CPC H04L 41/0636 (2013.01) [G06N 5/04 (2013.01); G06N 20/00 (2019.01); H04L 41/0681 (2013.01); H04L 63/1416 (2013.01); H04L 63/1441 (2013.01); H04L 63/20 (2013.01)] | 20 Claims |
1. A method, comprising:
receiving, by a device, alarm data identifying alarms associated with occurrences of an event;
determining, by the device, hit rates associated with the alarms of the alarm data;
determining, by the device, precisions associated with the alarms of the alarm data;
identifying, by the device, from the alarm data, and based on the hit rates and the precisions, a set of alarms that include false positives;
performing, by the device, feature engineering on the set of alarms to extract features from a feature store;
training, by the device, a model with the features to generate a trained model;
processing, by the device, the alarm data, with the trained model, to determine rules for reducing a quantity of future alarms that include the false positives;
identifying, by the device and from the rules for reducing the quantity of future alarms that include the false positives, a set of rules that satisfy a threshold for reducing the quantity of future alarms that include the false positives; and
performing, by the device, one or more actions based on the set of rules.
|