Compliance Server Clustering Change Data for Root Cause Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Compliance reports often become cumbersome due to numerous instances of rule, setting, and configuration parameter violations, making it difficult for users to identify and address the underlying causes of changes in computing devices, especially after events like software installations.

Innovation Solution

A compliance server analyzes change data from target hosts, groups instances into clusters using statistical and inference techniques, and correlates this data with change catalogs to categorize and classify changes, generating reports that highlight the causes of changes, allowing users to determine compliance and necessary adjustments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a server monitors and reports all individual compliance violations, then complete compliance information is captured, but the compliance report becomes cumbersome and difficult to use

Engineering Contradiction:
Improvecompliance information completenessVSAvoidreport usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines multiple individual compliance violation instances into grouped summaries organized by change category. Instead of listing each violation separately, similar violations are merged into consolidated entries that show the root cause and affected items, making the report manageable while preserving complete compliance information.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent segments the compliance report into hierarchical groups based on change categories (e.g., software installations, configuration changes). Each segment contains relevant violations and their relationships, allowing users to navigate and understand violations in organized chunks rather than a single overwhelming list.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If thousands of individual compliance violations are listed, then detailed violation data is provided, but users cannot quickly identify root causes

Engineering Contradiction:
Improveviolation data detailVSAvoidtime to identify root causes
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system performs preliminary analysis by automatically grouping violations and identifying root causes before generating the report. Change catalogs are pre-built with expected violations for common changes (e.g., software installations), allowing the system to pre-categorize violations and highlight root causes upfront, saving users time without losing violation details.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces change catalogs as an intermediary layer between raw violation data and the final report. These catalogs contain pre-defined relationships between changes and expected violations, acting as a mediator that automatically connects individual violations to their root causes, reducing the time users need to spend analyzing the data.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If compliance monitoring tracks every setting and rule, then comprehensive compliance coverage is achieved, but the complexity of analyzing changes increases

Engineering Contradiction:
Improvecompliance coverageVSAvoidchange analysis complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameter of analysis from individual compliance settings to change categories and root causes. Instead of analyzing each rule and setting separately, the system transforms the data into grouped changes with associated catalogs, reducing analysis complexity while maintaining comprehensive compliance coverage through the structured organization.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10346801B2Interpreting categorized change information in order to build and maintain change catalogs
Publication Date: 2019.07.09 TRIPWIRE INC
  • US10346801B2 patent drawing
  • US10346801B2 patent drawing
  • US10346801B2 patent drawing

AI summary

Methods, systems, and articles for receiving, by a monitor server, change data associated with a change captured on a target host, are described herein. In various embodiments, the target host may have provided the change data in response to detecting the change, and the change data may include one or more rules, settings, and/or parameters. Further, in some embodiments, the monitor server may then group the change data into clusters and may correlate the clusters with a change catalog in order to provide a possible reason or cause for the cluster of changes. Once the change data have been classified as clusters, a report may be generated providing classification or categorization and cluster information for the various changes. In various embodiments, the generating may comprise generating a report to the target host and/or to an administrative user. In various embodiments, a reason may be determined for causing a cluster of changes and the change catalog may updated with the reason.