Method and system for reducing false alarms in network fault management systems
First Claim
1. A method for improving diagnosis of a complex problem, wherein a plurality of indicators expected to relate to the problem are correlated over a window of time, the window of time comprising a plurality of time slices in each of which a state of each indicator is determined, the method comprising:
- determining which indicator or indicators changed state during a fist time slice in the window and which indicator or indicators did not change state during the first time slice;
computing a time slice transition factor based upon a number of indicators whose state changed and a number of indicators whose state did not change during the first time slice; and
adjusting the correlation of the indicators over the window of time using the time slice transition factor.
3 Assignments
0 Petitions
Accused Products
Abstract
Methods and systems are described for reducing the number of false alarms in fault correlation software used to detect and diagnose faults in computer networks and similar systems. The fault correlation software includes rules that monitor a number of indicators that, if occurring together over a window of time, are known to cause or reflect the occurrence of a fault. The method involves monitoring the transition of these indicators from one state to another over the time window and determining the extent of the correlation of the transitions of the indicators. The determination that indicators monitored by a rule do not correlate closely in their transitions is used to reduce the likelihood of the rule finding correlation of the indicators as a whole. This in turn reduces the number of false alarms which the rule-based system might otherwise have transmitted.
183 Citations
59 Claims
-
1. A method for improving diagnosis of a complex problem, wherein a plurality of indicators expected to relate to the problem are correlated over a window of time, the window of time comprising a plurality of time slices in each of which a state of each indicator is determined, the method comprising:
-
determining which indicator or indicators changed state during a fist time slice in the window and which indicator or indicators did not change state during the first time slice;
computing a time slice transition factor based upon a number of indicators whose state changed and a number of indicators whose state did not change during the first time slice; and
adjusting the correlation of the indicators over the window of time using the time slice transition factor. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13)
-
-
14. In a system for analyzing faults in devices by correlating a plurality of indicators over a window of time and generating alarms based upon the correlation, the window of time comprising a plurality of time slices in each of which a state of each indicator is probed, a method for reducing false alarms comprising:
-
determining which of the indicators changed state in similar fashion during a first time slice in the window or did not change state during the first time slice;
computing a time slice transition factor that relates a number of the indicators whose state changed in similar fashion or did not change during the first time slice to a total number of the indicators; and
adjusting the correlation of the indicators over the window of time using the time slice transition factor. - View Dependent Claims (15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26)
-
-
27. A computer readable medium storing program code which, when executed, causes a computer to perform a method for reducing false alarms in a system for analyzing problems by correlating a plurality of indicators over a window of time and generating alarms based upon the correlation, the window of time comprising a plurality of time slices in each of which a slate of each indicator is probed, the method comprising:
-
determining which of the indicators changed state in similar fashion during a first time slice in the window or did not change state during the first time slice;
computing a time slice transition factor that relates a number of the indicators whose state changed in similar fashion or did not change during the first time slice to a total number of the indicators; and
adjusting the correlation of the indicators over the window of time using the time slice transition factor. - View Dependent Claims (28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39)
-
-
40. A method for correlating a number of indicators in a rules-based correlation system, wherein a plurality of indicators each having multiple possible values and expected to relate to a problem are correlated over a window of time, the method comprising:
-
dividing the window of time into a plurality of time slices;
determining a value for each indicator during each of a plurality of the time slices;
determining a transition state for each indicator during each of the plurality of time slices, the transition state representing whether and bow the indicator changed state during the time slice; and
correlating the indicators over the window of time based upon the determined indicator values and transitions states. - View Dependent Claims (41, 42, 43, 44, 45, 46, 47, 48, 49)
-
-
50. A computer readable medium storing program code which, when executed, causes a computer to perform a method for correlating a number of indicators in a rules-based correlation system, wherein a plurality of indicators each having multiple possible values and expected to relate to a problem arc correlated over a window of limit, the method comprising:
-
dividing the window of time into a plurality of time slices;
determining a value for each indicator during each of a plurality of the time slices;
determining a transition state for each indicator during each of the plurality of time slices, the transition state representing whether and how the indicator changed state during the time slice; and
correlating the indicators over the window of time based upon the determined indicator values and transitions states. - View Dependent Claims (51, 52, 53, 54, 55, 56, 57, 58, 59)
-
Specification