Active Memory for Network Telemetry Analytics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security tools are inadequate in detecting and responding to malicious attacks in real-time due to their reliance on database analysis, which leads to delayed responses and vulnerabilities, allowing cybercriminals to penetrate and access sensitive information.

Innovation Solution

An automated security analytics platform that utilizes an active memory to store and analyze network telemetry information, enabling real-time threat neutralization through pluggable network security modules and visualization-agnostic selection linked portlets for rapid data processing and visualization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If conventional database servers are used to store and analyze network telemetry information, then data storage capacity is sufficient, but response time is delayed and real-time threat detection is inadequate

Engineering Contradiction:
Improveresponse timeVSAvoidtime lag in identifying security breaches
Core Design Contradiction:
SpeedVSLoss of time

Solution Approach 1:

The patent introduces an active memory component as an intermediary between network sensors and analysis modules. This active memory serves as a high-speed buffer that temporarily stores network telemetry information, enabling rapid access and analysis without the delays inherent in conventional database servers. The active memory acts as a mediator that bridges the gap between data collection and real-time analysis, resolving the contradiction between storage capacity and response speed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If network telemetry information is stored in active memory for real-time analysis, then response speed improves, but memory resource consumption increases

Engineering Contradiction:
Improvereal-time data processing speedVSAvoidactive memory resource consumption
Core Design Contradiction:
SpeedVSQuantity of substance

Solution Approach 1:

The patent extracts only the most critical and recently generated network telemetry information into active memory for real-time analysis, rather than storing all collected data. This selective extraction approach ensures that active memory resources are dedicated to high-priority security events that require immediate attention, while less critical data remains in conventional storage. This resolves the contradiction by taking out only the necessary portion of data into active memory.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If comprehensive network monitoring is implemented to detect all potential threats, then security coverage is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by configuring different analysis modules with specialized detection capabilities tailored to specific types of security threats. Each module can be independently optimized for particular protocols, application layers, or threat patterns, allowing comprehensive security coverage without requiring a single monolithic complex system. This modular approach with differentiated local capabilities resolves the contradiction between comprehensive coverage and system complexity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10200388B2Automated security analytics platform with multi-level representation conversion for space efficiency and incremental persistence
Publication Date: 2019.02.05 ALERT LOGIC LLC
  • US10200388B2 patent drawing
  • US10200388B2 patent drawing
  • US10200388B2 patent drawing

AI summary

Active memory for managing network telemetry information, or other types of information stored as objects, has objects partially-serialized to allow greater amounts of information to store in a memory of a given size with slightly increased retrieval times. Storing additional information in an active memory provides an overall increase in network security platform responsiveness by allowing a greater amount of information to be accessible from the active memory instead of archive.