Pluggable Security Analytics Platform for Real-Time Threat Neutralization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network security tools are vulnerable to cyber attacks, leading to delayed detection and response to security threats due to their reliance on database analysis and rule-based measures, which are inefficient in processing large amounts of network telemetry data.
Innovation Solution
An automated security analytics platform that utilizes an active memory to store and analyze network telemetry information in real-time, employing pluggable network security modules and visualization-agnostic selection linked portlets to rapidly detect and neutralize threats, while optimizing memory and processing resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If conventional database servers are used to store and analyze network telemetry information, then data storage capacity is sufficient, but analysis speed and response time are delayed
Solution Approach 1:
The patent segments the monolithic database server into separate storage and computation components. Telemetry data is stored in a database while analysis is performed by distributed sensor modules and analysis modules that can process data in real-time, eliminating the bottleneck of centralized database analysis.
Solution Approach 2:
The patent introduces an intermediary layer of sensor modules and analysis modules that sit between the data source and the database. These intermediaries perform preliminary processing and analysis, reducing the burden on the database server and enabling faster response times.
2Reliability
If rule-based security measures are used to detect known threats, then detection accuracy for known threats is high, but the system cannot detect new types of attacks
Solution Approach 1:
The patent implements dynamic security analysis modules that can adapt their detection rules based on observed patterns. The system evolves from static rule-based detection to dynamic behavior-based detection, allowing it to identify both known threats and novel attack patterns by learning from telemetry data.
Solution Approach 2:
The patent changes the detection parameters from fixed rules to flexible, learnable patterns. Analysis modules can adjust detection thresholds and parameters based on the specific characteristics of different threats, enabling accurate detection across diverse attack types.
3Adaptability or versatility
If anomaly detection systems are used to detect new attack types, then adaptability to new threats is improved, but large amounts of data must be analyzed over lengthy time periods
Solution Approach 1:
The patent performs preliminary filtering and preprocessing of telemetry data at the sensor module level before data is passed to analysis modules. This preliminary action reduces the volume of data that requires complex anomaly detection, improving analysis efficiency while maintaining detection capability.
Solution Approach 2:
The patent applies different analysis strategies to different portions of the data stream. High-volume routine data receives simplified processing while suspicious or anomalous data receives more intensive analysis, optimizing the balance between detection capability and processing efficiency.
4Reliability
If network telemetry information is collected and stored for historical analysis, then security threat identification is enhanced, but the process takes time and provides information only after a breach has occurred
Solution Approach 1:
The patent implements continuous real-time analysis of network telemetry data through distributed sensor and analysis modules. Instead of batch processing historical data, the system continuously monitors and analyzes data streams, enabling immediate detection and response to security threats as they occur.
Data Source
AI summary
Pluggable network security modules provide a collaborative response across plural networks by allowing modules associated with detection and neutralization of a network security threat to plug into a network security platform of other networks. Plugging the security modules in provides an automated insertion of detection and neutralization tools into the network security platform to respond to potential threats based upon proven successful responses at other networks.


