Network Infrastructure Analysis via Unified Data Lake Visualization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network analysts face challenges in efficiently gathering, processing, and analyzing data from disparate sources to identify changes in network infrastructure and threats, due to the need for manual querying, data standardization, and visualization of large datasets.

Innovation Solution

A system that aggregates network data from multiple sources into a central repository, processes it to remove duplicates, aligns formats, and generates an interactive graphical interface for visualizing network activity over time, allowing analysts to focus on threat analysis rather than data collection and processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If analysts manually query multiple disparate data sources to gather network data, then comprehensive network infrastructure information can be obtained, but significant time is incurred for data collection and processing

Engineering Contradiction:
Improvecomprehensive network infrastructure informationVSAvoidtime for data collection and processing
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent combines multiple disparate data sources (DNS records, WHOIS data, SSL certificates, vulnerability scans) into a single unified data lake. This consolidation allows analysts to query all network infrastructure information from one centralized location rather than manually querying each source separately, thereby maintaining comprehensive information coverage while dramatically reducing data collection time.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system pre-processes and standardizes data from multiple sources before analysts need it, organizing information into consistent formats and relationships in advance. This preliminary organization of data eliminates the need for analysts to perform time-consuming data gathering and initial processing steps when conducting network infrastructure analysis.

Inventive Principle:
Principle #10Preliminary action

2Loss of information

If data from multiple providers is gathered individually, then complete network data sets can be obtained, but the data requires extensive standardization and formatting work

Engineering Contradiction:
Improvecomplete network data setsVSAvoiddata standardization and formatting work
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent implements a universal data model that can accommodate multiple data types and formats from different providers through a common schema. This multi-functional framework automatically adapts to various input formats (DNS, WHOIS, SSL, vulnerability data) and standardizes them into a unified structure, eliminating manual formatting work while preserving complete data sets.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an intermediary layer (the data lake with unified schema) between the disparate data sources and the analysis tools. This intermediary automatically handles data standardization and formatting transformations, serving as a mediator that converts multiple provider formats into a consistent structure without requiring manual intervention from analysts.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If analysts manually aggregate and reduce large data sets to identify trends, then network threats can be detected, but the process is time-consuming and limits analytical capacity

Engineering Contradiction:
Improvenetwork threat detectionVSAvoidanalytical capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service analysis by providing analysts with direct access to pre-processed, organized data in the unified data lake. The data is automatically aggregated and structured in ways that facilitate trend identification and threat detection, allowing analysts to focus their expertise on interpretation rather than manual data processing, thereby maintaining reliability while increasing productivity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent transforms the data analysis process by adding a temporal dimension through time-series visualization capabilities. This allows analysts to view network infrastructure changes and threats over time through graphical interfaces, enabling rapid pattern recognition and trend identification without manual aggregation, thus preserving detection reliability while enhancing analytical throughput.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Loss of information

If detailed network data is visualized over time periods, then patterns and correlations can be identified, but the visualization complexity increases

Engineering Contradiction:
Improvepatterns and correlations in network activityVSAvoidvisualization complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system addresses visualization complexity by introducing temporal and spatial dimensions through graphical time-series displays. Instead of presenting raw detailed data, the system projects network activity patterns across time periods in visual formats that naturally reveal correlations and trends, maintaining information completeness while reducing the perceived complexity through intuitive visualization.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent employs visual encoding techniques including color variations to represent different network activities, threat levels, and time periods. These color-coded visualizations enable analysts to quickly perceive patterns and correlations in network data without being overwhelmed by raw data complexity, as visual cues naturally organize and highlight important relationships.

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS11362923B2Techniques for infrastructure analysis of internet-based activity
Publication Date: 2022.06.14 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11362923B2 patent drawing
  • US11362923B2 patent drawing
  • US11362923B2 patent drawing

AI summary

Some embodiments are directed to techniques for infrastructure analysis of Internet-based activity. Techniques are disclosed to enable analysts to spend more time focusing on analyzing and identifying threats to in a network infrastructure, and little time on data collection and data processing. Specifically, techniques are described for identifying network data relevant to Internet activity and providing an interactive interface (e.g., a “heat map” interface) for viewing and interactive analysis of the network data. The network data may be identified for assessing Internet activity with respect to one or more attributes, such as an Internet domain name or an Internet protocol (IP) address.