Telemetry Data Classification for Service Ticket Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current service ticket systems lack effective mechanisms to detect and alert on suspicious or malicious activities performed on devices, especially when these activities are not directly related to reported issues.

Innovation Solution

A system that integrates telemetry data and service ticket data using classification modules and natural language processing to determine the likelihood that device activities are in response to legitimate service requests, generating alerts for suspicious or malicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If service ticket systems only track reported issues, then the system remains simple and easy to operate, but it cannot detect suspicious or malicious activities that are not related to reported issues

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines telemetry data from devices with service ticket data in a unified analysis system. The telemetry data processor receives both data streams and integrates them to perform comprehensive activity analysis, enabling detection of suspicious activities beyond just tracked issues while maintaining a cohesive system architecture.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces classification modules as intermediaries that process and categorize both telemetry data and service ticket data. These classifiers act as mediators that translate raw data into comparable formats, enabling the system to detect suspicious activities without requiring direct complex interactions between all system components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If the system analyzes all device activities in detail, then detection precision improves, but processing time and computational resources increase

Engineering Contradiction:
Improveactivity detection precisionVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies different analysis depths to different types of activities based on their risk profiles. High-risk activities receive detailed scrutiny with multiple classification stages, while routine activities undergo faster processing. This localized quality approach maintains high detection precision for critical activities while reducing overall processing time.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs partial analysis on all activities and excessive (detailed) analysis only on suspicious or high-risk activities. The telemetry data processor initially screens all activities, then applies more rigorous classification only to those that warrant deeper investigation, optimizing the balance between detection precision and processing efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12265610B2Telemetry data
Publication Date: 2025.04.01 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US12265610B2 patent drawing
  • US12265610B2 patent drawing
  • US12265610B2 patent drawing

AI summary

An apparatus and method is described comprising: classifying service ticket data relating to a service request into a service topic, wherein the service ticket data is obtained from the service request relating to a device; determining, for the service request, an extent to which the service topic matches a telemetry data class, wherein the telemetry data class relates to activities at the device; and providing an output according to said determination.