distribution table L9 (step S105).
Herein, the process in step S104 and the process in step S105 may be executed in parallel, or any one of the processes may be executed first, and the other process thereafter.
Next, the compound probability integrating unit 243 calculates the probability Pr(x|p(t)=v,P) of an SLA breach at a time where the value of the SLA measured value p(t) is v at the current time t, and one or a plurality of events P occurs, using the various probabilities detected in step S104 and the probability densities calculated in step S105 (step S106).
Next, the display unit 30 displays the probability of SLA breach, as calculated in step S106, on a display (step S107).
In the agreement breach prediction system 1 of the first embodiment, as described above, a probability distribution, calculated on the basis of data that is stored in the learning event log L1 and the learning SLA log L2, is stored in a probability distribution table, and the probability of an SLA breach can be predicted on the basis of this probability distribution table. The accuracy of prediction can be enhanced as a result.
A probability distribution of whether or not an SLA breach occurs over a period of time since occurrence of an event until δt seconds have elapsed therefrom, is stored in an SLA probability distribution table, and the probability of an SLA breach within δt seconds can be predicted, using a current SLA measured value as a criterion, on the basis of the SLA probability distribution table. Therefore, predictions can be performed with yet higher accuracy.
Second Embodiment
An explanation follows next on a second embodiment of the present invention. The agreement breach prediction system 1 in a second embodiment illustrated in
The testing unit 40 tests, for each event, whether the probability distribution calculated by the probability distribution calculation unit 21 and the probability distribution calculated by the SLA distribution calculation unit 23 are normal distributions or not. For instance, a known chi-squared test can be used as the test method. Specifically, the testing unit 40 calculates a significance probability of the probability distributions to be tested, and if the calculated significance probability is greater than a hazard ratio (for instance, 0.05) set in the hazard ratio list L10, then the probability distribution is determined to be a normal distribution.
The testing unit 40 sets, as input targets for the probability distribution calculation unit 21 and the SLA distribution calculation unit 23, only those events corresponding to a probability distribution that has been tested to be a normal distribution. Specifically, the testing unit 40 establishes a use flag at a record of the event category list L5 corresponding to the event that has been tested to be of normal distribution. The probability distribution calculation unit 21 and the SLA distribution calculation unit 23 set, as process targets, only those events for which a use flag is established in the event category list L5. As a result, there can be set, as input targets of the probability distribution calculation unit 21 and the SLA distribution calculation unit 23, only those events corresponding to a probability distribution that has been tested to be a normal distribution.
The operation of the agreement breach prediction system 1 of the second embodiment will be explained next with reference to
Firstly, the testing unit 40 tests, for each event, whether the probability distributions calculated by the probability distribution calculation unit 21 and the probability distributions calculated by the SLA distribution calculation unit 23 are normal distributions or not (step S201).
Next, the testing unit 40 determines whether or not there exists an event that corresponds to a probability distribution that has been tested to be a normal distribution (step S202). If the determination is NO (step S202; NO), the process is terminated.
If in the determination of step S202 it is determined that an event exists that corresponds to the probability distribution that is tested to be a normal distribution (step S202; YES), then the process from the above-described step S101 (
As described above, the agreement breach prediction system 1 of the second embodiment can check whether a relationship between events in the system to be managed 90 and SLA measured values, and a relationship between an SLA measured value and a worst value of the SLA measured value within δt seconds, are as expected or not. Noise can be eliminated, and the prediction accuracy of SLA breaches can be enhanced by excluding thus unexpected events.
Third Embodiment
An explanation follows next on a third embodiment of the present invention. The agreement breach prediction system 1 of the third embodiment illustrated in
The correlation analysis unit 50 calculates a degree of correlation between events, as follows. Firstly, the correlation analysis unit 50 calculates a vector of the occurrence of each event. In the case, for instance, of the event Pi, a vector of the occurrence of event Pi is PO,i=(Pi(tO,1), . . . , Pi(tO,n)) where tO,1, . . . , tO,n are the points in time by which an SLA breach has not occurred until δt seconds have elapsed. Herein, Pi(ti) is 1 in a case where the event Pi has occurred, and 0 in a case where the event Pi has not occurred.
