Alert Policy Segmentation for Network Incident Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for managing alerts in complex network computer systems are inefficient, leading to overwhelming numbers of alerts, misdirection of incidents, lack of flexibility in alert generation, and failure to account for the dynamic status of incidents, resulting in unnecessary alerts and reduced performance reliability.
Innovation Solution
The system programmatically generates responder alert data objects based on global and inline alert policy data objects, allowing organizations to define policies for alert generation and management through user interfaces, dynamically updating alerts based on incident status and reducing unnecessary alerts by associating alert policies with specific incidents.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional alert management systems are used to monitor complex network computer systems, then incidents can be detected, but overwhelming numbers of alerts are generated including unnecessary alerts
Solution Approach 1:
The patent segments alert policies into two distinct levels: global alert policies that apply organization-wide and inline alert policies that are specific to individual incidents. This segmentation allows for differentiated alert generation rules, enabling the system to suppress unnecessary alerts at the global level while maintaining specific alerting behavior at the inline level for critical incidents.
Solution Approach 2:
The patent implements local quality by allowing different alert generation behaviors for different incidents through inline alert policies. Each incident can have its own customized alert policy that overrides or supplements global policies, enabling precise control over which incidents generate alerts and which do not, thereby reducing unnecessary alerts while maintaining alert accuracy.
2Reliability
If traditional alert management systems are used, then alerts can be generated, but misdirection of incidents occurs
Solution Approach 1:
The patent applies preliminary action by pre-configuring both global alert policies and inline alert policies before incidents occur. These policies contain pre-defined routing rules and responder assignments that are automatically applied when incidents are detected, ensuring accurate incident direction without loss of contextual information about which policy should apply.
Solution Approach 2:
The patent implements feedback mechanisms where the system continuously evaluates incident data against both global and inline alert policies, determining which policy takes precedence based on incident characteristics. This feedback loop ensures that incidents are correctly directed to appropriate responders while maintaining full context about the routing decision.
3Adaptability or versatility
If traditional alert management systems are used, then alerts can be generated, but lack of flexibility in alert generation occurs
Solution Approach 1:
The patent applies dynamics by making alert policies adaptable and changeable at two levels. Global alert policies provide a stable organizational framework, while inline alert policies can be dynamically created, modified, or deleted on a per-incident basis. This dynamic structure allows the system to adapt to changing incident patterns and organizational needs without requiring complete policy reconfiguration.
Solution Approach 2:
The patent implements the nested doll principle by nesting inline alert policies within the broader context of global alert policies. Inline policies are contained within and supplement the global policy framework, allowing complex alert generation logic to be organized in hierarchical layers. This nesting reduces management complexity by allowing administrators to work with appropriate policy levels rather than managing all alert logic at one level.
4Reliability
If traditional alert management systems are used, then alerts can be generated, but failure to account for dynamic status of incidents results in unnecessary alerts
Solution Approach 1:
The patent implements continuous feedback monitoring of incident status at both global and inline policy levels. The system automatically re-evaluates whether alerts should be generated or suppressed based on current incident state, ensuring that alerts remain relevant as incidents evolve. This feedback mechanism prevents unnecessary alerts while maintaining timely notification for incidents that require attention.
Solution Approach 2:
The patent applies periodic action by continuously and automatically re-evaluating incident status against alert policies at defined intervals or upon status changes. This periodic assessment ensures that alert generation decisions account for the most current incident state, reducing unnecessary alerts while maintaining alert relevance without requiring manual intervention.
Data Source
AI summary
Various embodiments herein described are directed to methods, apparatuses and computer program products configured for improving alert generation and management in network computer systems. In some embodiments, a client device may generate one or more responder alert data objects for an incident data object based at least in part on global alert policy data object(s) and inline alert policy data object(s). Additional example embodiments provide various example global alert policy creation user interfaces, global alert policy edit user interfaces, inline alert policy creation user interfaces, and/or inline alert policy edit user interfaces that facilitate various user inputs and software operations in an incident alert and management platform.


