Network Alert Ranking via Device Relation Models

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large-scale network monitoring environments, the vast amount of information generated by network monitoring systems makes it difficult for organizations to identify important alerts from numerous reports and alerts, leading to overwhelming and inefficient troubleshooting and management.

Innovation Solution

A network monitoring system that utilizes a monitoring engine to create a device relation model based on network traffic and metrics, with an inference engine assigning importance scores to entities based on their significance to the network operations, and an alert engine generating alerts prioritized by these scores to focus user attention on critical issues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network monitoring systems monitor large-scale networks, then comprehensive network visibility is achieved, but the volume of alerts and information becomes overwhelming making it difficult to identify important issues

Engineering Contradiction:
Improvenetwork visibilityVSAvoidvolume of alerts
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the most critical alert information by analyzing device relationships and importance scores. The system processes vast amounts of network monitoring data to identify and separate out only the alerts that require attention, filtering out redundant or low-priority information while maintaining comprehensive network visibility.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments alerts into priority levels based on device importance scores and relationships. By dividing the alert stream into categorized priority levels, the system enables users to focus on critical issues first while maintaining awareness of overall network status without being overwhelmed by equal-volume low-priority alerts.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If network monitoring systems generate detailed alerts for all network entities, then complete troubleshooting information is provided, but troubleshooting efficiency decreases due to the time required to review numerous alerts

Engineering Contradiction:
Improvetroubleshooting information completenessVSAvoidtroubleshooting time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent performs preliminary analysis of device relationships and calculates importance scores before generating alerts. This pre-computation of device criticality allows the system to automatically prioritize alerts in the correct sequence, so that when troubleshooting begins, the most important issues are already highlighted and ready for immediate attention, eliminating the need to review all alerts sequentially.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system incorporates feedback loops that continuously monitor network conditions and adjust alert prioritization based on actual device relationships and operational impact. This feedback mechanism ensures that troubleshooting information is not only complete but also dynamically prioritized based on current network state, reducing the time required to identify and resolve issues.

Inventive Principle:
Principle #23Feedback

3Reliability

If network monitoring systems provide detailed analysis of all network entities, then comprehensive network understanding is achieved, but system complexity increases making it difficult to manage and operate

Engineering Contradiction:
Improvenetwork understandingVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by providing detailed analysis and alert prioritization tailored to each device's specific importance and relationship context. Rather than treating all network entities uniformly, the system adjusts the level of detail and alert prominence based on each device's criticality, maintaining comprehensive network understanding while reducing the complexity burden on users by focusing detailed analysis only where needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11463299B2Ranking alerts based on network monitoring
Publication Date: 2022.10.04 EXTRAHOP NETWORKS INC
  • US11463299B2 patent drawing
  • US11463299B2 patent drawing
  • US11463299B2 patent drawing

AI summary

Embodiments are directed to monitoring network traffic. A monitoring engine may monitor network traffic associated with a plurality of entities in networks to provide metrics. And provide a device relation model based on the plurality of entities, the network traffic, and the metrics. An inference engine may associate each entity in the plurality of entities with an importance score based on the device relation model and the metrics such that each importance score is associated with a significance of an entity to operations of the networks. An alert engine may generate a plurality of alerts associated with the plurality of entities based on the metrics. And provide one or more alerts from the plurality of alerts to one or more users based on one or more ranked importance scores associated with one or more entities.