Graphical Network Traffic Viewer for Threat Pattern Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service provider networks face challenges in detecting and addressing cyber security threats due to information overload and non-intuitive threat presentations, making it difficult to recognize potential threats in time.

Innovation Solution

A cyber security threat tool utilizing a graphical database to transform network connection logs into nodes and relationships, enriched with additional threat information, and a graphical query interface for pattern matching, allowing for interactive visualization and detection of complex threat patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If conventional network traffic monitoring tools are used to detect cyber security threats, then the amount of network traffic that can be monitored increases, but the ability to recognize threats deteriorates due to information overload and non-intuitive presentations

Engineering Contradiction:
Improveamount of network traffic monitoredVSAvoidability to recognize threats
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The patent segments the overwhelming network traffic data into discrete graphical objects representing individual connections, devices, and threat indicators. Each object is visually distinct and can be independently analyzed, transforming the monolithic data stream into manageable units that operators can systematically examine for threats.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms flat, two-dimensional data tables into three-dimensional interactive graphical displays with multiple visual dimensions. Threat patterns are represented spatially through node positioning, connection routing, and visual hierarchies, allowing operators to perceive relationships and anomalies that are invisible in traditional flat presentations.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Loss of information

If detailed network connection data is presented to operators for threat detection, then the information completeness increases, but the complexity of analysis increases leading to information overload

Engineering Contradiction:
Improveinformation completenessVSAvoidcomplexity of analysis
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent applies local quality by providing different levels of detail in different parts of the graphical interface. High-level overview elements show summary information for quick scanning, while detailed inspection of specific nodes or connections reveals comprehensive technical data. This graduated disclosure maintains information completeness while managing analysis complexity through selective detail presentation.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces graphical intermediaries that mediate between raw network data and operator analysis. Visual metaphors such as node representations, connection lines, and threat indicator icons serve as intermediaries that simplify complex technical data into intuitive visual forms, reducing the cognitive load required to analyze complete network information.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If complex threat patterns are visualized in detail, then the detection accuracy improves, but the processing power and memory requirements increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing power and memory requirements
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent implements partial action by dynamically loading and rendering only the portions of the graphical display that are currently relevant to the operator's focus. When examining a specific node or connection, only the local neighborhood and related threat patterns are fully rendered in high detail, while other areas use simplified representations, reducing overall processing and memory requirements while maintaining detection accuracy for the area of interest.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11595418B2Graphical connection viewer for discovery of suspect network traffic
Publication Date: 2023.02.28 T MOBILE US INC
  • US11595418B2 patent drawing
  • US11595418B2 patent drawing
  • US11595418B2 patent drawing

AI summary

A cyber security threat tool may detect, analyze and alert of cyber security threats in, for example, a communication network of a service provider. For example, the tool may receive network connection data associated with a plurality of network connections between a plurality of computing devices, generate, based at least in part on the network connection data, a graphical database comprising a plurality of graph nodes corresponding to the plurality of computing devices and a plurality of graph edges corresponding to the plurality of network connections and performing a database query on the graphical database to generate query results, the database query including a connection pattern to be matched by the query results generated by the performing the database query. The cyber security threat tool may then render at least a portion of the query results in a graph view and cause the graph view to be output to a user.