Network Flow Data Aggregation for Storage Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network monitoring and control systems face challenges in validating and contextualizing security and compliance data across distributed, virtualized, and cloud computing environments, often relying on limited data sources and providing inadequate actionable information for access control decisions, and struggle with processing and storing large volumes of network flow data.

Innovation Solution

A computer-implemented method that aggregates network flow data from multiple sources over various periods, generating a graphical representation of network assets and connections, allowing for historical data presentation without storing large volumes of raw data, and dynamically modifying access control lists based on asset attribute changes and compliance policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Duration of action of stationary object

If network flow data is collected and stored for long periods to provide historical analysis, then the scope and usefulness of data presentation is improved, but the storage volume and processing burden increase significantly

Engineering Contradiction:
Improvedata retention periodVSAvoiddata storage volume
Core Design Contradiction:
Duration of action of stationary objectVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential and relevant features from raw network flow data, storing aggregated statistics and metadata rather than complete raw data records. This allows historical data to be retained for extended periods while dramatically reducing storage requirements by keeping only the most valuable analytical elements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of storing raw data and processing it when needed, the patent inverts the approach by pre-aggregating and processing data into compact representations that can be stored efficiently. The system transforms voluminous raw data into condensed statistical forms that are both space-efficient and immediately usable for historical analysis.

Inventive Principle:
Principle #13The other way round (Inversion)

2Loss of information

If multiple data sources are integrated to provide comprehensive contextual information, then the quality of security decisions is improved, but the system complexity increases

Engineering Contradiction:
Improveinformation completenessVSAvoidsystem architecture complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent creates a unified data model that serves multiple functions simultaneously - it can represent network flows, security events, contextual information, and analytical results all within a single flexible framework. This multi-functional approach allows comprehensive information integration without requiring separate complex systems for each data type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces contextual information as an intermediary layer that connects multiple data sources and provides meaningful interpretation. This intermediary contextualizes raw data from various sources, making the integration manageable by adding a layer of abstraction that unifies diverse inputs into coherent security intelligence.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If access control decisions are made in real-time based on comprehensive data analysis, then the security effectiveness is improved, but the processing time and resource requirements increase

Engineering Contradiction:
Improvesecurity control effectivenessVSAvoiddecision-making delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary analysis and aggregation of network flow data before access control decisions are required. By pre-processing data into aggregated statistics and identifying patterns in advance, the system reduces the computational burden during real-time decision-making, enabling fast responses without sacrificing analytical depth.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic adjustment of analysis depth and data aggregation levels based on current operational context and threat levels. During normal operations, less intensive analysis is performed to minimize delay, while during suspected threats or critical events, the system dynamically increases analysis depth to improve detection accuracy without constant high overhead.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11196636B2Systems and methods for network data flow aggregation
Publication Date: 2021.12.07 CATBIRD NETWORKS
  • US11196636B2 patent drawing
  • US11196636B2 patent drawing
  • US11196636B2 patent drawing

AI summary

Embodiments of the present disclosure can aggregate network flow data over various periods of time, and present a graphical representation of the network flow information based on the aggregated data instead of (or in addition to) the raw network flow data. Among other things, embodiments of the present disclosure are able to present historical network flow data for relatively long periods of time without having to store large volumes of raw network flow data.