Pluggable Security Analytics Platform for Real-Time Threat Neutralization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security tools are vulnerable to cyber attacks, leading to delayed detection and response to security threats due to their reliance on database analysis and rule-based measures, which are inefficient in processing large amounts of network telemetry data.

Innovation Solution

An automated security analytics platform that utilizes an active memory to store and analyze network telemetry information in real-time, employing pluggable network security modules and visualization-agnostic selection linked portlets to rapidly detect and neutralize threats, while optimizing memory and processing resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If conventional database servers are used to store and analyze network telemetry information, then data storage capacity is sufficient, but analysis speed and response time are delayed

Engineering Contradiction:
Improveanalysis speedVSAvoidresponse time
Core Design Contradiction:
SpeedVSLoss of time

Solution Approach 1:

The patent segments the monolithic database server into separate storage and computation components. Telemetry data is stored in a database while analysis is performed by distributed sensor modules and analysis modules that can process data in real-time, eliminating the bottleneck of centralized database analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer of sensor modules and analysis modules that sit between the data source and the database. These intermediaries perform preliminary processing and analysis, reducing the burden on the database server and enabling faster response times.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If rule-based security measures are used to detect known threats, then detection accuracy for known threats is high, but the system cannot detect new types of attacks

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security analysis modules that can adapt their detection rules based on observed patterns. The system evolves from static rule-based detection to dynamic behavior-based detection, allowing it to identify both known threats and novel attack patterns by learning from telemetry data.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the detection parameters from fixed rules to flexible, learnable patterns. Analysis modules can adjust detection thresholds and parameters based on the specific characteristics of different threats, enabling accurate detection across diverse attack types.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If anomaly detection systems are used to detect new attack types, then adaptability to new threats is improved, but large amounts of data must be analyzed over lengthy time periods

Engineering Contradiction:
Improvedetection capabilityVSAvoidanalysis efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent performs preliminary filtering and preprocessing of telemetry data at the sensor module level before data is passed to analysis modules. This preliminary action reduces the volume of data that requires complex anomaly detection, improving analysis efficiency while maintaining detection capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies different analysis strategies to different portions of the data stream. High-volume routine data receives simplified processing while suspicious or anomalous data receives more intensive analysis, optimizing the balance between detection capability and processing efficiency.

Inventive Principle:
Principle #3Local quality

4Reliability

If network telemetry information is collected and stored for historical analysis, then security threat identification is enhanced, but the process takes time and provides information only after a breach has occurred

Engineering Contradiction:
Improvethreat identificationVSAvoiddetection delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements continuous real-time analysis of network telemetry data through distributed sensor and analysis modules. Instead of batch processing historical data, the system continuously monitors and analyzes data streams, enabling immediate detection and response to security threats as they occur.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS8973132B2Automated security analytics platform with pluggable data collection and analysis modules
Publication Date: 2015.03.03 ALERT LOGIC LLC
  • US8973132B2 patent drawing
  • US8973132B2 patent drawing
  • US8973132B2 patent drawing

AI summary

Pluggable network security modules provide a collaborative response across plural networks by allowing modules associated with detection and neutralization of a network security threat to plug into a network security platform of other networks. Plugging the security modules in provides an automated insertion of detection and neutralization tools into the network security platform to respond to potential threats based upon proven successful responses at other networks.