Clustering Anomalous Event Records for Network Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large wireless networks, analyzing multidimensional data collected through monitoring to identify issues is challenging due to the presence of false alarms and irrelevant events, which can obscure hardware failures, overloading, malware infections, and security intrusions.

Innovation Solution

An anomalous event aggregation engine generates event records in the form of vectors, clusters them, and outputs these clusters for remediation, using a clustering engine to identify and prioritize issues based on relevant dimensions and context-specific models.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multidimensional data is collected through monitoring to identify network issues, then the ability to detect actual problems (hardware failures, malware infections, security intrusions) is improved, but false alarms and irrelevant events increase, obscuring real issues

Engineering Contradiction:
Improvedetection accuracyVSAvoidfalse alarms
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent segments the multidimensional monitoring data into multiple dimensions (e.g., performance metrics, security events, configuration changes) and processes each dimension separately through context-specific models. This segmentation allows the system to filter and analyze relevant events in each dimension independently, reducing false alarms while maintaining detection accuracy for actual network issues.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes parameters by applying context-specific models that adapt analysis thresholds and criteria based on the particular network context (e.g., normal vs. abnormal conditions, different network segments). This dynamic parameter adjustment allows the system to distinguish between relevant anomalies and false alarms by modifying detection sensitivity according to contextual information.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If comprehensive monitoring is implemented to detect all network issues, then detection capability is improved, but system complexity increases

Engineering Contradiction:
Improveissue detection capabilityVSAvoidanalysis system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the complex monitoring system into modular context-specific models, each responsible for analyzing particular types of events or network segments. This modular segmentation reduces overall system complexity by allowing independent development, deployment, and maintenance of individual analysis components while maintaining comprehensive detection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements universal context-specific models that can handle multiple types of network events and issues through a common analytical framework. These multi-functional models reduce complexity by providing a unified approach to analyzing diverse monitoring data rather than requiring separate specialized systems for each type of network issue.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If all monitoring events are analyzed in detail, then complete issue identification is achieved, but processing time and resources increase

Engineering Contradiction:
Improveissue identification completenessVSAvoidanalysis processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by focusing detailed analysis only on events that are relevant to the current network context and exhibit characteristics of actual problems. Rather than analyzing all monitoring events equally, the system selectively applies comprehensive analysis only where needed, reducing processing time while maintaining complete issue identification through targeted deep-dive analysis.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent applies local quality by varying the depth and type of analysis applied to different events based on their specific characteristics and context. Critical events receive detailed localized analysis while routine events receive streamlined processing, optimizing the balance between identification completeness and processing efficiency through context-appropriate analysis intensity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10742482B2Clustering event records representing anomalous events
Publication Date: 2020.08.11 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10742482B2 patent drawing
  • US10742482B2 patent drawing
  • US10742482B2 patent drawing

AI summary

In some examples, a system generates event records representing anomalous events associated with respective devices in a network, each respective anomalous event of the anomalous events being identified as anomalous for a respective context of a device of the devices. The system clusters the event records to produce a plurality of clusters of the event records. The system outputs the plurality of clusters for application of a remediation of an issue in the network.