Cybersecurity UI Filtering Network Traffic by Domain Prevalence
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security tools overwhelm users with vast amounts of network traffic data, making it difficult to quickly identify malicious or anomalous activity, as they often score "badness" without considering prevalence, resulting in thousands of potential threats to sift through.
Innovation Solution
A user interface with filters that allow users to filter network traffic data based on customer and global prevalence, internal traffic, first-time domain queries, and subdomains, minimizing irrelevant data and maximizing the visibility of important threats, enabling efficient identification of malicious behavior.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security tools display all network traffic data with badness scoring, then comprehensive security coverage is achieved, but users are overwhelmed with vast amounts of data making it difficult to identify malicious activity
Solution Approach 1:
The patent extracts and displays only the most relevant security events by applying multiple filtering criteria (prevalence, frequency, criticality) to the full network traffic dataset. This extraction principle allows the system to maintain comprehensive security coverage while presenting only the most suspicious activities to users, thereby resolving the contradiction between complete coverage and ease of analysis.
Solution Approach 2:
The patent applies different quality levels of filtering and scoring to different portions of the data based on their security relevance. High-prevalence, high-frequency events receive more aggressive filtering, while low-prevalence events are preserved with higher visibility. This local quality approach ensures comprehensive coverage while making the data more manageable by applying appropriate scrutiny levels to different data segments.
2Measurement precision
If security tools score badness of activities without considering prevalence, then individual threat assessment is improved, but the volume of potential threats to sort through increases dramatically
Solution Approach 1:
The patent changes the parameters used for threat assessment by incorporating prevalence and frequency metrics into the scoring system. Instead of relying solely on badness scoring, the system multiplies badness by prevalence and frequency factors, thereby transforming the assessment parameters to simultaneously improve accuracy while reducing the volume of threats requiring manual review.
Solution Approach 2:
The patent applies asymmetric weighting to different threat characteristics based on their security significance. High-prevalence events are weighted differently than low-prevalence events, and first-time occurrences receive special attention. This asymmetric approach improves threat assessment accuracy by emphasizing the most concerning patterns while reducing the apparent volume of threats through differentiated prioritization.
3Measurement precision
If users spend hours sorting through data to find anomalous behavior, then thorough analysis is achieved, but response time to mitigate threats is significantly delayed
Solution Approach 1:
The patent performs preliminary filtering, sorting, and scoring of network traffic data before presenting it to users. By pre-processing the data with multiple filtering criteria and badness scoring calculations, the system reduces the time users need to spend on manual analysis while maintaining thorough threat detection. This preliminary action resolves the contradiction by doing the heavy lifting before the user interaction phase.
Solution Approach 2:
The patent implements feedback mechanisms where the system continuously monitors network traffic, updates prevalence and frequency metrics, and dynamically adjusts the filtering and scoring. This feedback loop enables the system to maintain thorough threat detection while reducing response time by automatically adapting to changing threat patterns and prioritizing emerging anomalies without requiring manual re-analysis.
Data Source
AI summary
Methods, systems, and apparatus, including computer programs encoded on computer storage media, for surfacing anomalous network activity on a user interface. An example method provides, for presentation on a user device, a user interface for analyzing network traffic from a customer network. The user interface is populated with network traffic data from the customer network for display to the user. An interactive first filter that is configurable for filtering network traffic based on prevalence of the destination domains of the network traffic is displayed to the user. A first user input configuring the first filter to a first prevalence value is received. In response, the network traffic data is filtered in the user interface to only include network traffic data that has a destination domain that is less prevalent than the first prevalence value.


