3D Network Security Visualization System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network monitoring systems are limited in presenting comprehensive and correlated security event data to human analysts, leading to inefficiencies in intrusion detection and response due to reliance on two-dimensional visualizations and the need for manual correlation of complex network events.

Innovation Solution

A network security monitoring and correlation system utilizing mixed reality techniques to provide three-dimensional visualizations of network traffic and security alerts, allowing analysts to intuitively understand and prioritize security responses by overlaying relevant data onto a 3D environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If two-dimensional data visualizations are used to present security information, then the system is simple to implement, but the amount of data that can be displayed to analysts is limited

Engineering Contradiction:
Improveamount of data displayedVSAvoidvisualization system complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent transitions from two-dimensional spreadsheet visualizations to three-dimensional virtual environment visualizations. This dimensional change allows analysts to view and interact with security data in a spatial context, dramatically increasing the amount of information that can be displayed and correlated simultaneously without proportionally increasing system complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Loss of information

If traditional monitoring systems are used, then the system structure is simple, but the correlation of security events between multiple systems over time is limited

Engineering Contradiction:
Improvesecurity event correlationVSAvoidsystem architecture complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent merges multiple security event data sources and time periods into a single integrated three-dimensional virtual environment. Different security systems, networks, and temporal data are combined into one cohesive visualization, allowing analysts to correlate events across multiple systems and timeframes without managing separate complex analysis tools.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The three-dimensional virtual environment acts as an intermediary layer between raw security data and human analysts. This intermediary automatically performs complex correlations, spatial relationships, and temporal analyses, presenting processed information in an intuitively understandable format without requiring analysts to manually correlate events across multiple systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If detailed security analysis is performed manually, then accurate security assessment is achieved, but the time required for analysis increases

Engineering Contradiction:
Improvesecurity analysis speedVSAvoidtime for security response
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically organizing, correlating, and visualizing security data before analyst review. Data from multiple sources is pre-processed, spatially organized, and temporally aligned in the three-dimensional environment, so when analysts access the system, the heavy lifting of data correlation has already been completed, enabling faster decision-making.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12199846B2Network security monitoring and correlation system and method of using
Publication Date: 2025.01.14 VIEWPOINT SOFTWARE LLC
  • US12199846B2 patent drawing
  • US12199846B2 patent drawing
  • US12199846B2 patent drawing

AI summary

A network security monitoring and correlation system for providing a three-dimensional visualization of network traffic overlaid with security alerts and other relevant discrete data. The system may comprise an application server communicably linked to a client. The server functions to retrieve network traffic metadata and relevant discrete data associated with individual computer hosts and connections in the monitored network, process the network traffic data by building a graph data structure, and then embedding within the graph data structure one or more layers of additional information about the individual computer hosts and connections derived from the discrete data. The client functions to produce a three-dimensional visualization of the network environment by parsing the graph data structure received from the server and then spawning computer hosts and connections in the 3-D environment. The client will then add the overlay information to the appropriate hosts or connections, with the overlay information preferably being represented within the 3-D environment as a particular color, shape, size, position, or a changing dynamic value.