Proximity-Based Network Event Clustering for Issue Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The overwhelming number of logged events in IT networks obscures underlying network issues, as current reporting methods fail to consider higher abstractions such as technology domains or event proximity, making it difficult for administrators to identify and address network problems efficiently.
Innovation Solution
A system that groups events based on determined proximity in multiple dimensions, including time, physical space, and communication protocol, using weighted distances to cluster events into groups, with a scoring mechanism to determine group membership.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If events are reported based on network component and presented in chronological order, then events are easily collected and stored, but the overwhelming number of events obscures underlying network issues and makes problem identification difficult
Solution Approach 1:
The patent segments events into clusters based on proximity in multiple dimensions (time, physical space, virtual space, communication protocol). This segmentation transforms the overwhelming list of individual events into organized groups, making it easier to identify patterns and underlying issues while maintaining comprehensive event coverage.
Solution Approach 2:
The patent introduces multiple abstraction dimensions beyond traditional chronological ordering, including physical space, virtual space, and communication protocol dimensions. This dimensional expansion allows events to be viewed from multiple perspectives simultaneously, revealing relationships and patterns that are not visible in single-dimension views.
2Difficulty of detecting and measuring
If events are grouped into clusters based on multiple dimensions, then network problems become easier to identify, but the complexity of the grouping mechanism increases
Solution Approach 1:
The patent implements a universal clustering mechanism that handles multiple event types and dimensions through a single integrated framework. The same proximity-based algorithm works across time, physical space, virtual space, and protocol dimensions, reducing overall system complexity while maintaining comprehensive problem detection capabilities.
Solution Approach 2:
The patent introduces an intermediary clustering layer between raw event collection and problem identification. This intermediary layer automatically groups events based on proximity metrics, acting as a mediator that simplifies the relationship between individual events and underlying issues, thereby reducing the cognitive load on network administrators.
3Measurement precision
If multiple dimensions are considered for event grouping, then higher abstractions and event proximity are captured, but the computational requirements and processing time increase
Solution Approach 1:
The patent applies partial action by considering only the most relevant dimensions for each specific event clustering task, rather than uniformly processing all possible dimensions. This selective approach maintains measurement precision for critical dimensions while reducing unnecessary computational overhead in less relevant dimensions.
Data Source
AI summary
Methods and devices for grouping events in a network are disclosed. The method includes receiving notification of a first event that includes attributes of the first event; determining a score between the first event and a second event; and grouping the first event and the second event into a first group based on the score. The method includes determining a first distance in a first dimension between the first event and the second event and calculating the score based on the first distance. The method further includes displaying the first group on a user interface (UI).


