Network Change Auditing via Workflow Contextual Grouping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network change auditing systems face challenges in efficiently investigating and understanding changes in information handling systems due to the large volume of network events, making it time-consuming for administrators to identify the source and reason behind changes, which hinders effective network management.
Innovation Solution
A network change auditing system that includes a communication system, a database for workflow definitions, and a processing system with a contextual grouping correlation engine to associate activity events with workflows, allowing administrators to quickly identify and understand changes by correlating activity events with defined workflows and providing tools to undo changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If network change auditing systems collect and store all network events for comprehensive auditing, then the completeness of audit data is improved, but the time required to investigate and identify specific changes increases significantly
Solution Approach 1:
The patent segments the large volume of network events into contextual groups based on workflow definitions. Instead of presenting all individual events, the system groups related events that constitute a complete workflow (e.g., a software update process involving multiple servers and events), allowing administrators to investigate changes at the workflow level rather than individually analyzing each event.
Solution Approach 2:
The patent introduces workflow definitions as an intermediary layer between raw network events and administrator analysis. These workflow definitions act as pre-defined templates that automatically correlate and group relevant events, serving as a mediator that translates complex event data into meaningful contextual information without requiring administrators to manually analyze each event.
2Measurement precision
If administrators manually filter through collected network event data to identify changes, then comprehensive analysis is achieved, but productivity is significantly reduced due to the tedious and time-consuming nature of the task
Solution Approach 1:
The patent implements preliminary action by pre-defining workflow definitions that specify which events are related and how they should be grouped. These workflow definitions are created in advance and stored in the system, enabling automatic contextual grouping of events without requiring administrators to perform manual filtering or analysis when investigating changes.
Solution Approach 2:
The system performs self-service by automatically correlating and grouping network events according to pre-defined workflow definitions. The contextual grouping correlation engine autonomously processes incoming events, matches them against workflow definitions, and generates contextual groups without administrator intervention, thereby maintaining accuracy while eliminating manual labor.
3Loss of information
If the system provides detailed information about all network events, then the completeness of audit information is improved, but the complexity of the auditing interface and data presentation increases
Solution Approach 1:
The patent merges multiple individual network events into unified contextual groups representing complete workflows. Instead of presenting separate events (e.g., file transfer, authentication, process execution), the system combines them into a single contextual workflow representation, reducing interface complexity while preserving all underlying event information for detailed analysis when needed.
Data Source
AI summary
A network includes a workflow management system coupled to an administrator device, and servers coupled to a user device. A network change auditing system receives and stores workflow definitions from the workflow management system that are associated with respective workflows provided by the servers. The network change auditing system receives and stores activity events from the servers that are associated with instructions from user devices to the servers. The network change auditing system associates a first subset of the activity events with a first workflow based on the first subset of the activity events being defined by a first workflow definition. The network change auditing system receives an identification of a first activity event from an administrator device and, in response, provides an identification of the first workflow and at least one second activity event in the first subset of the activity events for display on the administrator device.


