Graphical Network Traffic Viewer for Threat Pattern Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Service provider networks face challenges in detecting and addressing cyber security threats due to information overload and non-intuitive threat presentations, making it difficult to recognize potential threats in time.
Innovation Solution
A cyber security threat tool utilizing a graphical database to transform network connection logs into nodes and relationships, enriched with additional threat information, and a graphical query interface for pattern matching, allowing for interactive visualization and detection of complex threat patterns.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If conventional network traffic monitoring tools are used to detect cyber security threats, then the amount of network traffic that can be monitored increases, but the ability to recognize threats deteriorates due to information overload and non-intuitive presentations
Solution Approach 1:
The patent segments the overwhelming network traffic data into discrete graphical objects representing individual connections, devices, and threat indicators. Each object is visually distinct and can be independently analyzed, transforming the monolithic data stream into manageable units that operators can systematically examine for threats.
Solution Approach 2:
The patent transforms flat, two-dimensional data tables into three-dimensional interactive graphical displays with multiple visual dimensions. Threat patterns are represented spatially through node positioning, connection routing, and visual hierarchies, allowing operators to perceive relationships and anomalies that are invisible in traditional flat presentations.
2Loss of information
If detailed network connection data is presented to operators for threat detection, then the information completeness increases, but the complexity of analysis increases leading to information overload
Solution Approach 1:
The patent applies local quality by providing different levels of detail in different parts of the graphical interface. High-level overview elements show summary information for quick scanning, while detailed inspection of specific nodes or connections reveals comprehensive technical data. This graduated disclosure maintains information completeness while managing analysis complexity through selective detail presentation.
Solution Approach 2:
The patent introduces graphical intermediaries that mediate between raw network data and operator analysis. Visual metaphors such as node representations, connection lines, and threat indicator icons serve as intermediaries that simplify complex technical data into intuitive visual forms, reducing the cognitive load required to analyze complete network information.
3Measurement precision
If complex threat patterns are visualized in detail, then the detection accuracy improves, but the processing power and memory requirements increase
Solution Approach 1:
The patent implements partial action by dynamically loading and rendering only the portions of the graphical display that are currently relevant to the operator's focus. When examining a specific node or connection, only the local neighborhood and related threat patterns are fully rendered in high detail, while other areas use simplified representations, reducing overall processing and memory requirements while maintaining detection accuracy for the area of interest.
Data Source
AI summary
A cyber security threat tool may detect, analyze and alert of cyber security threats in, for example, a communication network of a service provider. For example, the tool may receive network connection data associated with a plurality of network connections between a plurality of computing devices, generate, based at least in part on the network connection data, a graphical database comprising a plurality of graph nodes corresponding to the plurality of computing devices and a plurality of graph edges corresponding to the plurality of network connections and performing a database query on the graphical database to generate query results, the database query including a connection pattern to be matched by the query results generated by the performing the database query. The cyber security threat tool may then render at least a portion of the query results in a graph view and cause the graph view to be output to a user.


