Network Traffic Visualization with Color Coding for Security Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network monitoring solutions in Industry 4.0 environments, such as factories, fail to effectively and efficiently communicate security incidents and network anomalies to production managers without IT security expertise, due to complexity and high costs.

Innovation Solution

A system comprising a network probe, packet analyzing unit, and visualization unit that uses deep packet inspection and highlighting/color coding to visualize network node and connection statuses, integrated with data glasses for augmented reality overlays, enabling real-time visualization and anomaly detection with AI-driven countermeasure instructions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional network monitoring solutions are used, then security incidents can be detected, but the information is too complex for non-technical users to understand

Engineering Contradiction:
Improvesecurity incident detection accuracyVSAvoiduser comprehensibility
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent applies color coding to visual elements in the user interface, where different colors represent different security states or threat levels. This allows production managers to quickly grasp security incident information without needing to interpret complex technical data, directly addressing the comprehensibility issue while maintaining detection accuracy.

Inventive Principle:
Principle #32Color changes

Solution Approach 2:

The patent transforms complex network security data into a spatial visualization format, adding a dimensional aspect to data presentation. By displaying security incidents as visual elements in a spatial arrangement rather than text or numerical data, the system makes information more accessible to non-technical users while preserving the precision of security detection.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If detailed network monitoring is implemented, then security incidents can be detected, but the system complexity and costs increase

Engineering Contradiction:
Improvesecurity monitoring effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a visualization server as an intermediary component that handles the complex task of processing and interpreting network security data. This mediator translates raw security monitoring information into simplified visual representations, allowing the monitoring system to maintain high reliability while reducing the apparent complexity for end users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates visual copies or representations of network security states rather than directly presenting the raw data. By generating simplified visual models of complex security incidents, the system maintains accurate monitoring while presenting information in a less complex format that reduces system overhead and improves usability.

Inventive Principle:
Principle #26Copying

3Loss of time

If real-time network traffic analysis is performed, then network anomalies can be detected, but processing time and resources increase

Engineering Contradiction:
Improveanomaly detection response timeVSAvoidprocessing resource consumption
Core Design Contradiction:
Loss of timeVSUse of energy by moving object

Solution Approach 1:

The patent applies partial analysis by focusing visualization efforts on specific network segments or nodes that are most relevant to security incidents. Rather than analyzing and visualizing all network traffic equally, the system concentrates processing resources on critical areas, reducing overall processing demands while maintaining timely anomaly detection where it matters most.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3748912A1System and method for monitoring and analyzing a data flow in a network
Publication Date: 2020.12.09 ROHDE & SCHWARZ GMBH & CO KG
  • EP3748912A1 patent drawingFigure 1
  • EP3748912A1 patent drawingFigure 2
  • EP3748912A1 patent drawingFigure 3

AI summary

A system 100 for monitoring and analyzing a data flow in a network 101, wherein the system 100 comprises: a network probe 102 connected to the network 101 and configured to obtain network traffic corresponding to a network node 103 of the network 101; a packet analyzing unit 104 configured to analyze the network traffic to obtain an analyzing result 105; and a visualization unit 106 configured to visualize a representation 107 of the network node 103 and a representation 108 of a network connection 109 of the network node 103 based on the analyzing result 105; wherein the visualization unit 106 is further configured to visualize a status and/or a type of the network node 103 and/or the network connection 109 based on highlighting and/or color coding.