Dynamic Alert Filtering for User Group Additions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional alerting systems in computer network administration generate excessive alerts for user additions to user groups, leading to unnecessary resource utilization and making it difficult for operators to distinguish between benign and abnormal alerts.

Innovation Solution

An apparatus and method that differentiate between benign and abnormal user additions by maintaining an allowed entity list based on a learning period, reducing alerts to only those deemed abnormal, thereby minimizing resource utilization and focusing operator attention on critical alerts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If alerts are generated for every user addition to user groups, then security monitoring coverage is improved, but system resource utilization increases excessively and operator ability to distinguish abnormal alerts deteriorates

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoidsystem resource utilization
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system changes the parameter of alert generation from a static rule-based approach to a dynamic behavior-based approach. By monitoring user addition patterns over time and adapting alert thresholds based on learned normal behavior, the system optimizes the balance between comprehensive security monitoring and resource efficiency. This allows the system to generate alerts only when abnormal patterns are detected, reducing unnecessary resource consumption while maintaining security coverage.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements self-service through automated learning and adaptation mechanisms. The monitoring system automatically learns normal user addition patterns, identifies deviations, and adjusts alert generation without requiring manual configuration or operator intervention. This self-adjusting capability enables the system to maintain optimal security monitoring while automatically filtering out benign alerts, thereby conserving system resources.

Inventive Principle:
Principle #25Self-service

2Reliability

If alerts are generated for every user addition to user groups, then security monitoring coverage is improved, but operator ability to distinguish abnormal alerts deteriorates

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoidoperator ability to distinguish abnormal alerts
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system transforms alert generation from a uniform parameter approach to a dynamic, context-aware parameter system. By continuously learning normal behavior patterns and adjusting alert thresholds based on observed deviations, the system changes the parameter of alert sensitivity dynamically. This enables operators to receive only meaningful alerts that deviate from established baselines, making it easier to distinguish abnormal events while maintaining comprehensive security monitoring coverage.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements feedback mechanisms where alert generation is based on continuous monitoring and comparison against learned normal patterns. When user addition behavior deviates from the established baseline, the system provides feedback through selective alert generation. This feedback loop enables operators to focus on truly abnormal events while benign variations in user addition patterns are automatically filtered out, significantly improving operator efficiency.

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive alerting is implemented for all user additions, then security monitoring is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity monitoringVSAvoidalerting system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system reduces complexity through self-service automation. By implementing automated learning algorithms that continuously monitor and adapt to normal user addition patterns, the system eliminates the need for complex manual rule configuration. The automated behavior analysis and dynamic threshold adjustment mechanisms handle the complexity internally, providing simple, intelligent alert generation that maintains comprehensive security monitoring without requiring complex system architecture.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system manages complexity by dynamically changing alert parameters based on learned behavior patterns rather than using static, pre-configured rules. This parameter adaptation approach allows the system to maintain simple operational logic while achieving comprehensive security monitoring. The dynamic parameter adjustment based on observed deviations from normal behavior reduces the need for complex rule sets and manual configuration.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3635935B1Managing alerts regarding additions to user groups
Publication Date: 2021.02.17 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3635935B1 patent drawingFigure 1
  • EP3635935B1 patent drawingFigure 2
  • EP3635935B1 patent drawingFigure 3

AI summary

According to examples, an apparatus for managing alerts pertaining to additions of users to a user group in a computer network may include a processor and a memory, which may have stored thereon machine readable instructions that are to cause the processor to, during a learning period, identify an entity that added a user to the user group during the learning period and enter an identification of the identified entity into an allowed entity list for the user group. Following the learning period, the instructions are to cause the processor to identify a user addition event that indicates that an adding entity added another user to the user group, determine whether the adding entity is in the allowed entity list, and manage issuance of an alert regarding the user addition event based upon whether the adding entity is in the allowed entity list to reduce a number of issued alerts.