IP Library Granted Patent US 12705969
Granted Patent B2
US 12705969 · App. 18/754,194 · Granted Aug 11, 2026

System and method for optimizing alerts for a user technological field

Inventor: Noam Pettel (Kochav Yair, IL)
Assignee: HONEYWELL INTERNATIONAL INC.
G08B21/182G08B21/10G08B27/005
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12705969
App. No.
18/754,194
Granted
Aug 11, 2026
Kind
B2
Abstract

A method for optimizing alerts for a user is disclosed. The method comprises monitoring a plurality of alerts of one or more alert types within a predefined time period; determining a count of the plurality of alerts of each alert type within the predefined time period; determining the count of the plurality of alerts of each alert type exceeds a predefined threshold level within the predefined time period; triggering a storm alert corresponding to the plurality of alerts of each alert type upon determining the count of the plurality of alerts of each alert type exceeds the predefined threshold level, wherein the storm alert corresponds to an alert triggered when the plurality of alerts of each alert type is occurred multiple times within the predefined time period; and displaying a notification related to the storm alert and information related to the storm alert, to a user.

Claims (37)

1 . A method comprising:

monitoring, via at least one processor, a plurality of alerts of one or more alert types within a predefined time period, wherein the one or more alert types comprises at least one of threat alerts, asset management alerts, exposure alerts, health alerts, or operational alerts;

determining, via the at least one processor, a count of the plurality of alerts of each alert type of the one or more alert types within the predefined time period, wherein the count corresponds to a number of occurrences of the plurality of alerts of each alert type within the predefined time period;

determining, via the at least one processor, the count of the plurality of alerts of each alert type exceeds a predefined threshold level within the predefined time period, wherein the predefined threshold level corresponds to a maximum number of alerts of each alert type allowable within the predefined time period;

triggering, via the at least one processor, a storm alert corresponding to the plurality of alerts of each alert type upon determining the count of the plurality of alerts of each alert type exceeds the predefined threshold level within the predefined time period, wherein the storm alert corresponds to an alert triggered when the plurality of alerts of each alert type occurred multiple times within the predefined time period;

suppressing, via the at least one processor, the plurality of alerts of each alert type subsequent to the storm alert within the predefined time period, based at least on the determined severity level of the storm alert; and

displaying, via the at least one processor, a notification related to the storm alert and information related to the storm alert, to a user, wherein the information related to the storm alert comprises a severity level of the storm alert, an identifier, at least description of the storm alert, internet protocol (IP) address, or last event time.

2 . The method of claim 1 further comprising determining, via the at least one processor, the severity level of the storm alert based at least on a severity level of the plurality of alerts of each alert type that triggers a storm condition and a maximum severity level of the storm alert.

3 . The method of claim 1 , wherein the threat alerts correspond to alerts related to security threats, the asset management alerts correspond to alerts concerning asset management, the exposure alerts correspond to alerts related to exposure risks, the health alerts correspond to alerts concerning health of infrastructure components, and the operational alerts correspond to alerts related to operational issues.

4 . The method of claim 1 , wherein the severity level of the storm alert is configured to prioritize the storm alert over the plurality of alerts of each alert type within the predefined time period.

5 . The method of claim 1 , wherein the storm alert is triggered to indicate a potential abnormal condition or an unauthorized activity.

6 . The method of claim 1 , wherein the predefined time period comprises at least one of minutes, hours, weeks, days, or years.

