Geographical Intrusion Mapping via Data Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current response systems for cyber attacks on airlines are inefficient, requiring extensive manual efforts to correlate threat information, authenticate data, and prioritize resources, which hinders timely geographical identification and allocation of response resources.

Innovation Solution

A system utilizing a mapping computer that correlates intrusion, ARP, and location databases to geographically map intrusions, allowing for automated visualization and prioritization of response resources, enabling timely and efficient deployment of technical and human resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual review of TCP/IP switch information and manual drawing of network maps are performed, then intrusion location identification can be achieved, but response time is significantly extended and productivity is reduced

Engineering Contradiction:
Improveintrusion location identification accuracyVSAvoidresponse speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent replaces manual mechanical processes (reviewing TCP/IP switch information, manually drawing network maps) with an automated computer-based system that correlates authentication data, flight data, and network information to generate geographical intrusion maps automatically, thereby maintaining identification accuracy while dramatically improving response speed

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a mapping computer as an intermediary that correlates multiple data sources (authentication data, flight data, TCP/IP information) to produce geographical intrusion location information, eliminating the need for manual analysis while providing integrated visual representation

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If sequential or business prioritization order is used for resource deployment, then resource allocation follows established protocols, but the ability to identify and respond to critical geographical intrusions is limited

Engineering Contradiction:
Improveresource allocation processabilityVSAvoidresponse prioritization accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent adds a geographical spatial dimension to resource prioritization by mapping intrusions to physical locations and correlating with flight data, enabling response teams to prioritize based on actual geographical proximity and criticality rather than following sequential business protocols

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Loss of information

If extensive correlation of threat information, authentication data, and flight data is performed manually, then comprehensive intrusion analysis can be achieved, but response time is dramatically increased

Engineering Contradiction:
Improveinformation completenessVSAvoidresponse time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent replaces manual data correlation processes with automated computer-based correlation of authentication data, flight data, and network information, maintaining comprehensive information analysis while reducing response time from hours/days to minutes

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent enables continuous automated correlation and monitoring of multiple data streams, allowing real-time intrusion detection and response prioritization without the interruptions and delays inherent in manual sequential analysis

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS9591004B2Geographical intrusion response prioritization mapping through authentication and flight data correlation
Publication Date: 2017.03.07 PALO ALTO NETWORKS INC
  • US9591004B2 patent drawing
  • US9591004B2 patent drawing
  • US9591004B2 patent drawing

AI summary

Preferred systems and methods for geographically mapping intrusions through network or authentication data and flight data correlation are described. In one aspect, methods and systems include receiving threat data, receiving network or authentication data, receiving flight location data, correlating the threat data and the network or authentication data with the flight location data to generate map data, and generating a map displaying a geographical location of the intrusion based on the map data.