Event Clustering System for Managed Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing and organizing vast amounts of messages/events from infrastructure, such as email and network communications, face challenges in clustering and retrieving relevant information due to the lack of automated indexing and the scalability issues of rule-based systems, leading to inefficiencies in spam detection and application dependency analysis in data centers.

Innovation Solution

An event clustering system that utilizes a sigalizer engine to determine common steps from events, produce clusters, and employ graphing technology with vectors, effectively grouping events related to alerts and failures in managed infrastructure, and utilizing historical data for resilience and error estimation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If manual directory creation and organization is used, then information can be organized into hierarchical structures, but the process becomes impractical for massive amounts of web-based information and requires significant human time and effort

Engineering Contradiction:
Improveautomated information organizationVSAvoidinformation processing speed
Core Design Contradiction:
Extent of automationVSProductivity

Solution Approach 1:

The system enables self-service by automatically analyzing incoming events, extracting characteristics, and organizing them into clusters without human intervention. The event clustering system autonomously performs what previously required manual directory creation, using algorithms to identify patterns and group related events automatically.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system transforms the organization approach by changing from manual hierarchical classification to automated parameter-based clustering. Events are organized based on extracted characteristics and patterns rather than manual directory structures, allowing the system to handle massive volumes of information efficiently.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If rule-based systems are used for spam detection and event management, then specific patterns can be detected, but the systems face scalability issues and cannot effectively handle evolving spam techniques

Engineering Contradiction:
Improveadaptability to evolving spam patternsVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system transitions from static rule-based detection to dynamic pattern recognition. The event clustering system continuously learns from incoming events, adapting to new spam patterns and techniques automatically. This dynamic approach allows the system to evolve with emerging threats without requiring manual rule updates.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system replaces mechanical rule-based filtering with intelligent pattern recognition algorithms. Instead of relying on predefined rules that require manual updates, the system uses automated clustering and characteristic extraction to detect and adapt to evolving spam patterns, reducing the need for manual system reconfiguration.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If folders are used to organize messages, then messages can be sorted into categories, but tasks become invisible and easily neglected, and messages can only be in one folder at a time

Engineering Contradiction:
Improvemessage retrieval efficiencyVSAvoidtask visibility
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The event clustering system provides multi-functionality by allowing events to belong to multiple clusters simultaneously based on their characteristics. Unlike traditional single-folder organization, the system can categorize the same event under different clusters depending on the perspective or type of analysis, enabling comprehensive task management and improved visibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system adds another dimension to message organization by implementing multi-dimensional clustering. Instead of single-folder hierarchy, events are organized across multiple clustering dimensions simultaneously, allowing users to view and retrieve messages from multiple perspectives while maintaining task visibility through various cluster views.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10574551B2System for decomposing events from managed infrastructures
Publication Date: 2020.02.25 DELL PROD LP
  • US10574551B2 patent drawing
  • US10574551B2 patent drawing
  • US10574551B2 patent drawing

AI summary

A system is provided for clustering events. A first engine is configured to receive message data from managed infrastructure that includes managed infrastructure physical hardware that supports the flow and processing of information. A second engine determines common characteristics of events and produces clusters of events relating to a failure of errors in the managed infrastructure. Membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information. One or more situations are created that is a collection of one or more events or alerts representative of the actionable problem in the managed infrastructure. In response to the production of the clusters one or more physical changes in the managed infrastructure hardware.