Live Log Analysis Using Sankey Diagrams for Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems face challenges in visualizing and manipulating large datasets from cloud-based systems in real-time, requiring expert knowledge to derive actionable insights and optimize policies, making it difficult for users to understand and utilize live logs effectively.
Innovation Solution
A live log analysis system with a user-friendly graphical interface that uses Sankey diagrams and filter cards to simplify complex data, allowing users to visualize and interact with real-time data without needing extensive expertise, enabling users to identify important metrics and perform contextual actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional log analysis methods are used, then data accuracy is maintained, but user accessibility and ease of operation deteriorate due to requiring expert knowledge
Solution Approach 1:
The patent introduces an intermediary layer between the complex log data and the user. This intermediary processes and transforms raw log data into simplified visual representations (sankey diagrams, bar charts, pie charts) that are easy to understand. The intermediary handles the complexity internally while presenting simplified interfaces to users, thus improving ease of operation without sacrificing data accuracy.
Solution Approach 2:
The patent replaces traditional mechanical/manual log analysis methods with automated computational systems. Instead of requiring users to manually query and analyze complex log data, the system automatically processes logs and generates visualizations. This substitution of manual mechanical analysis with automated computational processing maintains data accuracy while dramatically improving user accessibility.
2Speed
If real-time data processing is implemented, then responsiveness is improved, but computational load and energy consumption increase
Solution Approach 1:
The patent applies partial action by processing and visualizing only the most relevant log data in real-time, rather than analyzing the entire dataset. The system identifies and focuses on critical events and anomalies, processing a subset of data that provides maximum insight. This partial processing approach maintains real-time responsiveness while significantly reducing computational energy consumption compared to processing all log data.
3Loss of information
If detailed log data is displayed, then information completeness is improved, but data visualization complexity and difficulty of understanding increase
Solution Approach 1:
The patent segments complex log data into distinct, organized categories and dimensions. The sankey diagrams divide data flow into manageable segments showing transitions between states. Bar charts and pie charts segment information by specific metrics and categories. This segmentation maintains information completeness by preserving all relevant data while making it visually organized and easier to interpret.
Solution Approach 2:
The patent transforms one-dimensional raw log data into multi-dimensional visual representations. Sankey diagrams add spatial dimensions to show data flow paths. Bar charts and pie charts add visual dimensions (length, area, angle) to represent quantitative relationships. This dimensional transformation preserves all information while making patterns and relationships visually apparent, reducing the difficulty of detection and measurement.
Data Source
AI summary
Systems and methods for visualization monitoring data from a cloud-based system include obtaining the monitoring data, wherein the monitoring data is based on transactions associated with a plurality of users of the cloud-based system; providing a Graphical User Interface (GUI); obtaining a plurality of filter selections for a plurality of filter types; and displaying a visualization comprising a Sankey diagram of the monitoring data with nodes in the Sankey diagram including each of the plurality of filter types and links between the nodes indicative of the transactions in the monitoring data. The monitoring data can be for one or more of cloud security service transactions, application access via a Zero Trust Network Access (ZTNA) service, and user experience metrics.


