Ranking alerts based on network monitoring
First Claim
1. A method for monitoring network traffic using one or more network computers, wherein execution of instructions by the one or more network computers perform the method comprising:
- instantiating a monitoring engine to perform actions, including;
monitoring network traffic associated with a plurality of entities in one or more networks to provide one or more metrics; and
providing a device relation model based on the plurality of entities, the network traffic, and the one or more metrics; and
instantiating an inference engine to perform actions including associating each entity in the plurality of entities with an importance score based on the device relation model and the one or more metrics, wherein each importance score is based on a significance of an entity to one or more operations of the one or more networks and an importance of one or more other entities to the entity based on the one or more other entities and the entity being members of a same cluster and interacting with a same resource while non-communicating with each other; and
instantiating an alert engine to perform actions, including;
generating a plurality of alerts associated with the plurality of entities based on the one or more metrics;
providing feedback from one or more users regarding the plurality of entities, wherein the feedback includes one or more of user interaction history with one or more of the plurality of entities, importance of the user interaction with the one or more entities, or one or more roles of the one or more users that provided feedback; and
providing one or more ranked alerts to the one or more users based on the provided feedback from the one or more users and a ranking of the importance scores associated with one or more entities.
6 Assignments
0 Petitions
Accused Products
Abstract
Embodiments are directed to monitoring network traffic. A monitoring engine may monitor network traffic associated with a plurality of entities in networks to provide metrics. And provide a device relation model based on the plurality of entities, the network traffic, and the metrics. An inference engine may associate each entity in the plurality of entities with an importance score based on the device relation model and the metrics such that each importance score is associated with a significance of an entity to operations of the networks. An alert engine may generate a plurality of alerts associated with the plurality of entities based on the metrics. And provide one or more alerts from the plurality of alerts to one or more users based on one or more ranked importance scores associated with one or more entities.
244 Citations
28 Claims
-
1. A method for monitoring network traffic using one or more network computers, wherein execution of instructions by the one or more network computers perform the method comprising:
-
instantiating a monitoring engine to perform actions, including; monitoring network traffic associated with a plurality of entities in one or more networks to provide one or more metrics; and providing a device relation model based on the plurality of entities, the network traffic, and the one or more metrics; and instantiating an inference engine to perform actions including associating each entity in the plurality of entities with an importance score based on the device relation model and the one or more metrics, wherein each importance score is based on a significance of an entity to one or more operations of the one or more networks and an importance of one or more other entities to the entity based on the one or more other entities and the entity being members of a same cluster and interacting with a same resource while non-communicating with each other; and instantiating an alert engine to perform actions, including; generating a plurality of alerts associated with the plurality of entities based on the one or more metrics; providing feedback from one or more users regarding the plurality of entities, wherein the feedback includes one or more of user interaction history with one or more of the plurality of entities, importance of the user interaction with the one or more entities, or one or more roles of the one or more users that provided feedback; and providing one or more ranked alerts to the one or more users based on the provided feedback from the one or more users and a ranking of the importance scores associated with one or more entities. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A processor readable non-transitory storage media that includes instructions for monitoring network traffic using one or more network monitoring computers, wherein execution of the instructions by the one or more network computers perform the method comprising:
-
instantiating a monitoring engine to perform actions, including; monitoring network traffic associated with a plurality of entities in one or more networks to provide one or more metrics; and providing a device relation model based on the plurality of entities, the network traffic, and the one or more metrics; and instantiating an inference engine to perform actions including associating each entity in the plurality of entities with an importance score based on the device relation model and the one or more metrics, wherein each importance score is based on a significance of an entity to one or more operations of the one or more networks and an importance of one or more other entities to the entity based on the one or more other entities and the entity being members of a same cluster and interacting with a same resource while non-communicating with each other; and instantiating an alert engine to perform actions, including; generating a plurality of alerts associated with the plurality of entities based on the one or more metrics; providing feedback from one or more users regarding the plurality of entities, wherein the feedback includes one or more of user interaction history with one or more of the plurality of entities, importance of the user interaction with the one or more entities, or one or more roles of the one or more users that provided feedback; and providing one or more ranked alerts to the one or more users based on the provided feedback from the one or more users and a ranking of the importance scores associated with one or more entities. - View Dependent Claims (9, 10, 11, 12, 13, 14)
-
-
15. A system for monitoring network traffic in a network:
-
one or more network computers, comprising; a transceiver that communicates over the network;
a memory that stores at least instructions; andone or more processors that execute instructions that perform actions, including; instantiating a monitoring engine to perform actions, including; monitoring network traffic associated with a plurality of entities in one or more networks to provide one or more metrics; and providing a device relation model based on the plurality of entities, the network traffic, and the one or more metrics; and instantiating an inference engine to perform actions including associating each entity in the plurality of entities with an importance score based on the device relation model and the one or more metrics, wherein each importance score is based on a significance of an entity to one or more operations of the one or more networks and an importance of one or more other entities to the entity based on the one or more other entities and the entity being members of a same cluster and interacting with a same resource while non-communicating with each other; and instantiating an alert engine to perform actions, including; generating a plurality of alerts associated with the plurality of entities based on the one or more metrics; providing feedback from one or more users regarding the plurality of entities, wherein the feedback includes one or more of user interaction history with one or more of the plurality of entities, importance of the user interaction with the one or more entities, or one or more roles of the one or more users that provided feedback; and providing one or more ranked alerts to the one or more users based on the provided feedback from the one or more users and a ranking of the importance scores associated with one or more entities; and one or more client computers, comprising; a transceiver that communicates over the network; a memory that stores at least instructions; and one or more processors that execute instructions that perform actions, including; providing one or more portions of the network traffic. - View Dependent Claims (16, 17, 18, 19, 20, 21)
-
-
22. A network computer for monitoring communication over a network between two or more computers, comprising:
-
a transceiver that communicates over the network;
a memory that stores at least instructions; andone or more processors that execute instructions that perform actions, including; instantiating a monitoring engine to perform actions, including; monitoring network traffic associated with a plurality of entities in one or more networks to provide one or more metrics; and providing a device relation model based on the plurality of entities, the network traffic, and the one or more metrics; and instantiating an inference engine to perform actions including associating each entity in the plurality of entities with an importance score based on the device relation model and the one or more metrics, wherein each importance score is based on a significance of an entity to one or more operations of the one or more networks and an importance of one or more other entities to the entity based on the one or more other entities and the entity being members of a same cluster and interacting with a same resource while non-communicating with each other; and instantiating an alert engine to perform actions, including; generating a plurality of alerts associated with the plurality of entities based on the one or more metrics; providing feedback from one or more users regarding the plurality of entities, wherein the feedback includes one or more of user interaction history with one or more of the plurality of entities, importance of the user interaction with the one or more entities, or one or more roles of the one or more users that provided feedback; and providing one or more ranked alerts to the one or more users based on the provided feedback from the one or more users and a ranking of the importance scores associated with one or more entities. - View Dependent Claims (23, 24, 25, 26, 27, 28)
-
Specification