Semantic Clustering Engine for Event Decomposition in Managed Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing and organizing large volumes of messages and events from managed infrastructures, such as emails and network traffic, face challenges in effective clustering and fault localization, leading to difficulties in retrieving relevant information and reducing spam, due to the lack of automated and efficient semantic clustering techniques.

Innovation Solution

A system employing a data-driven approach with a clustering engine that uses semantic clustering to analyze text descriptions of events in a sliding window of data, identifying common characteristics and producing clusters related to failures or errors in managed infrastructures, and operates in a streaming manner to provide real-time fault localization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual organization of messages and events into folders is used, then information can be sorted by topic, but the process becomes impractical when handling massive amounts of web-based information generated daily

Engineering Contradiction:
Improveinformation organization efficiencyVSAvoidtime required for manual sorting
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system enables automated self-service organization of events by extracting attributes from event data and automatically clustering them into groups without human intervention. The clustering engine processes events autonomously, identifying patterns and creating organized structures based on semantic similarity, thereby eliminating the need for manual folder sorting while handling massive volumes of information.

Inventive Principle:
Principle #25Self-service

2Productivity

If automated clustering techniques are implemented, then information organization becomes efficient at scale, but the system complexity increases

Engineering Contradiction:
Improveautomated information processing capacityVSAvoidsystem architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments the complex clustering task into distinct modular components: an extraction engine that identifies attributes from raw event data, a clustering engine that groups events based on semantic similarity, and a situation model that organizes clusters into meaningful structures. This segmentation reduces overall system complexity by creating independent, specialized modules that can be developed and maintained separately.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediate data structures and processing layers between raw event input and final organized output. The extraction engine creates structured attribute representations as intermediaries, and the situation model serves as an intermediary layer that synthesizes clustering results into coherent organizational structures, thereby managing complexity through staged processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If traditional folder-based organization is used, then messages can be stored in designated locations, but tasks become invisible and easily neglected

Engineering Contradiction:
Improvemessage storage organizationVSAvoidtask visibility and awareness
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The system creates multi-functional event groups that simultaneously serve as storage containers and active task management structures. Each clustered group of events can be viewed as a situational context that combines information archiving with task tracking capabilities, allowing users to monitor and manage tasks within the same organizational structure used for information storage, thereby preventing tasks from becoming invisible.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If semantic clustering is applied to decompose events, then fault localization accuracy improves, but the computational processing requirements increase

Engineering Contradiction:
Improvefault localization accuracyVSAvoidcomputational processing energy
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system applies partial semantic clustering by focusing extraction and clustering operations on specific attributes most relevant to fault localization rather than processing all event attributes uniformly. The extraction engine selectively identifies key attributes, and the clustering engine applies semantic analysis only to those critical attributes, achieving adequate fault localization accuracy while reducing unnecessary computational overhead.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10693707B2System for decomposing events from managed infrastructures with semantic clustering
Publication Date: 2020.06.23 DELL PROD LP
  • US10693707B2 patent drawing
  • US10693707B2 patent drawing
  • US10693707B2 patent drawing

AI summary

A system is provided for decomposing events from managed infrastructures. A first engine is configured to receive message data from a managed infrastructure that includes managed infrastructure physical hardware that supports the flow and processing of information, the at least one engine is configured to determine common characteristics of events and produce clusters of events relating to the failure of errors in the managed infrastructure. Membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in a physical hardware of the managed infrastructure directed to supporting the flow and processing of information. The first engine is configured to create one or more situations that is a collection of one or more events or alerts representative of the actionable problem in the managed infrastructure. A second engine is configured to determine one or more common steps from events and produces clusters relating to events. The second engine determines one or more common characteristics of events and produces clusters of events relating to the failure or errors in the managed infrastructure. The system is configured to use data-driven fault localization, more particularly using semantic clustering.