Firewall-Safe Transaction Visualization via Segmented Log Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In systems divided into multiple security segments, especially those with a DMZ, existing visualization technologies face challenges in accurately capturing and visualizing transactions across different segments without causing excessive processing load on firewalls, leading to degraded throughput and inaccurate analysis due to time lag issues.

Innovation Solution

A system comprising two visualization devices, one in the DMZ and one in the internal network, where the DMZ device produces protocol logs and transmits them to the internal device through the firewall, allowing for synchronization and time correction of messages to ensure accurate transaction analysis without direct message transmission across segments, thus avoiding security and processing issues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If the system visualization device is connected to switches across different security segments to capture messages, then message capture capability is improved, but firewall processing load increases significantly

Engineering Contradiction:
Improvemessage capture capabilityVSAvoidfirewall throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system divides the message capture function across multiple security segments by deploying separate system visualization devices in both the DMZ and internal networks. Each device independently captures messages within its own security segment, eliminating the need for the firewall to process and forward all message copies across segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces log data as an intermediary mechanism. Instead of directly transmitting captured messages across the firewall, the system converts messages into log data with extracted features (timestamps, source/destination addresses, protocols) and transmits only this processed information, significantly reducing firewall processing requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If messages are transmitted through the firewall across security segments, then transaction visualization accuracy is improved, but processing load on the firewall increases

Engineering Contradiction:
Improvetransaction visualization accuracyVSAvoidfirewall throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system creates local copies of the message capture and analysis functionality in both the DMZ and internal networks. Each location has its own system visualization device that independently captures and analyzes messages locally, then synchronizes findings through log data exchange, eliminating the need for the firewall to handle message transmission.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent transforms the transmission format from raw messages to processed log data with key parameters extracted (timestamps, addresses, protocols). This parameter transformation reduces the data volume and complexity that needs to traverse the firewall, maintaining analytical accuracy while reducing processing load.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If a single system visualization device is used in the internal network, then device simplicity is maintained, but message capture completeness deteriorates

Engineering Contradiction:
Improvesystem configuration simplicityVSAvoidmessage capture completeness
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The system divides the monitoring function into two separate devices positioned in different security segments (DMZ and internal network). Each device captures messages within its local segment, ensuring complete coverage of all traffic paths without requiring one device to bridge security boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent combines the data from multiple distributed visualization devices into a unified transaction view. By merging log data from both the DMZ and internal network devices, the system achieves complete message capture coverage while maintaining the simplicity of individual device configurations.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8965968B2Computer-readable medium storing system visualization processing program, method and device
Publication Date: 2015.02.24 FUJITSU LTD
  • US8965968B2 patent drawing
  • US8965968B2 patent drawing
  • US8965968B2 patent drawing

AI summary

A device carries out a receiving process to receive a message transmitted or received by a server from a communication device connected to the server. The device stores the message in a message storing unit in connection with a time when the receiving process is carried out. The device extracts a message for synchronization from the message storing unit. The device produces log data including identification data to identify the message for synchronization and a time when the message for synchronization is received. The device produces log data including a time when a message other than the message for synchronization is received. The device stores the log data in a log data storing unit. The device transmits the log data stored in the log data storing unit to a log data processing device connected to a network on an opposite side of a firewall connected to the communication device.