Policy-Based Network Alerting with Clustered Neural Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network management systems generate overwhelming numbers of alerts that can mask underlying issues, provide false positives, miss actual problems, or misattribute the source of issues due to device-specific conditions and predefined thresholds, making it difficult to manage complex networks effectively.

Innovation Solution

A machine learning-based assurance system that clusters network data into geographic, topological, and call flow clusters, correlates alerts, and dynamically adjusts alerting thresholds using unsupervised neural networks to identify shared nodes and transmit relevant alerts, reducing unnecessary alerts and improving network management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional alerting systems use device-specific conditions and predefined thresholds to monitor network health, then network monitoring coverage is improved, but alert quality deteriorates due to overwhelming numbers of false positives and maskings of underlying issues

Engineering Contradiction:
Improvenetwork monitoring coverageVSAvoidalert quality
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent combines multiple alerts into a single consolidated alert when they share common root causes. The system identifies clusters of related alerts and merges them into one comprehensive notification, reducing the overwhelming number of individual alerts while maintaining complete monitoring coverage. This directly addresses the contradiction by improving alert quality through consolidation without sacrificing monitoring precision.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal alerting mechanism that handles multiple types of network alerts through a single system. The alert correlation engine processes diverse alert types from different devices and sources using unified rules and machine learning models, enabling one system to perform multiple alert management functions simultaneously, thereby improving both coverage and reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If alerting thresholds are lowered to detect more network issues, then detection sensitivity is improved, but false positive rates increase causing overwhelming alert numbers

Engineering Contradiction:
Improvedetection sensitivityVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The patent implements feedback mechanisms where the system learns from alert patterns and adjusts threshold sensitivity dynamically. Machine learning models analyze historical alert data and feedback from operational responses to continuously refine detection thresholds, maintaining high sensitivity while reducing false positives through adaptive learning rather than static threshold settings.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary analysis and correlation of alerts before they reach the operator. By pre-processing alerts through clustering and root cause analysis, the system prepares consolidated information in advance, allowing lower detection thresholds without increasing false positives because the preliminary consolidation filter removes spurious alerts before they become problematic.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If network hierarchies become increasingly complex with more devices and functions, then network capability is improved, but alert management complexity increases making it difficult to identify underlying issues

Engineering Contradiction:
Improvenetwork capabilityVSAvoidalert management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the complex network alert management problem into distinct processing stages: alert collection, correlation clustering, root cause identification, and consolidated notification. This segmentation breaks down the overwhelming complexity of managing alerts from numerous devices by dividing the task into manageable components, each handled by specialized system functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an alert correlation engine as an intermediary between network devices and operators. This intermediary component processes, correlates, and consolidates alerts from the complex network infrastructure before presenting them to operators, acting as a buffer that simplifies the interface between complex network reality and operator perception.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Loss of information

If traditional systems transmit all generated alerts to service providers, then information completeness is improved, but bandwidth usage increases and relevance of alerts to administrators decreases

Engineering Contradiction:
Improveinformation completenessVSAvoidbandwidth usage
Core Design Contradiction:
Loss of informationVSLoss of energy

Solution Approach 1:

The patent extracts and removes redundant or correlated alerts from the complete alert set before transmission. By taking out duplicate or related alerts that have already been consolidated, the system reduces bandwidth usage while maintaining information completeness through selective extraction rather than transmitting all raw alerts.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary alert consolidation and filtering before transmission to administrators. By pre-processing alerts to combine related ones and remove duplicates in advance, the system ensures information completeness is preserved in the consolidated form while significantly reducing the bandwidth required for transmission compared to sending all individual alerts.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12380316B2Assurance of policy based alerting
Publication Date: 2025.08.05 CISCO TECHNOLOGY INC
  • US12380316B2 patent drawing
  • US12380316B2 patent drawing
  • US12380316B2 patent drawing

AI summary

Embodiments provide for assuring policy based alerting, via clustering, via a first neural network, operational data reported from a network into a plurality of anomalies organized into several clusters; correlating, via the first neural network, alerts received from devices in the network according to the several clusters; determining, via the second neural network, anomaly impacts in the several clusters from the filtered alerts; in response to determining that the anomaly impacts for a first cluster exceed an alerting threshold: identifying a first shared node in the first cluster; identifying a second cluster including a second shared node matching the first shared node that has not been determined to exceed the alerting threshold; and transmitting an alert for the first cluster and the second cluster; and in response to receiving a response to the alert, updating, via the second neural network, the first neural network.