Network Threat Visualization via Time Series Graphs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network monitoring systems face challenges in effectively recognizing relationships and associations between suspicious network traffic and traffic flow, due to the vast amount of data generated by network threats and traffic flow, limiting administrators' ability to make informed decisions.
Innovation Solution
A system that includes a processor and memory device with instructions to receive traffic metric data, identify network threats, and generate a graphical user interface (GUI) with a time series graph displaying network traffic and alert plots, allowing for visualization of network traffic characteristics and detected threats along a common timeline.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network monitoring systems collect and analyze vast amounts of network traffic data and threat information, then the completeness and accuracy of threat detection is improved, but the difficulty of recognizing relationships and associations between threats and traffic flow increases
Solution Approach 1:
The patent segments the vast network monitoring data into two distinct visual components: a network traffic plot showing traffic flow characteristics and an alert plot showing detected threats. Each plot is independently analyzed and then correlated through shared timeline markers, allowing administrators to comprehend complex relationships without being overwhelmed by the volume of data.
Solution Approach 2:
The patent transforms complex network threat data from a one-dimensional data stream into a two-dimensional graphical interface. By plotting both network traffic characteristics and threat alerts on separate but synchronized time series graphs, the system adds a visual dimension that makes correlations and patterns immediately apparent without requiring complex analytical processing.
2Speed
If network monitoring systems process large volumes of network traffic data in real-time, then the timeliness of threat detection is improved, but the ability to present information conducive to recognition of relationships and associations deteriorates
Solution Approach 1:
The patent creates a visual copy or representation of the raw network monitoring data in the form of graphical plots. Instead of presenting administrators with raw data streams and log files, the system generates graphical representations that preserve the temporal relationships and patterns while making them immediately comprehensible and easier to analyze.
Solution Approach 2:
The graphical user interface acts as an intermediary between the raw network monitoring data and the administrator's decision-making process. The time series graphs with correlated traffic and alert plots serve as a mediating representation that preserves the timing and relationships of events while presenting them in a form that is easily interpretable and actionable.
3Quantity of substance
If conventional network monitoring systems display raw data output, then the amount of information provided is high, but the administrators' ability to make correlations and informed decisions is limited
Solution Approach 1:
The patent uses visual differentiation in the graphical plots to highlight important correlations and relationships. By using distinct visual representations for network traffic characteristics and threat alerts, and by aligning them temporally on shared timelines, the system enables administrators to quickly identify correlations without having to manually analyze large volumes of raw data.
Data Source
AI summary
A method to monitor a network is provided which includes identifying a time associated with detection of each occurrence of the network threats and generating a graphical user interface that includes a display of a time series graph that corresponds to a selected time period and an interactive popup window indicating certain details associated with a user selected network threat.


