Clustering Anomalous Event Records for Network Remediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In large wireless networks, analyzing multidimensional data collected through monitoring to identify issues is challenging due to the presence of false alarms and irrelevant events, which can obscure hardware failures, overloading, malware infections, and security intrusions.
Innovation Solution
An anomalous event aggregation engine generates event records in the form of vectors, clusters them, and outputs these clusters for remediation, using a clustering engine to identify and prioritize issues based on relevant dimensions and context-specific models.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multidimensional data is collected through monitoring to identify network issues, then the ability to detect actual problems (hardware failures, malware infections, security intrusions) is improved, but false alarms and irrelevant events increase, obscuring real issues
Solution Approach 1:
The patent segments the multidimensional monitoring data into multiple dimensions (e.g., performance metrics, security events, configuration changes) and processes each dimension separately through context-specific models. This segmentation allows the system to filter and analyze relevant events in each dimension independently, reducing false alarms while maintaining detection accuracy for actual network issues.
Solution Approach 2:
The patent changes parameters by applying context-specific models that adapt analysis thresholds and criteria based on the particular network context (e.g., normal vs. abnormal conditions, different network segments). This dynamic parameter adjustment allows the system to distinguish between relevant anomalies and false alarms by modifying detection sensitivity according to contextual information.
2Reliability
If comprehensive monitoring is implemented to detect all network issues, then detection capability is improved, but system complexity increases
Solution Approach 1:
The patent divides the complex monitoring system into modular context-specific models, each responsible for analyzing particular types of events or network segments. This modular segmentation reduces overall system complexity by allowing independent development, deployment, and maintenance of individual analysis components while maintaining comprehensive detection capability.
Solution Approach 2:
The patent implements universal context-specific models that can handle multiple types of network events and issues through a common analytical framework. These multi-functional models reduce complexity by providing a unified approach to analyzing diverse monitoring data rather than requiring separate specialized systems for each type of network issue.
3Reliability
If all monitoring events are analyzed in detail, then complete issue identification is achieved, but processing time and resources increase
Solution Approach 1:
The patent applies partial action by focusing detailed analysis only on events that are relevant to the current network context and exhibit characteristics of actual problems. Rather than analyzing all monitoring events equally, the system selectively applies comprehensive analysis only where needed, reducing processing time while maintaining complete issue identification through targeted deep-dive analysis.
Solution Approach 2:
The patent applies local quality by varying the depth and type of analysis applied to different events based on their specific characteristics and context. Critical events receive detailed localized analysis while routine events receive streamlined processing, optimizing the balance between identification completeness and processing efficiency through context-appropriate analysis intensity.
Data Source
AI summary
In some examples, a system generates event records representing anomalous events associated with respective devices in a network, each respective anomalous event of the anomalous events being identified as anomalous for a respective context of a device of the devices. The system clusters the event records to produce a plurality of clusters of the event records. The system outputs the plurality of clusters for application of a remediation of an issue in the network.


