Managed Infrastructure Event Clustering for Security Breach Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing and securing managed infrastructure face challenges in efficiently organizing and retrieving messages, maintaining security, and detecting spam due to the high volume of information and evolving nature of spam, which leads to inefficiencies in resource allocation and productivity.

Innovation Solution

A system that includes an extraction engine and a signalizer engine to cluster events from a managed infrastructure, using NMF, k-means clustering, and topology proximity engines to identify common characteristics and produce clusters related to security breaches or errors, enabling physical changes to be made in the infrastructure for enhanced security and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional folder-based systems are used to organize messages, then messages can be sorted into categories, but it becomes difficult to manage and retrieve messages when the volume of information is very large

Engineering Contradiction:
Improvemessage organizationVSAvoidmessage retrieval efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system segments the large volume of messages into clusters based on common characteristics and topics. Instead of organizing all messages in a single hierarchical folder structure, the system divides them into multiple topic-based clusters, making it easier to navigate and retrieve specific messages without being overwhelmed by the entire message volume.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an automated clustering mechanism as an intermediary between message receipt and user retrieval. This intermediary automatically analyzes message content, identifies common characteristics, and groups messages into relevant clusters, eliminating the need for manual folder organization and enabling efficient retrieval through topic-based navigation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If manual directory creation is used to organize web-based information, then information can be categorized, but it is impractical to handle the massive amounts of information generated daily

Engineering Contradiction:
Improveinformation organizationVSAvoidvolume of information
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The system enables self-service organization of information by automatically analyzing and clustering messages based on their content and characteristics. The automated clustering mechanism processes massive volumes of information without human intervention, identifying common topics and grouping messages accordingly, thereby handling the sheer quantity of daily information generation efficiently.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the organizational parameter from manual hierarchical classification to automated topic-based clustering. By analyzing message content parameters such as subject lines, body text, and metadata, the system dynamically groups messages into clusters based on semantic similarity and common characteristics, enabling scalable organization regardless of information volume.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If rules-based service management is used to respond to events, then systematic responses can be generated, but the rules become dependent on point-in-time snapshots that are subject to continual change

Engineering Contradiction:
Improveresponse consistencyVSAvoidrule update frequency
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system transitions from static rules-based management to dynamic event clustering. Instead of relying on fixed rules that require continuous updates to reflect changing conditions, the system dynamically clusters events based on their characteristics and relationships. This dynamic approach automatically adapts to new event types and patterns without requiring manual rule updates, maintaining both consistency and adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary analysis of event characteristics and relationships to establish clustering patterns before specific incidents occur. By pre-defining clustering criteria based on event attributes and relationships, the system can consistently group similar events without requiring real-time rule updates, ensuring reliable responses while adapting to changing event landscapes.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11159364B2System in communication with a managed infrastructure
Publication Date: 2021.10.26 DELL PROD LP
  • US11159364B2 patent drawing
  • US11159364B2 patent drawing
  • US11159364B2 patent drawing

AI summary

A system is in communication with a managed infrastructure. An extraction engine is in communication with a managed infrastructure. The extraction engine is configured to receive managed infrastructure data and produces events as well as populates an entropy database with a dictionary of event entropy that can be included in the entropy database. A signalizer engine that includes one or more of an NMF engine, a k-means clustering engine and a topology proximity engine. The signalizer engine inputs a list of devices and a list of connections between components or nodes in the managed infrastructure. The signalizer engine determines one or more common characteristics and produces clusters of events relating to failure or errors in at least one of the devices and connections between components or nodes in the managed infrastructure. The events are converted into words and subsets to group the events into clusters that relate to security of the managed infrastructure. In response to grouping the events, physical changes are made to at least a portion of the physical hardware. In response to production of the clusters, security of the managed infrastructure is maintained.