7 . A system comprising:

a memory; and

at least one processor communicatively coupled to the memory, wherein the at least one processor is configured to:

monitor a plurality of alerts of one or more alert types within a predefined time period, wherein the one or more alert types comprises at least one of threat alerts, asset management alerts, exposure alerts, health alerts, or operational alerts;

determine a count of the plurality of alerts of each alert type of the one or more alert types within the predefined time period, wherein the count corresponds to a number of occurrences of the plurality of alerts of each alert type within the predefined time period;

determine the count of the plurality of alerts of each alert type exceeds a predefined threshold level within the predefined time period, wherein the predefined threshold level corresponds to a maximum number of alerts of each alert type allowable within the predefined time period;

trigger a storm alert corresponding to the plurality of alerts of each alert type upon determining the count of the plurality of alerts of each alert type exceeds the predefined threshold level within the predefined time period, wherein the storm alert corresponds to an alert triggered when the plurality of alerts of each alert type occurred multiple times within the predefined time period;

suppress the plurality of alerts of each alert type subsequent to the storm alert within the predefined time period, based at least on the determined severity level of the storm alert; and

display a notification related to the storm alert and information related to the storm alert, to a user, wherein the information related to the storm alert comprises a severity level of the storm alert, an identifier, at least description of the storm alert, internet protocol (IP) address, or last event time.

8 . The system of claim 7 , wherein the at least one processor is further configured to determine the severity level of the storm alert based at least on a severity level of the plurality of alerts of each alert type that triggers a storm condition and a maximum severity level of the storm alert.

9 . The system of claim 7 , wherein the threat alerts correspond to alerts related to security threats, the asset management alerts correspond to alerts concerning asset management, the exposure alerts correspond to alerts related to exposure risks, the health alerts correspond to alerts concerning health of infrastructure components, and the operational alerts correspond to alerts related to operational issues.

10 . The system of claim 7 , wherein the severity level of the storm alert is configured to prioritize the storm alert over the plurality of alerts of each alert type within the predefined time period.

11 . The system of claim 7 , wherein the storm alert is triggered to indicate a potential abnormal condition or an unauthorized activity.

12 . The system of claim 7 , wherein the predefined time period comprises at least one of minutes, hours, weeks, days, or years.

13 . A non-transitory machine-readable information storage medium comprising one or more instructions which when executed by at least one processor causes the at least one processor to:

monitor a plurality of alerts of one or more alert types within a predefined time period, wherein the one or more alert types comprises at least one of threat alerts, asset management alerts, exposure alerts, health alerts, or operational alerts;

determine a count of the plurality of alerts of each alert type of the one or more alert types within the predefined time period, wherein the count corresponds to a number of occurrences of the plurality of alerts of each alert type within the predefined time period;

determine the count of the plurality of alerts of each alert type exceeds a predefined threshold level within the predefined time period, wherein the predefined threshold level corresponds to a maximum number of alerts of each alert type allowable within the predefined time period;

trigger a storm alert corresponding to the plurality of alerts of each alert type upon determining the count of the plurality of alerts of each alert type exceeds the predefined threshold level within the predefined time period, wherein the storm alert corresponds to an alert triggered when the plurality of alerts of each alert type occurred multiple times within the predefined time period;

suppress the plurality of alerts of each alert type subsequent to the storm alert within the predefined time period, based at least on the determined severity level of the storm alert; and

display a notification related to the storm alert and information related to the storm alert, to a user, wherein the information related to the storm alert comprises a severity level of the storm alert, an identifier, at least description of the storm alert, internet protocol (IP) address, or last event time.

14 . The non-transitory machine-readable information storage medium of claim 13 , wherein the at least one processor is further configured to determine the severity level of the storm alert based at least on a severity level of the plurality of alerts of each alert type that triggers a storm condition and a maximum severity level of the storm alert.

15 . The non-transitory machine-readable information storage medium of claim 13 , wherein the threat alerts correspond to alerts related to security threats, the asset management alerts correspond to alerts concerning asset management, the exposure alerts correspond to alerts related to exposure risks, the health alerts correspond to alerts concerning health of infrastructure components, and the operational alerts correspond to alerts related to operational issues.

16 . The non-transitory machine-readable information storage medium of claim 13 , wherein the severity level of the storm alert is configured to prioritize the storm alert over the plurality of alerts of each alert type within the predefined time period.

17 . The non-transitory machine-readable information storage medium of claim 13 , wherein the storm alert is triggered to indicate a potential abnormal condition or an unauthorized activity.