Geographical Intrusion Mapping via Database Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current response systems for computer and telecommunications intrusions require extensive manual efforts to correlate threat information, locate physical equipment, and prioritize resource allocation, leading to delayed response times and inadequate geographical visualization of intrusion locations and progress.
Innovation Solution
A system utilizing a mapping computer that correlates intrusion, ARP, and location databases to geographically map intrusions, allowing for real-time visualization and prioritization of response resources, with updates on intrusion status and progress displayed on a map.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual review of TCP/IP switch information and manual drawing of network maps are used, then response personnel can identify intrusion locations, but response time is dramatically reduced due to extensive manual efforts
Solution Approach 1:
The patent replaces manual mechanical processes (reviewing TCP/IP switch information, drawing network maps) with an automated computer-based system that correlates threat information, router traffic information, and physical location data to generate graphical displays of intrusion locations, thereby eliminating manual review time while maintaining identification accuracy
Solution Approach 2:
The patent introduces a computer system as an intermediary that automatically correlates multiple data sources (threat information, router traffic, physical location databases) and produces synthesized graphical outputs, mediating between raw data and human decision-making to accelerate the response process without sacrificing precision
2Ease of operation
If sequential or business prioritization order is used for mitigation, then resource allocation follows organizational priorities, but geographical location of problems and resource needs cannot be easily identified
Solution Approach 1:
The patent adds a geographical spatial dimension to the traditional sequential prioritization approach by displaying intrusion locations and response progress on graphical maps, allowing managers to simultaneously view both priority-based resource allocation and geographical distribution of problems, thereby recovering lost spatial information
3Measurement precision
If extensive efforts are made to correlate threat information, router traffic information and physical location, then accurate intrusion location identification is achieved, but response time is dramatically reduced
Solution Approach 1:
The patent performs preliminary correlation of physical location information with router traffic data in advance, storing this pre-processed information in a database that can be quickly queried during intrusions, thereby maintaining high identification accuracy while reducing the time required for real-time response
Data Source
AI summary
Systems and methods for geographically mapping a threat into a network having one or more network points include receiving threat information identifying a threat to a point of the network, correlating the threat information with location information for the identified network point, and network identification information for the identified network point, and generating a map displaying a geographical location of the threat.


