Agent Technology System for Event Clustering and Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for managing and organizing vast amounts of digital communication, such as email and network traffic, face challenges in efficiently clustering events and detecting anomalies, particularly due to the high volume of spam and the dynamic nature of spam corpus, which leads to inefficiencies in resource allocation and productivity.
Innovation Solution
An agent technology system with a statistical analytical engine and monitoring policy that clusters events by determining common characteristics and producing clusters related to failures or errors in managed infrastructure, using techniques like Shannon entropy, NMF decomposition, and k-means clustering to identify actionable problems and generate alerts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If traditional folder-based systems are used to organize digital communications, then information can be stored in a structured manner, but retrieval efficiency deteriorates due to the vast amount of information and lack of automated indexing
Solution Approach 1:
The system automatically indexes and organizes digital communications without requiring manual user intervention. Agents autonomously monitor infrastructure, extract relevant information, and create organized clusters of events, allowing the system to serve itself rather than requiring continuous human management of directories and indexes.
Solution Approach 2:
The patent replaces manual mechanical processes of creating and maintaining directories with automated computational processes. Statistical analytical engines and machine learning algorithms automatically analyze communications, identify patterns, and organize information, substituting human cognitive and manual work with automated computational systems.
2Productivity
If manual organization of digital communications is performed, then information can be categorized by topic, but productivity deteriorates due to the time-consuming nature of sorting through hundreds of messages daily
Solution Approach 1:
The system performs automatic event clustering and organization without requiring user time investment. Agents continuously monitor and process communications in the background, automatically sorting and grouping messages by relevance and topic, freeing users from time-consuming manual organization tasks.
Solution Approach 2:
The system performs organization and clustering actions in advance before users need to retrieve information. Events are pre-processed, pre-clustered, and pre-indexed as they occur, so that when users need information, it is already organized and ready for rapid retrieval without requiring prior user effort.
3Reliability
If automated event clustering is implemented, then anomaly detection capability is improved, but system complexity increases due to the need for statistical analytical engines and monitoring policies
Solution Approach 1:
The system divides the complex anomaly detection task into separate functional agents with specialized responsibilities. Different agents handle different aspects such as event monitoring, statistical analysis, pattern recognition, and alert generation, allowing each component to be optimized independently while working together to achieve reliable anomaly detection.
Solution Approach 2:
The statistical analytical engine serves multiple functions including event clustering, anomaly detection, pattern recognition, and predictive analysis. This multi-functional approach consolidates what could be separate complex systems into a single versatile platform, managing complexity through functional integration rather than proliferation of separate components.
4Productivity
If high-volume digital communications are processed manually, then all messages can be reviewed, but resource allocation efficiency deteriorates due to the overwhelming volume of spam and legitimate messages
Solution Approach 1:
The system extracts and separates spam from legitimate communications using automated filtering and classification. By identifying and removing harmful or irrelevant messages early in the processing pipeline, the system reduces the volume of data requiring intensive analysis, optimizing resource allocation by focusing computational energy only on relevant communications.
Solution Approach 2:
The system applies different levels of analysis to different messages based on their importance and characteristics. High-priority or suspicious messages receive intensive scrutiny with full analytical resources, while clearly legitimate or low-priority messages receive minimal processing. This selective approach ensures adequate coverage without uniformly expending excessive resources on all messages.
Data Source
AI summary
A system is provided for clustering events. A first engine is configured to receive message data from a managed infrastructure that includes managed infrastructure physical hardware that supports the flow and processing of information, The at least one engine is configured to determine common characteristics of events and produce clusters of events relating to the failure of errors in the managed infrastructure. Membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in a physical hardware of the managed infrastructure directed to supporting the flow and processing of information. The first engine is configured to create one or more situations that is a collection of one or more events or alerts representative of the actionable problem in the managed infrastructure. A second engine is configured to determine one or more common steps from events and produces clusters relating to events. The second engine determines one or more common characteristics of events and producing clusters of events relating to the failure or errors in the managed infrastructure. A statistical analytical engine is included.


