Agent Technology System for Event Clustering and Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing and organizing vast amounts of digital communication, such as email and network traffic, face challenges in efficiently clustering events and detecting anomalies, particularly due to the high volume of spam and the dynamic nature of spam corpus, which leads to inefficiencies in resource allocation and productivity.

Innovation Solution

An agent technology system with a statistical analytical engine and monitoring policy that clusters events by determining common characteristics and producing clusters related to failures or errors in managed infrastructure, using techniques like Shannon entropy, NMF decomposition, and k-means clustering to identify actionable problems and generate alerts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If traditional folder-based systems are used to organize digital communications, then information can be stored in a structured manner, but retrieval efficiency deteriorates due to the vast amount of information and lack of automated indexing

Engineering Contradiction:
Improveinformation retrieval efficiencyVSAvoidmanual directory creation complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system automatically indexes and organizes digital communications without requiring manual user intervention. Agents autonomously monitor infrastructure, extract relevant information, and create organized clusters of events, allowing the system to serve itself rather than requiring continuous human management of directories and indexes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical processes of creating and maintaining directories with automated computational processes. Statistical analytical engines and machine learning algorithms automatically analyze communications, identify patterns, and organize information, substituting human cognitive and manual work with automated computational systems.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If manual organization of digital communications is performed, then information can be categorized by topic, but productivity deteriorates due to the time-consuming nature of sorting through hundreds of messages daily

Engineering Contradiction:
Improvemessage sorting efficiencyVSAvoidtime spent on message organization
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs automatic event clustering and organization without requiring user time investment. Agents continuously monitor and process communications in the background, automatically sorting and grouping messages by relevance and topic, freeing users from time-consuming manual organization tasks.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs organization and clustering actions in advance before users need to retrieve information. Events are pre-processed, pre-clustered, and pre-indexed as they occur, so that when users need information, it is already organized and ready for rapid retrieval without requiring prior user effort.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If automated event clustering is implemented, then anomaly detection capability is improved, but system complexity increases due to the need for statistical analytical engines and monitoring policies

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the complex anomaly detection task into separate functional agents with specialized responsibilities. Different agents handle different aspects such as event monitoring, statistical analysis, pattern recognition, and alert generation, allowing each component to be optimized independently while working together to achieve reliable anomaly detection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The statistical analytical engine serves multiple functions including event clustering, anomaly detection, pattern recognition, and predictive analysis. This multi-functional approach consolidates what could be separate complex systems into a single versatile platform, managing complexity through functional integration rather than proliferation of separate components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If high-volume digital communications are processed manually, then all messages can be reviewed, but resource allocation efficiency deteriorates due to the overwhelming volume of spam and legitimate messages

Engineering Contradiction:
Improvemessage processing throughputVSAvoidcomputational resources consumed
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The system extracts and separates spam from legitimate communications using automated filtering and classification. By identifying and removing harmful or irrelevant messages early in the processing pipeline, the system reduces the volume of data requiring intensive analysis, optimizing resource allocation by focusing computational energy only on relevant communications.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies different levels of analysis to different messages based on their importance and characteristics. High-priority or suspicious messages receive intensive scrutiny with full analytical resources, while clearly legitimate or low-priority messages receive minimal processing. This selective approach ensures adequate coverage without uniformly expending excessive resources on all messages.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10979304B2Agent technology system with monitoring policy
Publication Date: 2021.04.13 DELL PROD LP
  • US10979304B2 patent drawing
  • US10979304B2 patent drawing
  • US10979304B2 patent drawing

AI summary

A system is provided for clustering events. A first engine is configured to receive message data from a managed infrastructure that includes managed infrastructure physical hardware that supports the flow and processing of information, The at least one engine is configured to determine common characteristics of events and produce clusters of events relating to the failure of errors in the managed infrastructure. Membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in a physical hardware of the managed infrastructure directed to supporting the flow and processing of information. The first engine is configured to create one or more situations that is a collection of one or more events or alerts representative of the actionable problem in the managed infrastructure. A second engine is configured to determine one or more common steps from events and produces clusters relating to events. The second engine determines one or more common characteristics of events and producing clusters of events relating to the failure or errors in the managed infrastructure. A statistical analytical engine is included.