Field Area Network Visualization via Packet Interception
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Smart Grid Field Area Networks (FANs) face challenges in managing and securing wireless communications due to their wide area, multi-vendor, heterogeneous nature, vulnerability to physical and cyber-attacks, proprietary radio systems, and lack of effective network monitoring and intrusion detection systems, which are exacerbated by the immaturity of FAN technology and limited availability of commercial solutions.
Innovation Solution
A method for visualizing and analyzing FANs using a packet intercept system to obtain traffic data, extract connectivity and routing information, determine network characteristics, and import them into a data structure for monitoring and security analysis, employing tools like the MeshView application for network visualization and intrusion detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If comprehensive network monitoring and intrusion detection systems are deployed in FANs, then security monitoring capability and situational awareness are improved, but device complexity and implementation difficulty increase
Solution Approach 1:
The patent introduces a packet intercept system as an intermediary component that captures and analyzes network traffic between various FAN devices and the backend. This intermediary handles the complex tasks of packet capture, parsing, and analysis, isolating these functions from the core network operations and providing comprehensive monitoring without significantly complicating the overall system architecture.
Solution Approach 2:
The system creates detailed copies of network packets and traffic patterns for analysis. By capturing and replicating network communications in a monitoring environment, the system can analyze security threats and network performance without interfering with actual network operations, enabling comprehensive monitoring while maintaining system simplicity.
2Measurement precision
If packet intercept and analysis tools are implemented, then detection precision for security anomalies is improved, but loss of time for data processing increases
Solution Approach 1:
The patent implements selective packet filtering and analysis, focusing computational resources on suspicious or anomalous packets rather than analyzing every packet in detail. The system uses heuristics and patterns to identify packets worth detailed analysis, achieving high detection precision while minimizing overall processing time by applying partial analysis to the majority of traffic.
Solution Approach 2:
The system performs preliminary filtering and classification of packets before detailed analysis. By pre-processing traffic to identify potential threats and organize data structures in advance, the system reduces the time required for detailed security analysis when anomalies are detected, balancing detection precision with processing efficiency.
3Loss of information
If network visualization and analysis systems are deployed, then situational awareness and security monitoring are improved, but ease of operation decreases due to complexity of managing heterogeneous networks
Solution Approach 1:
The patent implements a universal network visualization system that can handle multiple network protocols, device types, and communication patterns through a single interface. The system provides multi-functional capabilities including traffic visualization, security monitoring, performance analysis, and anomaly detection, eliminating the need for separate tools for different network aspects and simplifying operation despite network heterogeneity.
Solution Approach 2:
The visualization system uses color-coded indicators to represent different network states, security threats, and performance metrics. By encoding complex network information in intuitive visual formats with different colors and symbols, the system improves situational awareness while maintaining ease of operation, allowing operators to quickly understand network status without complex data interpretation.
Data Source
AI summary
A method for visualizing and analyzing a field area network, which includes obtaining, network, traffic data that includes atomic communications and packet detail from a packet intercept system on a field area. This field area network includes a number of network nodes. The method also includes a processor extracting connectivity and routing information from the traffic data, where the connectivity and routing information includes packet information and node information, determining network characteristics based on the extracted connectivity and routing information, retaining the network characteristics in a data structure, and importing the data structure into a computer readable storage medium that is accessible to the processor.


