Event Clustering System for Managed Infrastructure Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing and securing managed infrastructure face challenges in organizing and retrieving large volumes of messages/events, maintaining security, and effectively detecting spam and intrusion due to the lack of automated indexing and scalable solutions.

Innovation Solution

An event clustering system that includes an extraction engine, alert engine, signalizer engine, and reporting engine to generate clusters from events, providing security features like access control, intrusion detection, and threat propagation, using NMF, k-means clustering, and topology proximity engines to analyze and report on infrastructure security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated indexing and clustering systems are implemented to organize large volumes of events, then information retrieval efficiency is improved, but system complexity increases

Engineering Contradiction:
Improveinformation retrieval efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments the infrastructure event stream into discrete events with specific attributes, then applies multiple specialized engines (extraction, alert, signalizer, reporting) to process different aspects of events separately. This modular segmentation enables efficient automated clustering while managing system complexity through divided responsibilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediate data structures and processing layers between raw events and final retrieval. Events are transformed through extraction engines into structured formats, then processed by alert engines and signalizer engines before reaching the reporting layer. These intermediaries enable automated indexing without requiring direct complex processing at each stage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple security features (access control, intrusion detection, threat propagation) are integrated into the event clustering system, then security capability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity capabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The event clustering system is designed as a universal platform that handles multiple security functions through a common architecture. The extraction engine, alert engine, and signalizer engine work together to provide access control, intrusion detection, and threat propagation capabilities simultaneously, rather than requiring separate systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines multiple security features into a unified event clustering system. Access control, intrusion detection, and threat propagation are merged into the same processing pipeline, where events are processed once but can trigger multiple security responses. This merging reduces overall system complexity compared to having separate systems for each security function.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If automated event processing and clustering is implemented to reduce manual organization, then productivity is improved, but the system requires sophisticated algorithms increasing complexity

Engineering Contradiction:
Improveautomated processing efficiencyVSAvoidalgorithm complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system implements self-service automated processing where events are automatically extracted, clustered, and routed without manual intervention. The extraction engines automatically identify event attributes, the alert engines automatically generate alerts based on patterns, and the signalizer engines automatically route events to appropriate destinations. This self-service capability achieves high productivity while managing algorithmic complexity through automated decision-making rules.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10686648B2System for decomposing clustering events from managed infrastructures
Publication Date: 2020.06.16 DELL PROD LP
  • US10686648B2 patent drawing
  • US10686648B2 patent drawing
  • US10686648B2 patent drawing

AI summary

An event clustering system includes a processor that generates reports. An extraction engine is in communication with an infrastructure. The extraction engine receives data from the infrastructure, produces events and populates a database with a dictionary of event or graph entropy. An alert engine receives the events and creates alerts mapped into a matrix, M. A signalizer engine includes one or more of an NMF engine, a k-means clustering engine and a topology proximity engine. The signalizer engine determines one or more common steps from events and produces clusters relating to the alerts and or events. One or more interactive displays provide a collaborative interface a coupled to the extraction and the signalizer engine for decomposing events from the infrastructure. A reporting engine generates a report from at least one of the clusters and the events that are retrieved from the collaborative interface with a source address for each event to assign a graph coordinate in the graph to the event with an optional subset of attributes being extracted for each event and turning that into a vector of the graph. In response to production of the clusters one or more physical changes in a managed infrastructure hardware is made, and in response.