Systems and methods for generating, managing, and displaying alarms for wireless network monitoring
First Claim
1. A method of generating alarms for wireless network monitoring comprising the steps of:
- monitoring a wireless local area network;
receiving events responsive to the monitoring step, wherein the events relate to security in the wireless local area network;
correlating received events to triggers;
raising an alarm responsive to one or more triggers being above a pre-defined threshold value;
leaving the raised alarm unaffected by new events and new triggers correlated to the raised alarm thereby avoiding flooding of alarms based on a same event; and
maintaining the alarm for a predetermined time following the one or more triggers being below the pre-defined threshold value;
wherein the triggers are utilized in the method of generating alarms as an intermediate step between the received events and any associated alarm to reduce a volume of the generated alarms by correlating the received events with one another and with the generated alarms.
9 Assignments
0 Petitions
Accused Products
Abstract
The present disclosure is directed to systems and methods for generating, managing, and displaying alarms associated with monitoring a wireless network. Advantageously, the present disclosure provides one alarm per security event, and the ability to see an event in context over time and aggregate information. This results in a significant reduction in alarm volume for wireless monitoring which increases manageability and reduces storage requirements. Further, this provides better security by avoiding the “needle in the haystack” problem where you see few actionable alarms rather than being flooded by multiple copies of the same event over time. Finally, the present disclosure provides improved system scalability with large deployments by managing alarms through lesser alarm volume, and through visual representation.
-
Citations
20 Claims
-
1. A method of generating alarms for wireless network monitoring comprising the steps of:
-
monitoring a wireless local area network; receiving events responsive to the monitoring step, wherein the events relate to security in the wireless local area network; correlating received events to triggers; raising an alarm responsive to one or more triggers being above a pre-defined threshold value; leaving the raised alarm unaffected by new events and new triggers correlated to the raised alarm thereby avoiding flooding of alarms based on a same event; and maintaining the alarm for a predetermined time following the one or more triggers being below the pre-defined threshold value; wherein the triggers are utilized in the method of generating alarms as an intermediate step between the received events and any associated alarm to reduce a volume of the generated alarms by correlating the received events with one another and with the generated alarms. - View Dependent Claims (2, 3, 4, 5, 6, 19, 20)
-
-
7. A method of managing alarms for wireless network monitoring comprising the steps of:
-
receiving events from monitoring of a wireless local area network, wherein the events relate to security in the wireless local area network; correlating each received event to one or more triggers in which the received event participates, wherein the one or more triggers comprise a count of events of a pre-defined period; updating one or more trigger sets responsive to the one or more triggers; generating alarms over the pre-defined period responsive to each trigger being high in the one or more trigger sets; leaving generated alarms unaffected responsive to newly received events correlated to the generated alarms thereby avoiding flooding of alarms based on a same event; and handling alarms to update active and inactive alarms; wherein the one or more triggers are utilized in the method of managing alarms as an intermediate step between the received events and any associated alarm to reduce a volume of the generated alarms by correlating the received events with one another and with the generated alarms. - View Dependent Claims (8, 9, 10, 11, 12, 13)
-
-
14. An alarm manager display for a wireless network, comprising:
-
a server comprising a display; an alarm table listing alarms in the wireless network, wherein each alarm comprises a criticality, category, type, time, and wireless device; a network tree comprising logical groupings of wireless network devices; alarm information comprising detailed information about an alarm selected in the alarm table; and network alarm totals comprising a count of the total alarms in the wireless network and a pie chart depicting the breakdown of alarms by category and priority; wherein alarms in the alarm table can be filtered by alarm priority, device type, wireless channel, signal strength, device state, date and time, and alarm category and type; wherein alarms in the alarm table can be cleared by a user and kept cleared for a configurable time; and wherein the alarms are generated by the server based on the steps of; receiving events responsive to monitoring a wireless local area network comprising the wireless network devices, wherein the events relate to security in the wireless local area network; correlating received events to triggers; raising an alarm responsive to one or more triggers being above a pre-defined threshold value; leaving the raised alarm unaffected by new events and new triggers correlated to the raised alarm thereby avoiding flooding of alarms based on a same event; and maintaining the alarm for a predetermined time following the one or more triggers being below the pre-defined threshold value; wherein the one or more triggers are utilized as an intermediate step between the received events and any associated alarm to reduce a volume of generated alarms in the alarm manager by correlating the received events with one another and with the generated alarms. - View Dependent Claims (15, 16, 17, 18)
-
Specification