Distributed Orchestrators for False Positive Filtering and Root Cause Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in handling the scale, complexity, and volatility of modern information systems, leading to inefficiencies in false positive filtering and root cause analysis, which can result in delayed responses to critical issues, as seen in the airplane and cyber security examples.
Innovation Solution
Implementing distributed orchestrators that communicate and collaborate to analyze local data, using algorithms and constraints to quickly identify true positives and root causes, thereby reducing the complexity of managing large, interconnected systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If distributed orchestrators are implemented to rapidly identify root causes and false positives, then response time and detection accuracy improve, but system complexity and deployment difficulty increase
Solution Approach 1:
The system segments the monitoring and analysis functions into distributed orchestrators deployed across multiple network elements. Each orchestrator independently analyzes local data and collaborates with others to identify root causes, dividing the complex task of system-wide monitoring into manageable local units that collectively solve the problem rapidly.
Solution Approach 2:
The orchestrators act as intermediary components between network elements and the central management system. They collect, process, and analyze data locally before presenting findings to the central system, reducing the complexity burden on the central system while enabling rapid local response to issues.
2Measurement precision
If distributed orchestrators analyze local data and collaborate to identify true positives, then false positive filtering accuracy improves, but computational resources and processing load increase
Solution Approach 1:
The computational workload is segmented and distributed across multiple orchestrators deployed at different network elements. Each orchestrator performs localized data analysis and shares findings with others, dividing the heavy computational burden of false positive filtering into manageable portions that can be processed in parallel, improving accuracy while distributing resource consumption.
Solution Approach 2:
The system merges the computational capabilities of multiple distributed orchestrators to achieve superior false positive filtering accuracy. By combining local analysis results from multiple orchestrators that each process different aspects of the data, the system achieves high accuracy while distributing the computational load across available resources.
Data Source
AI summary
An alert that is generated by a first orchestrator associated with a first subsystem or received from one or more distributed orchestrators that are associated with one or more corresponding subsystems is analyzed. The alert is triggered by a change in behavior determined by a behavioral analysis algorithm associated with the first orchestrator or corresponding behavior analysis algorithms associated with the one or more distributed orchestrators. It is determined whether an alert is indicative of a false positive based on an objective associated with the first orchestrator, an algorithm associated with the first orchestrator and one or more constraints associated with the first orchestrator. The alert is filtered in response to determining that the alert is indicative of the false positive.


