Deep Fusion Reasoning Engine for Network Alert Prioritization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network monitoring systems generate a large number of alerts, overwhelming administrators and leading to important alerts being ignored or disabled, due to the complexity and increasing number of network metrics and applications.
Innovation Solution
A deep fusion reasoning engine (DFRE) that uses machine learning models to detect anomalies, maps outputs to a conceptual space, and applies symbolic reasoning to rank alerts, prioritizing them for user interfaces based on impact and context, thereby reducing unnecessary alerts and optimizing resource allocation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network monitoring systems increase the number of monitored metrics and applications to improve network assessment capability, then the comprehensiveness of network monitoring is improved, but the number of generated alerts increases excessively, overwhelming administrators
Solution Approach 1:
The patent introduces an intermediary alert prioritization system that sits between the network monitoring components and administrators. This system uses machine learning models to process raw alerts, assign priority scores, and filter notifications. The intermediary translates the high-volume alert output from comprehensive monitoring into a manageable prioritized list, resolving the contradiction between thorough monitoring and alert overload.
Solution Approach 2:
The patent changes the parameter of alert presentation from raw quantity to prioritized ranking. By applying machine learning models that score alerts based on multiple factors (severity, impact, historical data, contextual information), the system transforms the alert metric from a simple count to a nuanced prioritized sequence, allowing administrators to focus on critical issues while maintaining comprehensive monitoring coverage.
2Reliability
If network monitoring systems generate comprehensive alerts for all detected anomalies, then the completeness of anomaly detection is improved, but the signal-to-noise ratio decreases, making it difficult to identify critical issues
Solution Approach 1:
The patent extracts critical information from the comprehensive alert set using machine learning models. The system separates signal from noise by identifying patterns, correlating events, and filtering out false positives. This extraction process maintains the completeness of anomaly detection while presenting only the most relevant alerts to administrators, effectively removing the noise component while preserving the essential diagnostic information.
Solution Approach 2:
The patent implements feedback loops where alert prioritization results are continuously refined based on administrator responses and system performance data. The machine learning models learn from historical alert patterns and administrator actions, progressively improving their ability to distinguish critical alerts from noise. This feedback mechanism maintains detection completeness while increasingly optimizing the signal-to-noise ratio over time.
Data Source
AI summary
In one embodiment, a service that monitors a network detects a plurality of anomalies in the network. The service uses data regarding the detected anomalies as input to one or more machine learning models. The service maps, using a conceptual space, outputs of the one or more machine learning models to symbols. The service applies a symbolic reasoning engine to the symbols, to rank the anomalies. The service sends an alert for a particular one of the detected anomalies to a user interface, based on its corresponding rank.


