Event Aggregation Correlation Rules for Network Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Aggregating large numbers of failure events into characteristic events in network management requires significant labor and time, often relying on network administrators, which hampers efficiency.

Innovation Solution

An information processing device calculates correlation values for combinations of event information, selecting those with high frequency and close temporal proximity to generate combination rules independently, automating the aggregation process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If aggregation of failure events is performed manually by network administrators, then accuracy of event aggregation can be maintained, but labor and time consumption increases significantly

Engineering Contradiction:
Improveaccuracy of event aggregationVSAvoidtime consumption for aggregation
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables automatic aggregation of failure events by calculating correlation values between event combinations and selecting high-correlation combinations autonomously, eliminating the need for manual administrator intervention while maintaining aggregation quality

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses correlation value as a quantitative parameter to automatically determine which event combinations should be aggregated, replacing manual judgment with objective parameter-based selection

Inventive Principle:
Principle #35Parameter changes

2Reliability

If aggregation of failure events is performed manually by network administrators, then quality control can be maintained, but workload increases significantly

Engineering Contradiction:
Improvequality control of aggregationVSAvoidworkload of network administrators
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs self-service by automatically calculating correlation values and selecting event combinations for aggregation without requiring administrator workload, while maintaining quality through systematic correlation-based selection

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses correlation value calculations as feedback to automatically determine which event combinations should be aggregated, creating a closed-loop system that maintains quality control without manual intervention

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If manual aggregation of event information is performed, then flexibility in handling diverse event patterns can be maintained, but processing time increases

Engineering Contradiction:
Improveflexibility in handling event patternsVSAvoidprocessing time for aggregation
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system handles diverse event patterns by calculating correlation values that adapt to different event combinations, using parameter-based selection that automatically adjusts to various patterns without manual reconfiguration

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The correlation-based aggregation system provides universal applicability across different event types and patterns, handling diverse scenarios through a single automated mechanism rather than multiple manual procedures

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12057996B2Combination rules creation device, method and program
Publication Date: 2024.08.06 NIPPON TELEGRAPH & TELEPHONE CORP
  • US12057996B2 patent drawing
  • US12057996B2 patent drawing
  • US12057996B2 patent drawing

AI summary

According to one aspect of the present invention, when a combination rule of event information to be monitored is created by aggregating a plurality of pieces of event information generated in a network, an information processing device executes: collecting the plurality of pieces of event information; calculating a correlation value for a plurality of combinations of event information including m (m≥3) pieces of event information generated from the plurality of pieces of event information collected; selecting a combination of the pieces of event information for which the calculated correlation value is equal to or higher than a predetermined value, wherein the correlation value increases as the number of times or frequency that the event information included in a combination appears according to the combination increases and also increases as a time interval between the pieces of event information included in the combination decreases; and generating the combination rule on the basis of the event information included in the selected combination.