Personalized Network Alert Filtering via User Interest Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Monitoring large-scale networks generates a vast amount of information, making it difficult for users to identify important or valuable data, as existing network monitoring systems produce numerous alerts and reports that are often irrelevant to individual users.
Innovation Solution
A system that uses a monitoring engine to track network traffic, generate device relation models, and employ an inference engine to assign interest scores to entities based on user interactions and feedback, personalizing alerts by filtering out irrelevant information and highlighting entities of interest.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If network monitoring systems monitor large-scale networks, then comprehensive network visibility is achieved, but information overload occurs making it difficult to identify important data
Solution Approach 1:
The system segments the monolithic alert system into personalized alert streams for different users based on their roles, interests, and historical interactions. Each user receives a customized subset of alerts rather than a comprehensive list, dividing the information overload into manageable, relevant portions.
Solution Approach 2:
The system applies local quality by tailoring alert content and priority to individual user characteristics. Different users receive different levels of detail, different alert types, and different prioritization based on their specific needs, making the information quality locally optimized for each user rather than uniformly generic.
2Reliability
If network monitoring systems generate comprehensive alerts and reports, then complete network coverage is achieved, but relevance to individual users decreases
Solution Approach 1:
The system performs preliminary action by analyzing user profiles, historical interactions, and device relationships before generating alerts. This pre-processing of user preferences and network topology enables the system to pre-filter and prioritize alerts according to each user's likely interests, making alerts relevant before they are even presented to the user.
Solution Approach 2:
The system implements feedback mechanisms where user interactions with alerts (such as acknowledgment, dismissal, or escalation) are fed back into the personalization engine. This continuous feedback loop refines the understanding of user preferences over time, improving alert relevance while maintaining comprehensive monitoring coverage.
3Device complexity
If traditional network monitoring systems provide generic alerts, then system simplicity is maintained, but user-specific valuable information is lost
Solution Approach 1:
The system introduces a personalization engine as an intermediary layer between the network monitoring infrastructure and end users. This intermediary processes comprehensive network data and transforms it into personalized alert streams, adding value through intelligent filtering and prioritization without requiring complexity in the underlying monitoring infrastructure.
Solution Approach 2:
The system applies parameter changes by dynamically adjusting alert parameters (priority, detail level, delivery method, timing) based on user profiles and current network conditions. This allows the same monitoring system to serve multiple users with different information needs without requiring separate monitoring systems for each user.
Data Source
AI summary
Embodiments are directed to monitoring network traffic using network computers. A monitoring engine may monitor network traffic associated with a plurality of entities in a network to provide metrics. A device relation model may be provided based on the plurality of entities, the network traffic, and the metrics. Interest information for a user may be provided based on one or more properties associated with the user. An inference engine may associate each entity in the plurality of entities with an interest score based on the interest information, the device relation model, and the metrics. An alert engine may generate a plurality of alerts associated with the plurality of entities based on the metrics. Some of the alerts may be provided to the user based on ranked interest scores associated with the entities.


