Telemetry Data Classification for Service Ticket Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current service ticket systems lack effective mechanisms to detect and alert on suspicious or malicious activities performed on devices, especially when these activities are not directly related to reported issues.
Innovation Solution
A system that integrates telemetry data and service ticket data using classification modules and natural language processing to determine the likelihood that device activities are in response to legitimate service requests, generating alerts for suspicious or malicious activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If service ticket systems only track reported issues, then the system remains simple and easy to operate, but it cannot detect suspicious or malicious activities that are not related to reported issues
Solution Approach 1:
The patent combines telemetry data from devices with service ticket data in a unified analysis system. The telemetry data processor receives both data streams and integrates them to perform comprehensive activity analysis, enabling detection of suspicious activities beyond just tracked issues while maintaining a cohesive system architecture.
Solution Approach 2:
The patent introduces classification modules as intermediaries that process and categorize both telemetry data and service ticket data. These classifiers act as mediators that translate raw data into comparable formats, enabling the system to detect suspicious activities without requiring direct complex interactions between all system components.
2Measurement precision
If the system analyzes all device activities in detail, then detection precision improves, but processing time and computational resources increase
Solution Approach 1:
The patent applies different analysis depths to different types of activities based on their risk profiles. High-risk activities receive detailed scrutiny with multiple classification stages, while routine activities undergo faster processing. This localized quality approach maintains high detection precision for critical activities while reducing overall processing time.
Solution Approach 2:
The system performs partial analysis on all activities and excessive (detailed) analysis only on suspicious or high-risk activities. The telemetry data processor initially screens all activities, then applies more rigorous classification only to those that warrant deeper investigation, optimizing the balance between detection precision and processing efficiency.
Data Source
AI summary
An apparatus and method is described comprising: classifying service ticket data relating to a service request into a service topic, wherein the service ticket data is obtained from the service request relating to a device; determining, for the service request, an extent to which the service topic matches a telemetry data class, wherein the telemetry data class relates to activities at the device; and providing an output according to said determination.


