Infrastructure Behavior Analysis via Multi-Dimensional Data Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer infrastructure monitoring systems face challenges in efficiently detecting and diagnosing malfunctions, particularly in complex environments, leading to potential system crashes and financial losses due to the difficulty in identifying abnormal behaviors and performance deviations in real-time.

Innovation Solution

A system and method utilizing an analytics engine that analyzes continuous and asynchronous data to create a multi-dimensional model of the computer infrastructure, visualizing behavior through graphic elements, allowing IT administrators to intuitively detect abnormal performances and malfunctions, and reducing the need for time-consuming data mining.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional monitoring methods examining protocols or log files are used, then forensic examination can be conducted, but detection and diagnosis of malfunctions become time-consuming and difficult in complex environments

Engineering Contradiction:
Improvedetection accuracyVSAvoiddiagnosis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary analysis by continuously collecting and processing data from multiple sources (protocols, log files, performance metrics) to establish baseline behavior patterns before malfunctions occur. This preliminary action enables the system to detect deviations from normal behavior in real-time, eliminating the need for time-consuming post-incident forensic examinations and allowing administrators to respond proactively to emerging issues.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary analysis layer that processes raw data from various monitoring sources and transforms it into meaningful behavioral patterns and anomalies. This intermediary layer correlates data across multiple devices and processes, making complex infrastructure behavior understandable and enabling rapid diagnosis without requiring administrators to manually examine numerous log files and protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive monitoring of complex computer infrastructure is implemented, then malfunction detection capability improves, but system complexity and difficulty of operation increase

Engineering Contradiction:
Improvemalfunction detection capabilityVSAvoidoperational simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The monitoring system is segmented into distinct functional modules: data collection agents deployed on individual devices, a central correlation engine that processes data from multiple sources, and visualization components that present information in manageable formats. This segmentation allows comprehensive monitoring of complex infrastructure while maintaining operational simplicity, as each module handles specific tasks and the system can be configured incrementally.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary correlation engine serves as a mediator between the complex underlying infrastructure and the user interface. This engine automatically correlates data from numerous devices, processes, and log sources, transforming complex multi-dimensional data into simplified behavioral patterns and anomaly detections that are easy for administrators to interpret and act upon.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If real-time behavior analysis is performed on multiple data sources, then abnormal behavior detection improves, but data processing requirements and computational resources increase

Engineering Contradiction:
Improveabnormal behavior detectionVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Data processing is performed in preliminary stages where raw data from multiple sources is collected, filtered, and pre-processed into standardized formats before being analyzed for behavioral patterns. This preliminary action reduces the computational burden of real-time analysis by preparing data in advance and identifying obvious anomalies early, allowing the system to focus computational resources on detecting subtle deviations from normal behavior.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements partial analysis by focusing computational resources on the most critical data sources and the most significant deviations from baseline behavior. Rather than analyzing every data point from every source with equal intensity, the system applies varying levels of analysis depth based on the importance and anomaly level of each data stream, optimizing the balance between detection capability and resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11657309B2Behavior analysis and visualization for a computer infrastructure
Publication Date: 2023.05.23 ELASTICSEARCH BV
  • US11657309B2 patent drawing
  • US11657309B2 patent drawing
  • US11657309B2 patent drawing

AI summary

The field of the disclosure relates generally to a method and system for analyzing behavior of a computer infrastructure and the displaying the behavior of the computer infrastructure in a graphical manner. The system comprises an analytical engine connected to agents running on devices in the computer infrastructure and analyzing continuous data and asynchronous data.