Network Security Device Metadata Refinement for Scalable Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security devices face challenges in efficiently monitoring and displaying a large number of concurrent connections due to the overwhelming volume of connection metadata, which leads to performance issues and difficulties in interpreting the data effectively.

Innovation Solution

A system and method that includes a network security device with a monitoring module to gather metadata, a refinement module to filter and aggregate connection metadata into refined metadata based on designated properties, and a communication module to provide this refined data to a terminal, allowing for abstract representations and weighted connection groups to be displayed, reducing data transfer and improving usability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If all connection metadata is transferred and displayed, then complete monitoring information is provided, but the data volume overwhelms the user and system performance degrades

Engineering Contradiction:
Improveconnection metadata completenessVSAvoiduser interpretability
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The refinement module extracts only the most relevant connection metadata fields based on user-defined criteria, separating essential information from redundant data. This extraction process filters out unnecessary metadata while preserving critical connection details, thereby reducing data volume without completely losing important information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The connection metadata is segmented into hierarchical groups (e.g., by source, destination, application, or security policy) allowing users to view aggregated summaries at higher levels and drill down to individual connection details only when necessary. This segmentation enables manageable presentation of large datasets while maintaining access to complete information.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If all connection metadata is transferred to the terminal, then complete monitoring data is available, but data transfer overhead increases and system performance decreases

Engineering Contradiction:
Improvemonitoring data completenessVSAvoidsystem performance
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The refinement module on the network security device extracts and processes only the necessary metadata fields before transmission, removing redundant information at the source. This extraction reduces the volume of data that needs to be transferred over the network while ensuring that complete monitoring capability is maintained through selective data retention.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The refinement module performs preliminary filtering, aggregation, and sorting of connection metadata before it is transmitted to the terminal. By pre-processing the data on the network security device, the system eliminates the need to transfer and process unnecessary information at the terminal, thereby improving overall system performance while maintaining monitoring completeness.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If detailed connection metadata is displayed, then comprehensive monitoring information is provided, but the volume of information becomes overwhelming and difficult to interpret

Engineering Contradiction:
Improvemonitoring detail levelVSAvoiddata interpretability
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The interface module presents connection metadata in segmented, hierarchical groups organized by user-defined criteria such as source, destination, application, or security policy. Users can view aggregated summaries at the group level for high-level overview and drill down to individual connection details only when needed, making the information manageable and interpretable while preserving comprehensive monitoring capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The interface allows dynamic adjustment of the level of detail displayed based on user interaction. Users can toggle between aggregated views and detailed individual connection information, and the system dynamically adjusts the amount of information presented based on selection criteria, enabling flexible interpretation of monitoring data at appropriate detail levels.

Inventive Principle:
Principle #15Dynamics

4Productivity

If connection metadata is filtered and aggregated into groups, then data transfer is reduced and usability improves, but some level of detail is lost

Engineering Contradiction:
Improvedata transfer efficiencyVSAvoidconnection detail information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The refinement module aggregates connection metadata into logical groups based on user-defined criteria, creating hierarchical structures where individual connections are organized under parent groups. This segmentation reduces data transfer by transmitting aggregated summaries rather than individual connection records, while the hierarchical structure preserves access to detailed connection information when users drill down into specific groups.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary aggregation and filtering of connection metadata before transmission, organizing data into meaningful groups on the network security device. This pre-processing reduces the volume of data that must be transferred to the terminal while maintaining the ability to access detailed connection information through the grouped structure, balancing efficiency with information completeness.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8977746B2Systems and methods for scalable network monitoring
Publication Date: 2015.03.10 WATCHGUARD
  • US8977746B2 patent drawing
  • US8977746B2 patent drawing
  • US8977746B2 patent drawing

AI summary

A network security device may gather a large amount of metadata pertaining to the connections being managed thereby. A refinement module may filter and/or aggregate the connection metadata. The metadata may be refined on the network security device. The refined metadata may be provided for display on a terminal. The refined metadata may include a subset of the larger connection metadata, which may reduce the overhead required to display and/or transmit monitoring information to the terminal device. The refined metadata may comprise connection groups, which may be formed based on aggregation criteria, such as connection source, destination, application, security policy, protocol, port, and/or the like. The connection groups may be ranked in accordance with ranking criteria.