Communications Flow Analysis for Storage Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communications flow analysis systems face significant data storage and computational resource challenges due to the need to store and analyze large volumes of network traffic data in real-time, leading to high storage demands and lengthy analysis times, especially in environments like cloud-based datacenters with multiple high-speed communications links.

Innovation Solution

Implementing a real-time monitoring system that injects extraneous data sets into communications flows to identify and mark flows of interest, allowing for efficient data storage management by retaining relevant flows and removing unmarked flows, without compromising the integrity of the communications flow.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If all communications flows are stored for off-line analysis, then analysis completeness is improved, but storage resource consumption increases significantly

Engineering Contradiction:
Improveanalysis completenessVSAvoidstorage resource consumption
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system performs preliminary real-time monitoring and analysis of communications flows before storing them. During this preliminary phase, flows are analyzed for malicious, erratic, or non-compliant activity patterns. Only flows that exhibit suspicious characteristics are retained for storage and subsequent off-line analysis, while normal flows are discarded. This preliminary action significantly reduces the volume of data requiring storage without compromising the detection of malicious activity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system extracts and retains only the specific subset of communications flows that display malicious, erratic, or non-compliant characteristics from the overall data stream. By using real-time analysis to identify and extract only these problematic flows for storage, the system separates the useful information (suspicious flows) from the bulk data (normal flows), thereby reducing storage requirements while maintaining analysis completeness for security-relevant traffic.

Inventive Principle:
Principle #2Taking out (Extraction)

2Measurement precision

If real-time analysis is performed on all communications flows, then detection accuracy is improved, but computational resource consumption increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system applies partial action by performing real-time analysis with full detection accuracy only on a selected subset of communications flows that exhibit suspicious characteristics. Normal flows receive minimal processing or are discarded without comprehensive analysis. This approach achieves high detection accuracy for malicious activity while avoiding the computational overhead of analyzing every single flow in detail.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system applies different levels of analysis quality to different portions of the data stream. Suspicious flows identified through initial monitoring receive intensive real-time analysis with high detection accuracy, while normal flows receive minimal or no real-time analysis. This local differentiation of analysis quality optimizes computational resource allocation by concentrating processing power where it is most needed for security detection.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If communications flows are stored for off-line analysis, then analysis depth is improved, but analysis time increases

Engineering Contradiction:
Improveanalysis depthVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary real-time analysis during the flow's active transmission to identify suspicious patterns, characteristics, or anomalies. This preliminary assessment prepares the data for more efficient off-line analysis by pre-identifying flows that require deeper investigation. As a result, off-line analysis can focus on a pre-filtered set of suspicious flows, reducing the overall analysis time while maintaining or improving analysis depth for the most relevant cases.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8995271B2Communications flow analysis
Publication Date: 2015.03.31 TREND MICRO INC
  • US8995271B2 patent drawing
  • US8995271B2 patent drawing
  • US8995271B2 patent drawing

AI summary

In one implementation, a communications flow analysis system determines whether a communications flow between a source and a destination should be retained. If the communications flow should be retained, the communications flow analysis system injects an extraneous data set into the communications flow in response to determining that the communications flow should be retained.