Network Flow Data Aggregation for Storage Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network monitoring and control systems face challenges in validating and contextualizing security and compliance data across distributed, virtualized, and cloud computing environments, often relying on limited data sources and providing inadequate actionable information for access control decisions, and struggle with processing and storing large volumes of network flow data.
Innovation Solution
A computer-implemented method that aggregates network flow data from multiple sources over various periods, generating a graphical representation of network assets and connections, allowing for historical data presentation without storing large volumes of raw data, and dynamically modifying access control lists based on asset attribute changes and compliance policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Duration of action of stationary object
If network flow data is collected and stored for long periods to provide historical analysis, then the scope and usefulness of data presentation is improved, but the storage volume and processing burden increase significantly
Solution Approach 1:
The patent extracts only the essential and relevant features from raw network flow data, storing aggregated statistics and metadata rather than complete raw data records. This allows historical data to be retained for extended periods while dramatically reducing storage requirements by keeping only the most valuable analytical elements.
Solution Approach 2:
Instead of storing raw data and processing it when needed, the patent inverts the approach by pre-aggregating and processing data into compact representations that can be stored efficiently. The system transforms voluminous raw data into condensed statistical forms that are both space-efficient and immediately usable for historical analysis.
2Loss of information
If multiple data sources are integrated to provide comprehensive contextual information, then the quality of security decisions is improved, but the system complexity increases
Solution Approach 1:
The patent creates a unified data model that serves multiple functions simultaneously - it can represent network flows, security events, contextual information, and analytical results all within a single flexible framework. This multi-functional approach allows comprehensive information integration without requiring separate complex systems for each data type.
Solution Approach 2:
The patent introduces contextual information as an intermediary layer that connects multiple data sources and provides meaningful interpretation. This intermediary contextualizes raw data from various sources, making the integration manageable by adding a layer of abstraction that unifies diverse inputs into coherent security intelligence.
3Reliability
If access control decisions are made in real-time based on comprehensive data analysis, then the security effectiveness is improved, but the processing time and resource requirements increase
Solution Approach 1:
The patent performs preliminary analysis and aggregation of network flow data before access control decisions are required. By pre-processing data into aggregated statistics and identifying patterns in advance, the system reduces the computational burden during real-time decision-making, enabling fast responses without sacrificing analytical depth.
Solution Approach 2:
The patent implements dynamic adjustment of analysis depth and data aggregation levels based on current operational context and threat levels. During normal operations, less intensive analysis is performed to minimize delay, while during suspected threats or critical events, the system dynamically increases analysis depth to improve detection accuracy without constant high overhead.
Data Source
AI summary
Embodiments of the present disclosure can aggregate network flow data over various periods of time, and present a graphical representation of the network flow information based on the aggregated data instead of (or in addition to) the raw network flow data. Among other things, embodiments of the present disclosure are able to present historical network flow data for relatively long periods of time without having to store large volumes of raw network flow data.


