Event Series Chart for Precise Enterprise Threat Forensics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current enterprise threat detection (ETD) systems face difficulties in pinpointing individual, rarely-occurring events crucial for forensic investigations due to their aggregated data display, which hides specific event timestamps and makes it hard to detect anomalies effectively.
Innovation Solution
The implementation of an Event Series Chart that displays events along a time axis, allowing for zooming, panning, filtering, and tooltip functionality, enabling users to focus on individual events and their properties, thereby facilitating faster and more accurate detection of rare events.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If aggregated distribution of Events is displayed, then frequency of Events can be revealed, but individual Events and their exact timestamps are hidden making it difficult to pinpoint crucial Events
Solution Approach 1:
The patent segments the visualization into two distinct views: an aggregated distribution view that shows frequency patterns, and an individual event view that displays specific events with precise timestamps. This segmentation allows users to switch between overview and detailed perspectives without mixing the two types of information in a confusing manner.
Solution Approach 2:
The patent introduces a temporal dimension by displaying events along a time axis, transforming the data from a static aggregated distribution into a dynamic temporal sequence. This dimensional change enables precise timestamp visualization while maintaining the ability to see frequency patterns through the distribution overlay.
2Productivity
If individual Events are emphasized over aggregated distributions, then rare Events can be detected faster, but overview of Event frequency patterns is lost
Solution Approach 1:
The patent merges the aggregated distribution visualization with individual event markers on the same time axis. The distribution provides contextual frequency information while individual events are highlighted with distinct markers, allowing users to simultaneously see both the overview pattern and specific rare events without losing either type of information.
Solution Approach 2:
The patent uses color differentiation to distinguish between common events and rare/anomalous events. Rare events are highlighted with distinctive colors or markers that stand out against the background distribution, enabling rapid detection of anomalies while the overall color-coded distribution maintains frequency pattern visibility.
3Ease of operation
If zooming and panning functionality is added to view individual Events, then detailed observation is enabled, but interface complexity increases
Solution Approach 1:
The patent implements dynamic zooming and panning capabilities that allow users to interactively explore event details at different temporal scales. The interface dynamically adjusts the time axis scaling and event marker density based on zoom level, providing detailed observation when needed while maintaining overview capability at default zoom levels.
Solution Approach 2:
The patent introduces intermediate visualization elements such as tooltips, pop-up details, and hierarchical event grouping that mediate between the need for detailed observation and interface simplicity. These intermediaries provide additional event information on-demand without permanently cluttering the main view, reducing the perceived interface complexity.
Data Source
AI summary
One or more entities are selected for which logged Events are to be displayed in an Event Series Chart. One or more filters and a timeframe are selected. Events are fetched from one or more selected log files based on the one or more selected filters and the timeframe. The fetched Events are displayed in an Event Series Chart according to an associated timestamp and identification Event property value associated with each fetched Event.


