Network Analytics System Enriching Flow Data for Security Visibility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network telemetry systems are inadequate in providing comprehensive insights into network security, availability, and compliance due to limited knowledge of flow origins, destinations, and behaviors, relying on sampling which can miss malicious activity, and consuming significant resources while raising privacy concerns.
Innovation Solution
A network analytics system that captures and enriches flow data with contextual information using hardware assistance, generating multiple planes of enriched data to provide deeper insights into network elements and their interactions, supporting fault injection analysis and visualizations without over-extending computing resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If conventional network flow data collection is used, then resource consumption is reduced, but network visibility and analytical insights are insufficient
Solution Approach 1:
The patent segments network data collection into two distinct layers: flow data collected by network devices (switches/routers) and contextual data collected by agents on endpoint devices. This segmentation allows comprehensive network visibility without requiring any single device to consume excessive resources, as the analytics system distributes the data collection burden across multiple components.
Solution Approach 2:
The patent introduces an intermediary analytics system that receives data from multiple sources (network devices and endpoint agents) and synthesizes comprehensive network insights. This intermediary consolidates resources by centralizing the analytical processing, allowing individual network devices to maintain low resource consumption while achieving enhanced overall network visibility through the coordinated data collection architecture.
2Measurement precision
If sampling methods are used for network monitoring, then resource consumption is reduced, but detection accuracy for malicious activity deteriorates
Solution Approach 1:
The patent implements preliminary action by having endpoint agents continuously collect and buffer contextual data locally before transmitting to the analytics system. This preliminary data collection at the source ensures complete information capture without requiring continuous high-resource processing during transmission and analysis phases, thereby maintaining detection accuracy while optimizing resource consumption patterns.
Solution Approach 2:
The patent applies partial action by collecting only the specific contextual data elements needed for security analysis (application identities, user information, device state) rather than monitoring all network traffic in detail. This selective data collection approach maintains high detection accuracy for malicious activities while consuming fewer resources compared to comprehensive packet-level monitoring.
3Adaptability or versatility
If comprehensive flow data collection is implemented, then network analytics capability is improved, but device complexity increases
Solution Approach 1:
The patent extracts complex analytical processing functions from individual network devices and relocates them to a centralized analytics system. Network devices only perform simple flow data collection and forwarding, while the analytics system handles the complex tasks of correlating flow data with contextual information, generating security insights, and providing network visibility. This extraction reduces device complexity at the network edge while maintaining enhanced analytics capability centrally.
Solution Approach 2:
The patent creates a universal analytics system that handles multiple analytical functions (security monitoring, performance analysis, compliance checking) through a single centralized platform. This multi-functional approach improves overall analytics capability without requiring each individual network device to be complex, as the centralized system provides versatile analysis capabilities that serve multiple purposes across the network.
Data Source
AI summary
Systems and methods provide for enriching flow data to analyze network security, availability, and compliance. A network analytics system can capture flow data and metadata from network elements. The network analytics system can enrich the flow data by in-line association of the flow data and metadata. The network analytics system can generate multiple planes with each plane representing a dimension of enriched flow data. The network analytics system can generate nodes for the planes with each node representing a unique value or set of values for the dimensions represented by planes. The network analytics system can generate edges for the nodes of the planes with each edge representing a flow between endpoints corresponding to the nodes. The network analytics system can update the planes in response to an interaction with the planes or in response to a query.


