Network Alert Ranking via Device Relation Models
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In large-scale network monitoring environments, the vast amount of information generated by network monitoring systems makes it difficult for organizations to identify important alerts from numerous reports and alerts, leading to overwhelming and inefficient troubleshooting and management.
Innovation Solution
A network monitoring system that utilizes a monitoring engine to create a device relation model based on network traffic and metrics, with an inference engine assigning importance scores to entities based on their significance to the network operations, and an alert engine generating alerts prioritized by these scores to focus user attention on critical issues.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network monitoring systems monitor large-scale networks, then comprehensive network visibility is achieved, but the volume of alerts and information becomes overwhelming making it difficult to identify important issues
Solution Approach 1:
The patent extracts only the most critical alert information by analyzing device relationships and importance scores. The system processes vast amounts of network monitoring data to identify and separate out only the alerts that require attention, filtering out redundant or low-priority information while maintaining comprehensive network visibility.
Solution Approach 2:
The patent segments alerts into priority levels based on device importance scores and relationships. By dividing the alert stream into categorized priority levels, the system enables users to focus on critical issues first while maintaining awareness of overall network status without being overwhelmed by equal-volume low-priority alerts.
2Loss of information
If network monitoring systems generate detailed alerts for all network entities, then complete troubleshooting information is provided, but troubleshooting efficiency decreases due to the time required to review numerous alerts
Solution Approach 1:
The patent performs preliminary analysis of device relationships and calculates importance scores before generating alerts. This pre-computation of device criticality allows the system to automatically prioritize alerts in the correct sequence, so that when troubleshooting begins, the most important issues are already highlighted and ready for immediate attention, eliminating the need to review all alerts sequentially.
Solution Approach 2:
The system incorporates feedback loops that continuously monitor network conditions and adjust alert prioritization based on actual device relationships and operational impact. This feedback mechanism ensures that troubleshooting information is not only complete but also dynamically prioritized based on current network state, reducing the time required to identify and resolve issues.
3Reliability
If network monitoring systems provide detailed analysis of all network entities, then comprehensive network understanding is achieved, but system complexity increases making it difficult to manage and operate
Solution Approach 1:
The patent applies local quality by providing detailed analysis and alert prioritization tailored to each device's specific importance and relationship context. Rather than treating all network entities uniformly, the system adjusts the level of detail and alert prominence based on each device's criticality, maintaining comprehensive network understanding while reducing the complexity burden on users by focusing detailed analysis only where needed.
Data Source
AI summary
Embodiments are directed to monitoring network traffic. A monitoring engine may monitor network traffic associated with a plurality of entities in networks to provide metrics. And provide a device relation model based on the plurality of entities, the network traffic, and the metrics. An inference engine may associate each entity in the plurality of entities with an importance score based on the device relation model and the metrics such that each importance score is associated with a significance of an entity to operations of the networks. An alert engine may generate a plurality of alerts associated with the plurality of entities based on the metrics. And provide one or more alerts from the plurality of alerts to one or more users based on one or more ranked importance scores associated with one or more entities.


