Deep Fusion Reasoning Engine for Network Alert Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network monitoring systems generate a large number of alerts, overwhelming administrators and leading to important alerts being ignored or disabled, due to the complexity and increasing number of network metrics and applications.

Innovation Solution

A deep fusion reasoning engine (DFRE) that uses machine learning models to detect anomalies, maps outputs to a conceptual space, and applies symbolic reasoning to rank alerts, prioritizing them for user interfaces based on impact and context, thereby reducing unnecessary alerts and optimizing resource allocation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network monitoring systems increase the number of monitored metrics and applications to improve network assessment capability, then the comprehensiveness of network monitoring is improved, but the number of generated alerts increases excessively, overwhelming administrators

Engineering Contradiction:
Improvenetwork monitoring capabilityVSAvoidnumber of alerts
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent introduces an intermediary alert prioritization system that sits between the network monitoring components and administrators. This system uses machine learning models to process raw alerts, assign priority scores, and filter notifications. The intermediary translates the high-volume alert output from comprehensive monitoring into a manageable prioritized list, resolving the contradiction between thorough monitoring and alert overload.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter of alert presentation from raw quantity to prioritized ranking. By applying machine learning models that score alerts based on multiple factors (severity, impact, historical data, contextual information), the system transforms the alert metric from a simple count to a nuanced prioritized sequence, allowing administrators to focus on critical issues while maintaining comprehensive monitoring coverage.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If network monitoring systems generate comprehensive alerts for all detected anomalies, then the completeness of anomaly detection is improved, but the signal-to-noise ratio decreases, making it difficult to identify critical issues

Engineering Contradiction:
Improveanomaly detection completenessVSAvoidsignal-to-noise ratio
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts critical information from the comprehensive alert set using machine learning models. The system separates signal from noise by identifying patterns, correlating events, and filtering out false positives. This extraction process maintains the completeness of anomaly detection while presenting only the most relevant alerts to administrators, effectively removing the noise component while preserving the essential diagnostic information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements feedback loops where alert prioritization results are continuously refined based on administrator responses and system performance data. The machine learning models learn from historical alert patterns and administrator actions, progressively improving their ability to distinguish critical alerts from noise. This feedback mechanism maintains detection completeness while increasingly optimizing the signal-to-noise ratio over time.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10965516B2Deep fusion reasoning engine (DFRE) for prioritizing network monitoring alerts
Publication Date: 2021.03.30 CISCO TECHNOLOGY INC
  • US10965516B2 patent drawing
  • US10965516B2 patent drawing
  • US10965516B2 patent drawing

AI summary

In one embodiment, a service that monitors a network detects a plurality of anomalies in the network. The service uses data regarding the detected anomalies as input to one or more machine learning models. The service maps, using a conceptual space, outputs of the one or more machine learning models to symbols. The service applies a symbolic reasoning engine to the symbols, to rank the anomalies. The service sends an alert for a particular one of the detected anomalies to a user interface, based on its corresponding rank.