Event Clustering System for Network Topology Inference

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing and organizing vast amounts of network traffic and messages, such as email and other digital communications, face challenges in efficiently clustering events and inferring network topology, particularly due to high volumes of spam and the dynamic nature of spam corpus, which complicates effective filtering and data center monitoring.

Innovation Solution

An event clustering system that employs Non-negative Matrix Factorization (NMF) to estimate matrices W and H, utilizing a convolution product for delay measurements and graph entropy to cluster events and infer network topology, thereby identifying alerts caused by dysfunctional nodes and reconstructing the true network topology.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional folder-based systems are used to organize messages, then messages can be sorted into categories, but the systems cannot effectively handle the massive volume of messages and adapt to dynamic spam patterns

Engineering Contradiction:
Improvemessage organization efficiencyVSAvoidadaptability to dynamic spam corpus
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic adaptability through continuous learning mechanisms where the system updates its spam filtering models and clustering algorithms based on evolving spam patterns. The event clustering system adapts to new spam types by learning from incoming messages and adjusting its classification criteria, making the system versatile against dynamic spam corpus while maintaining organization efficiency.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes parameters of its clustering and filtering algorithms based on observed spam patterns. By adjusting clustering parameters, threshold values, and model weights dynamically, the system maintains high productivity in message organization while adapting to new spam variations without requiring manual reconfiguration.

Inventive Principle:
Principle #35Parameter changes

2Manufacturing precision

If manual directory creation is used to organize web information, then information can be categorized, but the process is impractical for handling massive amounts of web-based information

Engineering Contradiction:
Improveinformation categorization accuracyVSAvoidinformation processing volume
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The event clustering system performs self-service by automatically categorizing and organizing messages without manual intervention. The system autonomously clusters events, identifies spam patterns, and organizes information flows, enabling it to handle massive volumes of web-based information while maintaining categorization accuracy through its learned models and algorithms.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical categorization processes with automated computational systems. By substituting human-directed folder creation with algorithmic event clustering and machine learning-based classification, the system achieves both high processing volume capability and accurate information categorization at scale.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Object-affected harmful factors

If rule-based spam filtering is used, then spam can be filtered, but the filtering effectiveness decreases as spammers modify their techniques

Engineering Contradiction:
Improvespam filtering effectivenessVSAvoidresilience to evolving spam tactics
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The system implements feedback loops where filtering results are continuously monitored and fed back into the learning models. This allows the system to detect when spam tactics evolve and automatically adjust its filtering strategies, maintaining effectiveness against modified spam techniques while adapting to new patterns through continuous learning from filtered message data.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The event clustering system performs preliminary analysis and clustering of incoming messages before final spam classification. By pre-processing and grouping similar events, the system prepares data structures that enable faster and more accurate spam detection, allowing it to maintain filtering effectiveness while adapting to new spam tactics through its learned patterns from clustered data.

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If complex matrix factorization is used to infer network topology, then accurate topology prediction is achieved, but computational complexity increases

Engineering Contradiction:
Improvenetwork topology inference accuracyVSAvoidcomputational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the network topology inference problem into manageable components through event clustering. By dividing the complex matrix factorization task into smaller sub-tasks based on clustered event groups, the system reduces computational complexity while maintaining accuracy. Each cluster can be processed independently, allowing parallel computation and reducing the overall computational burden of inferring network topology from massive message flows.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10425291B2System for decomposing events from managed infrastructures with prediction of a networks topology
Publication Date: 2019.09.24 DELL PROD LP
  • US10425291B2 patent drawing
  • US10425291B2 patent drawing
  • US10425291B2 patent drawing

AI summary

An event clustering system is provided that in response to a time series infers a network topology. Matrices W and H are estimated as a local minimum. For each pair of nodes: (i) a computation of the convolution is made; a number of peaks within the convolution is a function of a delay; and a comparison is made to an average behavior of a pair of nodes that emits the same number of alerts. Alerts are only spread to adjacent nodes, alerts are caused by dysfunctional nodes that do not emit alerts, and a true topology coincides with the end of the recording.