Alert Classification via Cluster Analysis and Frequent Pattern Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network monitoring systems are unable to generate appropriate classification rules based on communication information within alerts, leading to inadequate differentiation of alert importance levels.
Innovation Solution
An information processing device that includes a cluster analyzer to classify alerts, a rule generator to extract frequent patterns from communication information, and a rule applicator to update classification rules, ensuring accurate alert classification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If classification is performed only based on signature, IP address, and port number, then routine alerts can be classified automatically, but alerts with different importance levels cannot be differentiated
Solution Approach 1:
The patent segments the classification process into multiple stages: initial classification based on signature, IP address, and port number to identify routine alerts, followed by secondary classification based on communication information content to differentiate importance levels. This segmentation allows automatic classification of routine alerts while enabling precise differentiation of important alerts through additional analysis layers.
Solution Approach 2:
The patent adds a new dimension to the classification process by incorporating communication information content analysis alongside the traditional signature, IP address, and port number-based classification. This dimensional expansion enables the system to differentiate alert importance levels while maintaining automatic classification capabilities for routine alerts.
2Measurement precision
If all alerts are classified manually by operators, then accurate importance determination is achieved, but operator workload increases
Solution Approach 1:
The patent applies partial automation by automatically classifying routine alerts that match established patterns, while reserving manual classification for non-routine or high-importance alerts. This partial action approach maintains high accuracy for important alerts while significantly reducing operator workload by automating the classification of routine, low-importance alerts.
Solution Approach 2:
The system performs self-service by automatically analyzing communication information content and classifying alerts based on predefined importance criteria. This self-service capability handles routine classification tasks without operator intervention, freeing operators to focus on complex or high-priority alerts that require human judgment.
3Measurement precision
If communication information content is analyzed for all alerts, then accurate importance differentiation is achieved, but processing complexity increases
Solution Approach 1:
The patent segments the analysis process to apply communication information content analysis only to alerts that require importance differentiation, rather than analyzing all alerts uniformly. This selective segmentation reduces overall processing complexity while maintaining high classification accuracy for alerts where it matters most.
Solution Approach 2:
The system applies communication information analysis partially, focusing resources on alerts where such analysis provides value for importance differentiation. By avoiding unnecessary analysis of routine alerts that can be classified automatically, the system reduces processing complexity while maintaining accurate importance determination where needed.
Data Source
AI summary
An information processing device according to the present invention includes: a cluster analyzer that determines a cluster identifier indicating a cluster that is a result of classifying an alert, receives a classification result of the alert, and generates alert information that is information including the alert, the cluster identifier, and the classification result; a rule generator that calculates a number of occurrence times of a pattern that is a combination of information and includes the cluster identifier, extracts a frequent pattern, generates a classification rule used in setting of the classification result, and updates a previously generated old classification rule with a newly generated classification rule; and a rule applicator that sets the classification result included in the alert information.


