Network Security Analysis via Multi-Source Flow Information Graph

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network monitoring and control systems face challenges in validating security technical controls and providing a comprehensive view of network security and compliance in dynamic environments like distributed or cloud computing, as they typically rely on limited data sources and lack contextualization of security and compliance-relevant data.

Innovation Solution

A computer-implemented method that collects and analyzes data from multiple sources to generate a flow information graph, depicting network assets and their connections, including allowed and blocked traffic, to present a more accurate representation of network security and compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If conventional network monitoring systems use data from a single source or one type of data, then the system complexity is reduced, but the completeness and accuracy of security representation is worsened

Engineering Contradiction:
Improvesystem complexityVSAvoidcompleteness of security representation
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The patent combines multiple data sources including network flow data, asset data, security control data, and compliance data into a unified multi-dimensional model. This integration allows the system to maintain comprehensive security representation while managing complexity through standardized data structures and processing pipelines.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system creates a universal data model that can process and integrate various types of data from different sources simultaneously. The multi-dimensional model serves multiple functions: representing network assets, security controls, compliance requirements, and their interrelationships in a single framework that supports comprehensive analysis.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Power

If conventional systems rely on limited data sources, then the data processing load is reduced, but the contextualization capability of security data is worsened

Engineering Contradiction:
Improvedata processing loadVSAvoidcontextualization capability
Core Design Contradiction:
PowerVSLoss of information

Solution Approach 1:

The patent introduces intermediary processing layers including data normalization modules, context enrichment services, and relationship mapping mechanisms. These intermediaries transform raw data from multiple sources into contextualized information by adding metadata, establishing relationships between entities, and enriching data with security and compliance context before final analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If systems use multiple data sources and comprehensive analysis, then the accuracy of network security representation is improved, but the device complexity increases

Engineering Contradiction:
Improveaccuracy of network security representationVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the complex analysis task into distinct processing modules: data collection from multiple sources, data normalization, multi-dimensional model construction, security control mapping, and compliance analysis. Each module handles a specific aspect of the analysis, improving accuracy while managing complexity through modular design and clear separation of concerns.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11012318B2Systems and methods for network analysis and reporting
Publication Date: 2021.05.18 CATBIRD NETWORKS
  • US11012318B2 patent drawing
  • US11012318B2 patent drawing
  • US11012318B2 patent drawing

AI summary

Among other things, embodiments of the present disclosure can collect and analyze asset and network data from multiple sources, and use such data to present a more complete and accurate representation of the network connections between various systems and software applications and the policies dictating the operation of security controls on a network compared to conventional systems.