Cybersecurity UI Filtering Network Traffic by Domain Prevalence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security tools overwhelm users with vast amounts of network traffic data, making it difficult to quickly identify malicious or anomalous activity, as they often score "badness" without considering prevalence, resulting in thousands of potential threats to sift through.

Innovation Solution

A user interface with filters that allow users to filter network traffic data based on customer and global prevalence, internal traffic, first-time domain queries, and subdomains, minimizing irrelevant data and maximizing the visibility of important threats, enabling efficient identification of malicious behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security tools display all network traffic data with badness scoring, then comprehensive security coverage is achieved, but users are overwhelmed with vast amounts of data making it difficult to identify malicious activity

Engineering Contradiction:
Improvesecurity coverageVSAvoiddata analysis difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts and displays only the most relevant security events by applying multiple filtering criteria (prevalence, frequency, criticality) to the full network traffic dataset. This extraction principle allows the system to maintain comprehensive security coverage while presenting only the most suspicious activities to users, thereby resolving the contradiction between complete coverage and ease of analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different quality levels of filtering and scoring to different portions of the data based on their security relevance. High-prevalence, high-frequency events receive more aggressive filtering, while low-prevalence events are preserved with higher visibility. This local quality approach ensures comprehensive coverage while making the data more manageable by applying appropriate scrutiny levels to different data segments.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If security tools score badness of activities without considering prevalence, then individual threat assessment is improved, but the volume of potential threats to sort through increases dramatically

Engineering Contradiction:
Improvethreat assessment accuracyVSAvoidnumber of potential threats
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent changes the parameters used for threat assessment by incorporating prevalence and frequency metrics into the scoring system. Instead of relying solely on badness scoring, the system multiplies badness by prevalence and frequency factors, thereby transforming the assessment parameters to simultaneously improve accuracy while reducing the volume of threats requiring manual review.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent applies asymmetric weighting to different threat characteristics based on their security significance. High-prevalence events are weighted differently than low-prevalence events, and first-time occurrences receive special attention. This asymmetric approach improves threat assessment accuracy by emphasizing the most concerning patterns while reducing the apparent volume of threats through differentiated prioritization.

Inventive Principle:
Principle #4Asymmetry

3Measurement precision

If users spend hours sorting through data to find anomalous behavior, then thorough analysis is achieved, but response time to mitigate threats is significantly delayed

Engineering Contradiction:
Improvethreat detection thoroughnessVSAvoidthreat response time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary filtering, sorting, and scoring of network traffic data before presenting it to users. By pre-processing the data with multiple filtering criteria and badness scoring calculations, the system reduces the time users need to spend on manual analysis while maintaining thorough threat detection. This preliminary action resolves the contradiction by doing the heavy lifting before the user interaction phase.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the system continuously monitors network traffic, updates prevalence and frequency metrics, and dynamically adjusts the filtering and scoring. This feedback loop enables the system to maintain thorough threat detection while reducing response time by automatically adapting to changing threat patterns and prioritizing emerging anomalies without requiring manual re-analysis.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10958534B2User interfaces for presenting cybersecurity data
Publication Date: 2021.03.23 CHRONICLE LLC
  • US10958534B2 patent drawing
  • US10958534B2 patent drawing
  • US10958534B2 patent drawing

AI summary

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for surfacing anomalous network activity on a user interface. An example method provides, for presentation on a user device, a user interface for analyzing network traffic from a customer network. The user interface is populated with network traffic data from the customer network for display to the user. An interactive first filter that is configurable for filtering network traffic based on prevalence of the destination domains of the network traffic is displayed to the user. A first user input configuring the first filter to a first prevalence value is received. In response, the network traffic data is filtered in the user interface to only include network traffic data that has a destination domain that is less prevalent than the first prevalence value.