Event Clustering System for Managed Infrastructure Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for managing and securing managed infrastructure face challenges in organizing and retrieving large volumes of messages/events, maintaining security, and effectively detecting spam and intrusion due to the lack of automated indexing and scalable solutions.
Innovation Solution
An event clustering system that includes an extraction engine, alert engine, signalizer engine, and reporting engine to generate clusters from events, providing security features like access control, intrusion detection, and threat propagation, using NMF, k-means clustering, and topology proximity engines to analyze and report on infrastructure security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If automated indexing and clustering systems are implemented to organize large volumes of events, then information retrieval efficiency is improved, but system complexity increases
Solution Approach 1:
The system segments the infrastructure event stream into discrete events with specific attributes, then applies multiple specialized engines (extraction, alert, signalizer, reporting) to process different aspects of events separately. This modular segmentation enables efficient automated clustering while managing system complexity through divided responsibilities.
Solution Approach 2:
The patent introduces intermediate data structures and processing layers between raw events and final retrieval. Events are transformed through extraction engines into structured formats, then processed by alert engines and signalizer engines before reaching the reporting layer. These intermediaries enable automated indexing without requiring direct complex processing at each stage.
2Reliability
If multiple security features (access control, intrusion detection, threat propagation) are integrated into the event clustering system, then security capability is improved, but device complexity increases
Solution Approach 1:
The event clustering system is designed as a universal platform that handles multiple security functions through a common architecture. The extraction engine, alert engine, and signalizer engine work together to provide access control, intrusion detection, and threat propagation capabilities simultaneously, rather than requiring separate systems for each function.
Solution Approach 2:
The patent combines multiple security features into a unified event clustering system. Access control, intrusion detection, and threat propagation are merged into the same processing pipeline, where events are processed once but can trigger multiple security responses. This merging reduces overall system complexity compared to having separate systems for each security function.
3Productivity
If automated event processing and clustering is implemented to reduce manual organization, then productivity is improved, but the system requires sophisticated algorithms increasing complexity
Solution Approach 1:
The system implements self-service automated processing where events are automatically extracted, clustered, and routed without manual intervention. The extraction engines automatically identify event attributes, the alert engines automatically generate alerts based on patterns, and the signalizer engines automatically route events to appropriate destinations. This self-service capability achieves high productivity while managing algorithmic complexity through automated decision-making rules.
Data Source
AI summary
An event clustering system includes a processor that generates reports. An extraction engine is in communication with an infrastructure. The extraction engine receives data from the infrastructure, produces events and populates a database with a dictionary of event or graph entropy. An alert engine receives the events and creates alerts mapped into a matrix, M. A signalizer engine includes one or more of an NMF engine, a k-means clustering engine and a topology proximity engine. The signalizer engine determines one or more common steps from events and produces clusters relating to the alerts and or events. One or more interactive displays provide a collaborative interface a coupled to the extraction and the signalizer engine for decomposing events from the infrastructure. A reporting engine generates a report from at least one of the clusters and the events that are retrieved from the collaborative interface with a source address for each event to assign a graph coordinate in the graph to the event with an optional subset of attributes being extracted for each event and turning that into a vector of the graph. In response to production of the clusters one or more physical changes in a managed infrastructure hardware is made, and in response.


