Network Hologram for Real-Time Data Breach Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security tools fail to provide reliable real-time detection of ongoing data breaches in computer networks, leading to inadequate visibility and ineffective prevention and remediation measures, especially in cloud-based and distributed systems.

Innovation Solution

A computer-implemented method using a network hologram to monitor and compare data movement in real-time, establishing a baseline behavior and detecting anomalous movements to identify data breaches, thereby connecting users, devices, and applications with the flow of data, reducing false positives and enabling immediate preventive measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing network security tools are used to monitor data movement, then network security monitoring is performed, but real-time detection of ongoing data breaches is not achieved

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-establishes baseline behavior profiles for normal data movement patterns before monitoring begins. These baselines include expected data volumes, frequencies, destinations, and relationships between network elements. When monitoring starts, actual data movement is immediately compared against these pre-established baselines, enabling real-time anomaly detection without requiring analysis historical data accumulation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously compares actual data movement against baseline behavior and provides immediate feedback when deviations are detected. This feedback loop operates in real-time, allowing the system to identify ongoing data breaches as they occur rather than after the fact. The feedback mechanism enables dynamic adjustment and immediate alerting when anomalous patterns are recognized.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If comprehensive network monitoring is implemented to improve detection capability, then visibility into network activities increases, but false positives increase

Engineering Contradiction:
Improvebreach detection precisionVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system segments the analysis into multiple dimensions including data volume, frequency, destination, source, and relationships between network elements. Each dimension is evaluated separately against its own baseline, and only when multiple segments simultaneously deviate from normal behavior is an anomaly flagged. This multi-dimensional segmentation reduces false positives by requiring convergence of multiple anomaly indicators.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The baseline behavior profiles are dynamic and adapt to changing normal patterns in the network. Rather than using static thresholds, the system continuously learns and adjusts what constitutes normal behavior based on ongoing observations. This dynamic approach allows the system to accommodate legitimate changes in network usage patterns while maintaining sensitivity to actual breaches.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If traditional security tools are used, then basic security monitoring is provided, but relationship-based analysis among multiple network elements is not performed

Engineering Contradiction:
Improveanalysis capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system uses a unified baseline comparison mechanism that handles multiple types of network elements (users, devices, applications, data) and multiple analysis dimensions through a single analytical framework. Rather than requiring separate tools for different analysis types, this universal approach compares all data movement against established baselines using the same core logic, simplifying the system architecture while maintaining comprehensive analysis capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11153331B2Detection of an ongoing data breach based on relationships among multiple network elements
Publication Date: 2021.10.19 HEFEI HOLONET SECURITY TECH CO LTD
  • US11153331B2 patent drawing
  • US11153331B2 patent drawing
  • US11153331B2 patent drawing

AI summary

The disclosed teachings include a computer-implemented method a computer-implemented method for identifying a data breach. The method includes monitoring movement of data over a computer network in real-time or near real-time relative to at least one of a user, a device, or a software application, comparing the monitored movement of the data to a baseline movement of the data over the computer network in real-time or near real-time relative to at least one of the user, the device, or the software application, and identifying an ongoing data breach in real-time or near real-time based on the comparison. The identified ongoing data breach indicates a relationship between the data and at least one of the user, the device, and the software application.