Active Memory Security Analytics Platform for Real-Time Threat Neutralization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security tools are inadequate in providing real-time protection against malicious attacks, often reacting only after a security breach has occurred due to their reliance on database analysis and rule-based measures, which are slow and vulnerable to cyber threats.

Innovation Solution

An automated security analytics platform that utilizes an active memory to store and analyze network telemetry information in real-time, employing pluggable network security modules and incremental partial serialization to rapidly detect and neutralize threats, while optimizing memory and processing resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If conventional database servers are used to store and analyze network telemetry, then data storage and historical analysis are enabled, but real-time response speed is slow and security threats are detected only after breaches occur

Engineering Contradiction:
Improveresponse timeVSAvoidthreat detection speed
Core Design Contradiction:
Loss of timeVSProductivity

Solution Approach 1:

The patent replaces conventional database servers with an active memory-based system. Instead of using traditional disk-based relational databases that require complex queries and have slow read speeds, the invention uses active memory to store network telemetry in a format that enables direct, fast access by security modules. This substitution of the storage mechanism fundamentally improves response time and threat detection speed.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent segments the network telemetry data into discrete objects that can be independently processed by multiple security modules simultaneously. Each security module operates independently on specific portions of the data, enabling parallel processing and eliminating the bottleneck of sequential database queries. This segmentation allows real-time analysis without overwhelming a single central processing system.

Inventive Principle:
Principle #1Segmentation

2Reliability

If rule-based security measures are used to protect network resources, then known threats can be detected, but new and sophisticated attacks cannot be identified

Engineering Contradiction:
Improvesecurity protection accuracyVSAvoidcapability to detect new threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic security module architecture where modules can be automatically activated, deactivated, or modified based on real-time network conditions and detected threats. The system transitions from static rule-based security to dynamic analysis where security modules adapt their behavior based on the actual data patterns they observe, enabling detection of new and evolving threats without manual rule updates.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The security modules operate autonomously by directly analyzing network telemetry data without requiring centralized control or manual intervention. Each module independently evaluates network traffic against its detection capabilities and can trigger appropriate responses automatically. This self-service architecture enables the system to adapt to new threat patterns autonomously while maintaining reliable security protection.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If anomaly detection systems are deployed to identify new attack patterns, then detection capability improves, but data processing time increases and response is delayed

Engineering Contradiction:
Improvedetection capabilityVSAvoidanalysis time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent applies partial action by having security modules analyze only the specific portions of network telemetry data relevant to their detection capabilities rather than processing the entire dataset. Each module focuses on particular aspects of network traffic that are most indicative of threats, enabling efficient anomaly detection without the time penalty of full-data analysis. This selective processing maintains detection capability while reducing analysis time.

Inventive Principle:
Principle #16Partial or excessive action

4Productivity

If pluggable network security modules are implemented with active memory, then real-time threat neutralization is enabled, but system complexity increases

Engineering Contradiction:
Improvereal-time response capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent creates a universal active memory platform that can accommodate multiple types of security modules with different detection and response capabilities. The active memory system provides a common interface and data format that allows diverse security functions to coexist and operate efficiently. This universality simplifies the overall architecture by providing a single platform for multiple security functions rather than requiring separate complex systems for each security task.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8984633B2Automated security analytics platform with visualization agnostic selection linked portlets
Publication Date: 2015.03.17 ALERT LOGIC LLC
  • US8984633B2 patent drawing
  • US8984633B2 patent drawing
  • US8984633B2 patent drawing

AI summary

Visualization agnostic selection linked portlets provide a tree from a parent to one or more children that present each portlet with its own visualization and data synchronized with a root portlet based upon related filters. Each portlet uses its visualization to display a data set derived by applying its filter in conjunction with the filters of its ancestors. Each portlet then presents data that is at most the same size as its root in a visualization adapted to the child's type and quantity of data.