Specifically, the correlation analysis unit 50 uses the learning event log L1 and the learning SLA log L2 as inputs, and every 5 minutes, generates an SLA measured value, a worst value of the SLA measured value in 5 minutes, and information on events occurred in 5 minutes, as in the table illustrated in
Next, the correlation analysis unit 50 calculates respective correlation coefficients k between events. Herein, Pearson's product-moment correlation coefficients can for instance be used as the correlation coefficients k. In this case, the correlation coefficients are worked out by calculating ki,j=(Pi−ki*n)·(Pj−kj*n)/|Pi−ki*n∥Pj−kj*n|. The correlation analysis unit 50, for instance, calculates kOi-j=PO,i·PO,i/∥PO,i∥PO,i| and kxi-j=Px,i·Px,i∥Px,i| as the correlation coefficients ki-j of Pi and Pj. Herein, Pi·Pi is the inner product, and |Pi| is the vector length. In
Next, the correlation analysis unit 50 calculates a vector δp=(δp(t1), . . . , δp(tn) of δp(t)=pworst(t)−p(t) represented by the difference between an SLA measured value p(t) at time t and the worst value pworst(t) of the SLA measured value in the period from time t up to δt.
Next, the correlation analysis unit 50 calculates correlation coefficients ki,δp between respective events Pi and δp(t). The Pearson's product-moment correlation coefficient can for instance be used as the correlation coefficient. In such a case, the correlation coefficients can be worked out by calculating ki,δp=(Pi−ki*n)·(δp−kδp*n)/|Pi−ki*n∥δp−kδp*n|. Herein, n is (1, 1, . . . , 1), k, is the mean value (1/n)Σjci,j of Pi=(ci,1, ci,2, . . . . , ci,n), and kδp is the mean value (1/n)Σjdi,j1 of δp=(d1, d2, . . . , dn). In
The event category filter unit 51 illustrated in
The event category filter unit 51 refers to the correlation schedule L11 illustrated in
The event category filter unit 51 outputs, for instance, the event category list L5 illustrated in
The operation of the agreement breach prediction system 1 of the third embodiment will be explained next with reference to
Firstly, the correlation analysis unit 50 calculates correlation coefficients between δp(t) and the events that have occurred in the system to be managed 90, and stores the results in the correlation schedule L11 (step S301).
Next, the correlation analysis unit 50 calculates correlation coefficients between respective events that have occurred in the system to be managed 90, and stores the results in the correlation schedule L11 (step S302).
Next, the event category filter unit 51 rules out, from candidates in the event category list, those events for which interconnectedness with δp(t) is smaller than a first predefined threshold value (for instance, 0.005) (step S303).
Next, the event category filter unit 51 rules out, from the candidates in the event category list, events having low interconnectedness with δp(t), from among events for which the interconnectedness between events exceeds a second predefined threshold value (for instance, 0.5) (step S304).
Next, the event category filter unit 51 outputs the event category list L5 (step S305).
Next, the SLA breach probability computation unit 20 determines whether or not an event exists for which a use flag is established in the event category list L5 (step S306). If the determination is NO (step S306; NO), the process is terminated.
By contrast, if in step S306 it is determined that an event exists for which a use flag is established (step S306; YES), then the process from the above-described step S101 (
As described above, the device 1 of the third embodiment allows ruling out events having low interconnectedness with δp(t), and allows predicting SLA breaches by targeting only events having high interconnectedness with δp(t). Events that do not influence service quality can be ruled out thereby, and hence the prediction accuracy of SLA breaches can be enhanced.
Also, it becomes possible to rule out one of the events from among events having high interconnectedness between events. The present invention assumes that event occurrences are stochastically independent. Therefore, prediction accuracy of SLA breaches can be enhanced by ruling out one of the events in a case where there exist events of high stochastic dependence.
Variations
The above-described embodiments are merely exemplary in nature, and do not exclude various modifications and technical applications that have not been explicitly set forth in the embodiments. That is, the present invention can be carried out in the form of all manner of embodiment variations without departing from the scope of the invention.
For instance, part or the entirety of the above embodiments can be described according to the appendices set forth below, but the present invention is not limited thereto.
(Supplementary note 1) An agreement breach prediction system, comprising: a probability distribution calculation unit that, for each of events that occur in a target system of a service level agreement, calculates a probability distribution of a measured value of a service item included in the service level agreement, on the basis of event information relating to the event and of measured value information relating to the measured value; a probability calculation unit that refers to the probability distribution calculated by the probability distribution calculation unit and to an agreement threshold value of the service item, and that calculates, for each of the events, a probability that applies to a service level agreement breach and a probability that does not apply to the service level agreement breach; a probability density calculation unit that refers to the measured value information, and calculates a probability density of the measured value that applies to the service level agreement breach during a period of time from event occurrence until a predefined time has elapsed, and a probability density of the measured value that does not apply to the service level agreement breach during the period of time from the event occurrence until the predefined time has elapsed; and a breach occurrence probability calculation unit that, when the event occurs, calculates a probability that the agreement breach occurs within the predefined time after the occurrence of the event, by using the respective probabilities corresponding to the event and the respective probability densities corresponding to the measured values at a time of occurrence of the event.
