Active Memory for Network Telemetry Analytics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network security tools are inadequate in detecting and responding to malicious attacks in real-time due to their reliance on database analysis, which leads to delayed responses and vulnerabilities, allowing cybercriminals to penetrate and access sensitive information.
Innovation Solution
An automated security analytics platform that utilizes an active memory to store and analyze network telemetry information, enabling real-time threat neutralization through pluggable network security modules and visualization-agnostic selection linked portlets for rapid data processing and visualization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If conventional database servers are used to store and analyze network telemetry information, then data storage capacity is sufficient, but response time is delayed and real-time threat detection is inadequate
Solution Approach 1:
The patent introduces an active memory component as an intermediary between network sensors and analysis modules. This active memory serves as a high-speed buffer that temporarily stores network telemetry information, enabling rapid access and analysis without the delays inherent in conventional database servers. The active memory acts as a mediator that bridges the gap between data collection and real-time analysis, resolving the contradiction between storage capacity and response speed.
2Speed
If network telemetry information is stored in active memory for real-time analysis, then response speed improves, but memory resource consumption increases
Solution Approach 1:
The patent extracts only the most critical and recently generated network telemetry information into active memory for real-time analysis, rather than storing all collected data. This selective extraction approach ensures that active memory resources are dedicated to high-priority security events that require immediate attention, while less critical data remains in conventional storage. This resolves the contradiction by taking out only the necessary portion of data into active memory.
3Reliability
If comprehensive network monitoring is implemented to detect all potential threats, then security coverage is improved, but system complexity and processing overhead increase
Solution Approach 1:
The patent applies local quality by configuring different analysis modules with specialized detection capabilities tailored to specific types of security threats. Each module can be independently optimized for particular protocols, application layers, or threat patterns, allowing comprehensive security coverage without requiring a single monolithic complex system. This modular approach with differentiated local capabilities resolves the contradiction between comprehensive coverage and system complexity.
Data Source
AI summary
Active memory for managing network telemetry information, or other types of information stored as objects, has objects partially-serialized to allow greater amounts of information to store in a memory of a given size with slightly increased retrieval times. Storing additional information in an active memory provides an overall increase in network security platform responsiveness by allowing a greater amount of information to be accessible from the active memory instead of archive.


