Network Activity Data Processing with Bayesian Event Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The manual interpretation of numerous network events in data centers is labor-intensive and inefficient, as existing systems lack automated prioritization and correlation of symptom and cause relationships, leading to overwhelming amounts of data for administrators.

Innovation Solution

The implementation of causal models with Bayesian probability calculations to automate event prioritization and correlation, generating event messages based on probabilistic relationships between symptom and cause events, and triggering micro-workflow data gathering for detailed diagnostics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual interpretation of network events is used, then detailed analysis can be performed, but labor intensity and time consumption increase significantly

Engineering Contradiction:
Improveevent analysis accuracyVSAvoidtime for event interpretation
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent introduces an automated event correlation system that acts as an intermediary between raw network events and administrator analysis. This system uses causal models and probability calculations to automatically correlate events, identify cause-symptom relationships, and generate prioritized event messages, thereby reducing manual labor while maintaining analysis quality

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the manual mechanical process of event interpretation with an automated computational system. The system uses probability calculations, causal models, and algorithmic event correlation to automatically analyze network events, eliminating the need for manual labor in event interpretation while maintaining or improving analysis accuracy

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Loss of information

If all network events are processed and presented to administrators, then complete information is provided, but information overload occurs making interpretation difficult

Engineering Contradiction:
Improveevent information completenessVSAvoidadministrator workload
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent extracts and separates significant events from less significant ones using automated correlation and probability analysis. The system identifies cause events and symptom events, calculates their relationships, and extracts only the most relevant event correlations for administrator review, thereby reducing information overload while maintaining completeness of critical information

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different processing qualities to different events based on their significance. High-priority cause-symptom event pairs receive detailed probabilistic analysis and are prominently presented, while less significant events are processed with standard correlation methods or suppressed, thereby optimizing administrator focus on critical issues

Inventive Principle:
Principle #3Local quality

3Productivity

If automated event processing is implemented, then labor intensity is reduced, but system complexity increases

Engineering Contradiction:
Improveevent processing efficiencyVSAvoidsystem architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the automated event processing system into distinct functional modules: event collection, causal model storage, probability calculation engine, event correlation logic, and message generation. This modular architecture manages system complexity by organizing functions into separate, manageable components that can be independently maintained and scaled

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9917741B2Method and system for processing network activity data
Publication Date: 2018.03.13 MICRO FOCUS LLC
  • US9917741B2 patent drawing
  • US9917741B2 patent drawing

AI summary

An exemplary embodiment of the present invention provides a method of processing network activity data. The method includes receiving network activity data and generating an event based on the network activity data. The method also includes generating a probability based at least in part on Bayesian statistics, the probability corresponding to a likelihood that the event caused or was caused by another event. The method also includes generating an event message corresponding to the event based on the probability.