(Supplementary note 2) The agreement breach prediction system according to Supplementary note 1, further comprising a testing unit that tests whether the probability distribution calculated by the probability distribution calculation unit is a predefined distribution or not, wherein the probability distribution calculation unit calculates the probability distribution on the basis of the measured value information and the event information corresponding to the probability distribution having been determined to be the predefined distribution by the testing unit.
(Supplementary note 3) The agreement breach prediction system according to Supplementary note 1 or 2, further comprising: a correlation coefficient calculation unit that refers to the measured value information, and calculates, for each of the events, a first correlation coefficient between a measured value at the time of occurrence of the event and a change value of the measured value in a period of time from occurrence of the event until a predefined time has elapsed; and a filter unit that excludes, from targets of the event information, the event for which the first correlation coefficient calculated by the correlation coefficient calculation unit is smaller than a predefined threshold value.
(Supplementary note 4) The agreement breach prediction system according to Supplementary note 3, further comprising: a second correlation coefficient calculation unit that refers to the event information and calculates a second correlation coefficient between the respective events; and a second filter unit that excludes, from the targets of the event information, the event for which the first correlation coefficient calculated by the correlation coefficient calculation unit is the smaller, from among the two events corresponding to the second correlation coefficient, in a case where the second correlation coefficient calculated by the second correlation coefficient calculation unit is greater than a second predefined threshold value.
(Supplementary note 5) The agreement breach prediction system according to any one of Appendices 1 to 4, wherein the probability distribution is a normal distribution.
(Supplementary note 6) An agreement breach prediction method, comprising: a probability distribution calculation step of, for each of events that occur in a target system of a service level agreement, calculating a probability distribution of a measured value of a service item included in the service level agreement, on the basis of event information relating to the event and of measured value information relating to the measured value; a probability calculation step of referring to the probability distribution calculated in the probability distribution calculation step and to an agreement threshold value of the service item, and calculating, for each of the events, a probability that applies to a service level agreement breach and a probability that does not apply to the service level agreement breach; a probability density calculation step of referring to the measured value information, and calculating a probability density of the measured value that applies to the service level agreement breach during a period of time from event occurrence until a predefined time has elapsed, and a probability density of the measured value that does not apply to the service level agreement breach during the period of time from the event occurrence until the predefined time has elapsed; and a breach occurrence probability calculation step of, when the event occurs, calculating a probability that the agreement breach occurs within the predefined time after the occurrence of the event, by using the respective probabilities corresponding to the event and the respective probability densities corresponding to the measured values at a time of occurrence of the event.
(Supplementary note 7) An agreement breach prediction program for causing a computer to execute each step described in Supplementary note 6.
The present application claims priority on the basis of Japanese Patent Application No. 2010-132300, filed on Jun. 9, 2010, the entire content whereof is incorporated herein by reference.
The agreement breach prediction system, agreement breach prediction method and agreement breach prediction program according to the present invention are appropriate for improving the prediction accuracy of service level agreement breaches.
1 . . . agreement breach prediction system; 10 . . . monitor unit; 20 . . . SLA breach probability computation unit; 21 . . . probability distribution calculation unit; 22 . . . probability calculation unit; 23 . . . SLA distribution calculation unit; 24 . . . breach occurrence probability calculation unit; 241 . . . event probability retrieval unit; 242 . . . SLA probability calculation unit; 243 . . . compound probability integrating unit; 30 . . . display unit; 40 . . . testing unit; 50 . . . correlation analysis unit; 51 . . . event category filter unit; 90 . . . system to be managed; L1 . . . learning event log; L2 . . . learning SLA log; L3 . . . inspection object event log; L4 . . . inspection object SLA log; L5 . . . event category list; L6 . . . probability distribution table; L7 . . . SLA list; L8 . . . breach probability table; L9 . . . SLA probability distribution table; L10 . . . hazard ratio list; L11 . . . correlation schedule.
