Geographical Intrusion Mapping via Database Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current response systems for computer and telecommunications intrusions require extensive manual efforts to correlate threat information, locate physical equipment, and prioritize resource allocation, leading to delayed response times and inadequate geographical visualization of intrusion locations and progress.

Innovation Solution

A system utilizing a mapping computer that correlates intrusion, ARP, and location databases to geographically map intrusions, allowing for real-time visualization and prioritization of response resources, with updates on intrusion status and progress displayed on a map.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual review of TCP/IP switch information and manual drawing of network maps are used, then response personnel can identify intrusion locations, but response time is dramatically reduced due to extensive manual efforts

Engineering Contradiction:
Improveidentification accuracy of intrusion locationVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical processes (reviewing TCP/IP switch information, drawing network maps) with an automated computer-based system that correlates threat information, router traffic information, and physical location data to generate graphical displays of intrusion locations, thereby eliminating manual review time while maintaining identification accuracy

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a computer system as an intermediary that automatically correlates multiple data sources (threat information, router traffic, physical location databases) and produces synthesized graphical outputs, mediating between raw data and human decision-making to accelerate the response process without sacrificing precision

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If sequential or business prioritization order is used for mitigation, then resource allocation follows organizational priorities, but geographical location of problems and resource needs cannot be easily identified

Engineering Contradiction:
Improveresource allocation according to prioritiesVSAvoidgeographical view of intrusions and response progress
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent adds a geographical spatial dimension to the traditional sequential prioritization approach by displaying intrusion locations and response progress on graphical maps, allowing managers to simultaneously view both priority-based resource allocation and geographical distribution of problems, thereby recovering lost spatial information

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If extensive efforts are made to correlate threat information, router traffic information and physical location, then accurate intrusion location identification is achieved, but response time is dramatically reduced

Engineering Contradiction:
Improveaccuracy of intrusion location identificationVSAvoidresponse efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent performs preliminary correlation of physical location information with router traffic data in advance, storing this pre-processed information in a database that can be quickly queried during intrusions, thereby maintaining high identification accuracy while reducing the time required for real-time response

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8631493B2Geographical intrusion mapping system using telecommunication billing and inventory systems
Publication Date: 2014.01.14 PALO ALTO NETWORKS INC
  • US8631493B2 patent drawing
  • US8631493B2 patent drawing
  • US8631493B2 patent drawing

AI summary

Systems and methods for geographically mapping a threat into a network having one or more network points include receiving threat information identifying a threat to a point of the network, correlating the threat information with location information for the identified network point, and network identification information for the identified network point, and generating a map displaying a geographical location of the threat.