Network Activity Data Processing with Bayesian Event Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The manual interpretation of numerous network events in data centers is labor-intensive and inefficient, as existing systems lack automated prioritization and correlation of symptom and cause relationships, leading to overwhelming amounts of data for administrators.
Innovation Solution
The implementation of causal models with Bayesian probability calculations to automate event prioritization and correlation, generating event messages based on probabilistic relationships between symptom and cause events, and triggering micro-workflow data gathering for detailed diagnostics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual interpretation of network events is used, then detailed analysis can be performed, but labor intensity and time consumption increase significantly
Solution Approach 1:
The patent introduces an automated event correlation system that acts as an intermediary between raw network events and administrator analysis. This system uses causal models and probability calculations to automatically correlate events, identify cause-symptom relationships, and generate prioritized event messages, thereby reducing manual labor while maintaining analysis quality
Solution Approach 2:
The patent replaces the manual mechanical process of event interpretation with an automated computational system. The system uses probability calculations, causal models, and algorithmic event correlation to automatically analyze network events, eliminating the need for manual labor in event interpretation while maintaining or improving analysis accuracy
2Loss of information
If all network events are processed and presented to administrators, then complete information is provided, but information overload occurs making interpretation difficult
Solution Approach 1:
The patent extracts and separates significant events from less significant ones using automated correlation and probability analysis. The system identifies cause events and symptom events, calculates their relationships, and extracts only the most relevant event correlations for administrator review, thereby reducing information overload while maintaining completeness of critical information
Solution Approach 2:
The patent applies different processing qualities to different events based on their significance. High-priority cause-symptom event pairs receive detailed probabilistic analysis and are prominently presented, while less significant events are processed with standard correlation methods or suppressed, thereby optimizing administrator focus on critical issues
3Productivity
If automated event processing is implemented, then labor intensity is reduced, but system complexity increases
Solution Approach 1:
The patent segments the automated event processing system into distinct functional modules: event collection, causal model storage, probability calculation engine, event correlation logic, and message generation. This modular architecture manages system complexity by organizing functions into separate, manageable components that can be independently maintained and scaled
Data Source
AI summary
An exemplary embodiment of the present invention provides a method of processing network activity data. The method includes receiving network activity data and generating an event based on the network activity data. The method also includes generating a probability based at least in part on Bayesian statistics, the probability corresponding to a likelihood that the event caused or was caused by another event. The method also includes generating an event message corresponding to the event based on the probability.

