Infrastructure Event Clustering for Security Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing infrastructure face challenges in efficiently organizing and retrieving large volumes of messages and events due to lack of automated indexing, leading to difficulties in finding relevant information and managing spam, with existing methods failing to effectively handle the dynamic nature of spam and application traffic in data centers.

Innovation Solution

A system with a collaborative interface that uses an extraction engine, signalizer engine, and interactive displays to cluster events based on common characteristics, employing Non-negative Matrix Factorization (NMF), k-means clustering, and topology proximity engines to group similar events and maintain security in managed infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated indexing and clustering systems are implemented, then information retrieval efficiency is improved, but device complexity increases

Engineering Contradiction:
Improveinformation retrieval efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments the infrastructure event management into distinct functional modules: extraction engine for event collection, signalizer engine for processing, NMF engine for dimensionality reduction, k-means clustering engine for event grouping, and topology proximity engine for relationship analysis. Each module handles a specific aspect of the complex task, making the overall system more manageable and maintainable while achieving high retrieval efficiency

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The clustering system is designed as a universal platform that can handle multiple types of infrastructure events (logs, alerts, performance metrics) from various sources simultaneously. The system provides multiple retrieval methods (keyword search, clustering-based search, topology-based search) that can be applied to different event types, reducing the need for separate specialized systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If multiple clustering engines (NMF, k-means, topology proximity) are used to group events, then event organization accuracy is improved, but device complexity increases

Engineering Contradiction:
Improveevent clustering accuracyVSAvoidprocessing system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system merges three different clustering approaches (NMF for semantic similarity, k-means for statistical grouping, and topology proximity for structural relationships) into a unified event clustering framework. Each engine contributes its unique strength to the overall clustering accuracy, and their results are integrated to provide comprehensive event organization that leverages multiple perspectives simultaneously

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The signalizer engine acts as an intermediary that receives raw infrastructure events, processes them through standardized formatting and feature extraction, and prepares them for input to the multiple clustering engines. This intermediary layer ensures consistent data quality and format across different event sources, enabling the clustering engines to operate efficiently with standardized input

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If automated event processing and clustering is implemented, then productivity is improved, but loss of information increases due to potential automated errors

Engineering Contradiction:
Improveevent processing throughputVSAvoidinformation accuracy
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The system incorporates feedback mechanisms where clustering results are continuously evaluated and used to refine future clustering operations. The system monitors clustering quality metrics and adjusts processing parameters accordingly, ensuring that automated processing maintains high information accuracy while achieving high throughput. User feedback on clustering results can also be incorporated to improve system performance over time

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11960601B2System for managing an instructure with security
Publication Date: 2024.04.16 DELL PROD LP
  • US11960601B2 patent drawing
  • US11960601B2 patent drawing
  • US11960601B2 patent drawing

AI summary

A system for managing an infrastructure includes extraction engine is in communication with a managed infrastructure that includes physical hardware. A signalizer engine includes one or more of an NMF engine (Non-negative matrix factorization), a k-means clustering engine (a method of vector quantization), and a topology proximity engine. The signalizer engine determines one or more common characteristics of events and produces clusters of events relating to the failure or errors in the infrastructure. The signalizer engine uses graph coordinates and optionally a subset of attributes assigned to each event to generate one or more clusters to bring together events whose characteristics are similar. One or more interactive displays provide a collaborative interface coupled to the extraction and the signalizer engine with a collaborative interface (UI) for decomposing events from the infrastructure. The events are converted into words and subsets to group the events into clusters that relate to security of the managed infrastructure. In response to grouping the events physical changes are made to at least a portion of the physical hardware. In response to production of the clusters security of the managed infrastructure is maintained.