Network Route Viewing System for Illicit Activity Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Monitoring and analyzing large amounts of data from publicly accessible networks to detect illicit activities is challenging due to the complexity and volume of the data, making it difficult to identify real illicit activities amidst extraneous information.
Innovation Solution
A route viewing system that receives and analyzes network route information to identify routes associated with illicit users, filters this information based on criteria such as malicious behavior and geographical location, and displays the routes on a geographical map at their source and destination locations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If conventional data processing applications are used to analyze network data, then the processing capability is limited, but the data volume and complexity increase making it difficult to detect illicit activities
Solution Approach 1:
The patent segments the network data analysis process into multiple specialized components: flow data collectors at network nodes, a flow data processor that aggregates and filters data, and a route viewer for visualization. This segmentation allows each component to handle specific aspects of the complex data processing task, improving overall productivity while managing complexity through division of labor.
Solution Approach 2:
The patent introduces intermediary components including flow data collectors that act as intermediaries between network nodes and the central processor, and a flow data processor that serves as an intermediary layer between raw data collection and final analysis. These intermediaries filter, aggregate, and preprocess data, reducing the complexity burden on the final analysis system while maintaining high processing throughput.
2Loss of information
If all network route information is displayed, then complete visibility is achieved, but the ability to identify real illicit activities amidst extraneous information decreases
Solution Approach 1:
The patent extracts and highlights only the relevant illicit route information from the vast amount of network data. The route viewer selectively displays routes associated with illicit activities by filtering out normal traffic patterns, thereby maintaining information completeness for detection purposes while removing extraneous information that obscures real threats.
Solution Approach 2:
The patent applies local quality by providing different levels of detail and filtering for different users and contexts. The system can display aggregated summary views for high-level oversight while allowing drill-down into specific route details when needed, optimizing the information presentation based on the local detection context and user needs.
3Measurement precision
If detailed analysis of all routes is performed, then detection accuracy improves, but the time required to analyze the data increases
Solution Approach 1:
The patent performs preliminary actions by pre-processing and filtering network flow data before detailed analysis. Flow data collectors continuously gather data and the flow data processor pre-aggregates and filters this data to identify potential illicit patterns, so that when detailed analysis is needed, the work has already been partially completed, maintaining high detection accuracy while reducing the time required for final analysis.
Solution Approach 2:
The patent implements continuous monitoring and analysis of network routes, maintaining constant surveillance of data flows. This continuous useful action allows the system to detect illicit activities in real-time or near-real-time, achieving high detection accuracy without significant time loss by continuously processing and analyzing routes as they occur rather than batch-processing historical data.
Data Source
AI summary
A route viewing system includes a computing system that receives information associated with one or more routes through a network, and identifies the routes that are associated with at least one illicit user computer used by an illicit user. The computing system then obtains a source location of a source address of the routes and a destination location of a destination address of the routes, and displays the routes on a geographical display at the source location of the source address and the destination location of the destination address of each of the routes.