Number | Date | Country | Kind |
---|---|---|---|
2010-132300 | Jun 2010 | JP | national |
Filing Document | Filing Date | Country | Kind | 371c Date |
---|---|---|---|---|
PCT/JP2011/061673 | 5/20/2011 | WO | 00 | 12/4/2012 |
Publishing Document | Publishing Date | Country | Kind |
---|---|---|---|
WO2011/155308 | 12/15/2011 | WO | A |
Number | Name | Date | Kind |
---|---|---|---|
5538897 | Yates, III | Jul 1996 | A |
5867494 | Krishnaswamy | Feb 1999 | A |
6321179 | Glance | Nov 2001 | B1 |
7006435 | Davies | Feb 2006 | B1 |
7145898 | Elliott | Dec 2006 | B1 |
7313533 | Chang et al. | Dec 2007 | B2 |
7546039 | Boroditsky | Jun 2009 | B1 |
7957413 | Childress et al. | Jun 2011 | B2 |
8041797 | Childress | Oct 2011 | B2 |
20030125888 | Yamaguchi | Jul 2003 | A1 |
20030200075 | Meng et al. | Oct 2003 | A1 |
20030200191 | Pao et al. | Oct 2003 | A1 |
20040019574 | Meng et al. | Jan 2004 | A1 |
20040136379 | Liao | Jul 2004 | A1 |
20040215430 | Huddleston et al. | Oct 2004 | A1 |
20040220900 | Yang et al. | Nov 2004 | A1 |
20040261044 | Yonezawa | Dec 2004 | A1 |
20050010456 | Chang et al. | Jan 2005 | A1 |
20050165925 | Dan | Jul 2005 | A1 |
20060149854 | Rudkin | Jul 2006 | A1 |
20060227810 | Childress et al. | Oct 2006 | A1 |
20070226228 | Her et al. | Sep 2007 | A1 |
20070239496 | Supatgiat | Oct 2007 | A1 |
20080097807 | Chang et al. | Apr 2008 | A1 |
20080098454 | Toh | Apr 2008 | A1 |
20080148225 | Sarkar | Jun 2008 | A1 |
20080228755 | Haga et al. | Sep 2008 | A1 |
20090076859 | Phillips | Mar 2009 | A1 |
20110161497 | Childress et al. | Jun 2011 | A1 |
20130080367 | Tonouchi | Mar 2013 | A1 |
Number | Date | Country |
---|---|---|
2003-150723 | May 2003 | JP |
2004-532445 | Oct 2004 | JP |
2005-523526 | Aug 2005 | JP |
2007-529048 | Oct 2007 | JP |
2008-519327 | Jun 2008 | JP |
2008-535113 | Aug 2008 | JP |
2008-225995 | Sep 2008 | JP |
WO 2009144780 | Dec 2009 | JP |
WO 2011155308 | Dec 2011 | JP |
WO 02067136 | Aug 2002 | WO |
WO 03090147 | Oct 2003 | WO |
WO 2005008402 | Jan 2005 | WO |
WO 2006010692 | Feb 2006 | WO |
WO 2006049584 | May 2006 | WO |
2006106142 | Oct 2006 | WO |
WO 2006106921 | Oct 2006 | WO |
WO 2009144780 | Dec 2009 | WO |
WO 2011155308 | Dec 2011 | WO |
Entry |
---|
Bartolini et al., “IT Service Management Driven by Business Objectives: An Application to Incident Management,” Proceedings, the 10th IEEE/IFIP Network Operations and Management Symposium, Apr. 3-7, 2006, Vancouver, Canada, 10 pages., 2006. |
Bartolini, et al, “IT service management driven by business objectives: an application to incident management,” HPL-2006-38, 2006. |
International Search Report, PCT/JP2011/061673, Jun. 28, 2011. |
P. Domingos/M. Pazzani co-authors “On the Optimality of the Simple Bayesian Classifier under Zero-One Loss”, Machine Learning, 29, pp. 103-130, 1997 Kluwer Academic Publishers, Manufactured in The Netherlands. |
Tsuyoshi Furukawa, “A Study of SLM functions about a VoIP service”, IEICE Technical Report, Dec. 10, 2001, vol. 101, No. 508, pp. 97 to 102. |
Sho Ishikawa, “Web site design using user model with Bayesian networks”, Proceedings of DBWeb2005, Nov. 21, 2005, vol. 2005, pp. 141 to 147. |
Number | Date | Country | |
---|---|---|---|
20130080367 A1 | Mar 2013 | US |