3D Dome Network Security Visualization for Attack State Recognition
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security visualization methods struggle to effectively convey the security state of a network, particularly in recognizing attack locations and security system states, due to their reliance on IP-based representations, which complicate real-time response and correlation analysis.
Innovation Solution
A method and apparatus that collect and normalize security event information, categorize and contract it into attack state information, and visualize this data as a three-dimensional (3D) screen, allowing for real-time display of attack details by regional groups and detection equipment, using a dome structure to represent attack states and additional information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If security events are expressed from the viewpoint of IPs, then detailed information for each IP can be provided, but it is difficult to recognize the state of each location, security system, and destination, and response effectiveness is reduced
Solution Approach 1:
The patent segments security event information into multiple classification dimensions: IP-based details, location-based regional groups, security system-based detection equipment, and destination-based attack targets. This segmentation allows simultaneous viewing of detailed IP information and aggregated views by location, system, and destination, resolving the contradiction between detailed information and operational ease.
Solution Approach 2:
The patent adds spatial and organizational dimensions to the traditional IP-based security event view. By introducing location-based regional groups and security system-based detection equipment as additional classification dimensions, the system enables multi-dimensional analysis of security events, allowing security managers to switch between detailed IP views and aggregated regional/system views without losing information.
2Loss of information
If security events are expressed from the viewpoint of IPs, then detailed information for each IP can be provided, but the security manager should cope with each IP which complicates the response process
Solution Approach 1:
The patent segments the response process by introducing location-based regional groups and security system-based detection equipment as organizational units. Security managers can now respond to attacks at the regional or system level rather than individually addressing each IP, significantly reducing response process complexity while maintaining access to detailed IP information when needed.
Solution Approach 2:
The patent merges multiple IP-based security events into location-based regional groups and security system-based detection equipment aggregates. This merging allows security managers to handle groups of related security events as unified entities, reducing the complexity of coping with numerous individual IPs while preserving the ability to drill down to specific IP details.
3Loss of information
If traditional security visualization methods are used, then security events can be displayed, but the attack location and security system state are not clearly recognized
Solution Approach 1:
The patent introduces location-based spatial dimensions to security event visualization. By mapping security events to geographical locations and organizing them into regional groups, the system enables precise attack location recognition while maintaining complete security event information. This spatial dimension transformation allows security managers to visually identify attack locations and affected regions with high precision.
Solution Approach 2:
The patent segments security event information into location-based regional groups and security system-based detection equipment categories. This segmentation enables clear identification of attack locations and security system states by organizing events according to their geographical and organizational context, making it easy to recognize which locations are under attack and which security systems are detecting threats.
Data Source
AI summary
A network security state visualization scheme is suitable for collecting security events existing in a network, analyzing the security events, categorizing and contracting the analyzed security events into attack state information, and visualizing the attack state information as a three-dimensional (3D) screen to display the visualized information on a display panel. Unlike the related art where security events are expressed from the viewpoint of IPs, this scheme normalizes collected security event information, analyzes the normalized information, categorizes and contracts the analyzed information into the attack state information, extracts visualization target data, visualizes the visualization target data as the 3D screen, and displays the visualized 3D screen on the display panel.


