Network Threat Visualization via Time Series Graphs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network monitoring systems face challenges in effectively recognizing relationships and associations between suspicious network traffic and traffic flow, due to the vast amount of data generated by network threats and traffic flow, limiting administrators' ability to make informed decisions.

Innovation Solution

A system that includes a processor and memory device with instructions to receive traffic metric data, identify network threats, and generate a graphical user interface (GUI) with a time series graph displaying network traffic and alert plots, allowing for visualization of network traffic characteristics and detected threats along a common timeline.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network monitoring systems collect and analyze vast amounts of network traffic data and threat information, then the completeness and accuracy of threat detection is improved, but the difficulty of recognizing relationships and associations between threats and traffic flow increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoiddata analysis complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the vast network monitoring data into two distinct visual components: a network traffic plot showing traffic flow characteristics and an alert plot showing detected threats. Each plot is independently analyzed and then correlated through shared timeline markers, allowing administrators to comprehend complex relationships without being overwhelmed by the volume of data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms complex network threat data from a one-dimensional data stream into a two-dimensional graphical interface. By plotting both network traffic characteristics and threat alerts on separate but synchronized time series graphs, the system adds a visual dimension that makes correlations and patterns immediately apparent without requiring complex analytical processing.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Speed

If network monitoring systems process large volumes of network traffic data in real-time, then the timeliness of threat detection is improved, but the ability to present information conducive to recognition of relationships and associations deteriorates

Engineering Contradiction:
Improvethreat detection speedVSAvoidinformation presentation quality
Core Design Contradiction:
SpeedVSEase of operation

Solution Approach 1:

The patent creates a visual copy or representation of the raw network monitoring data in the form of graphical plots. Instead of presenting administrators with raw data streams and log files, the system generates graphical representations that preserve the temporal relationships and patterns while making them immediately comprehensible and easier to analyze.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The graphical user interface acts as an intermediary between the raw network monitoring data and the administrator's decision-making process. The time series graphs with correlated traffic and alert plots serve as a mediating representation that preserves the timing and relationships of events while presenting them in a form that is easily interpretable and actionable.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Quantity of substance

If conventional network monitoring systems display raw data output, then the amount of information provided is high, but the administrators' ability to make correlations and informed decisions is limited

Engineering Contradiction:
Improvedata volumeVSAvoidcorrelation recognition ability
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The patent uses visual differentiation in the graphical plots to highlight important correlations and relationships. By using distinct visual representations for network traffic characteristics and threat alerts, and by aligning them temporally on shared timelines, the system enables administrators to quickly identify correlations without having to manually analyze large volumes of raw data.

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS10567415B2Visualization of network threat monitoring
Publication Date: 2020.02.18 ARBOR NETWORKS INC
  • US10567415B2 patent drawing
  • US10567415B2 patent drawing
  • US10567415B2 patent drawing

AI summary

A method to monitor a network is provided which includes identifying a time associated with detection of each occurrence of the network threats and generating a graphical user interface that includes a display of a time series graph that corresponds to a selected time period and an interactive popup window indicating certain details associated with a user selected network threat.