N-Dimensional Graphs for Intrusion Detection in Low Bandwidth Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Intrusion detection systems face challenges in low bandwidth environments, requiring high bandwidth connections and dedicated networks for data transmission, which can be inefficient and costly, especially in correlating data from multiple sensors.
Innovation Solution
A method that assigns attribute values to event information to create n-dimensional graphs, allowing for data compression and transmission in low bandwidth networks, enabling correlation and prioritization of data for attack detection without diminishing its usefulness.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional intrusion detection systems transmit voluminous data from multiple sensors to a central server, then the system can perform comprehensive attack detection and correlation, but the network bandwidth requirement becomes excessively high and costly
Solution Approach 1:
The patent divides the intrusion detection system into distributed network nodes, each capable of independent data processing and n-dimensional graph generation. Instead of transmitting all raw sensor data to a central server, each node processes its local data into compressed n-dimensional representations, significantly reducing the quantity of data transmitted across the network while preserving the ability to perform comprehensive attack correlation.
Solution Approach 2:
The patent introduces n-dimensional graphs as an intermediary data structure that bridges raw sensor data and attack detection analysis. These graphs serve as a compressed representation that captures essential security patterns without requiring transmission of the full voluminous dataset, enabling effective correlation with minimal bandwidth consumption.
2Reliability
If the system transmits and processes large volumes of raw event data, then complete attack patterns can be detected, but the data transmission time and processing overhead increase significantly
Solution Approach 1:
The patent performs preliminary data processing by generating n-dimensional graphs at each distributed network node before transmission. This preprocessing step converts raw event data into compact graphical representations that capture essential attack patterns, reducing both the volume of data to be transmitted and the time required for centralized processing, while maintaining complete attack pattern detection capability.
3Quantity of substance
If the system compresses and transmits data in low bandwidth networks, then network resource consumption is reduced, but there is a risk of diminishing the usefulness of data for detecting attacks
Solution Approach 1:
The patent transforms data from raw event formats into n-dimensional graphical representations, changing the parameter space in which security data is expressed. This transformation compresses the data into a more efficient format suitable for low-bandwidth transmission while preserving the essential characteristics needed for attack detection, thereby maintaining data usefulness despite reduced transmission volume.
4Reliability
If a dedicated high bandwidth network connection is used for intrusion detection data, then data transmission reliability is improved, but the cost and complexity of network infrastructure increases
Solution Approach 1:
The patent segments the data processing function across multiple distributed network nodes, eliminating the need for a dedicated high-bandwidth connection to a central server. Each node independently generates n-dimensional graphs from local sensor data, reducing network dependency and infrastructure complexity while maintaining reliable attack detection through distributed collaboration.
Data Source
AI summary
A method for security information management in a network comprises receiving event information for a plurality of events, wherein the event information for a particular event comprises a plurality of attributes associated with that event. The method continues by assigning a plurality of attribute values to each event, the attribute values of each event defining a point in n-dimensional space. The method continues by generating a first n-dimensional graph comprising a plurality of points, the points corresponding to the events. The method continues by receiving a second n-dimensional graph comprising a plurality of points. The method concludes by combining the first n-dimensional graph with the second n-dimensional graph.


