Security Analysis Assistance via Departmental Alert Visualization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security analysis systems do not effectively reduce the administrative burden by visualizing traffic in units of departments, making it difficult to determine network risk, especially with the introduction of thin client services that obscure IP address departmental specifications.

Innovation Solution

A security analysis assistance apparatus and method that obtain alerts, organization address information specifying departments, compare alert occurrences by department, and visualize analysis results to facilitate departmental risk assessment in network systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If traffic is visualized in units of IP addresses on a network topology, then the administrator can quickly grasp unauthorized traffic, but it becomes difficult to specify a department by tracing the IP address of a terminal when thin client service is introduced

Engineering Contradiction:
ImproveSpeed of grasping unauthorized trafficVSAvoidLoss of departmental information
Core Design Contradiction:
SpeedVSLoss of information

Solution Approach 1:

The patent introduces a thin client management server as an intermediary between the network traffic visualization system and the thin client terminals. This server maintains the mapping relationship between thin client terminal IDs and department information, allowing the visualization system to display departmental information without directly tracing IP addresses. The intermediary preserves departmental information that would otherwise be lost in thin client environments where IP addresses do not directly correspond to departments.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If manual analysis of alerts is performed using internal-organization information, then the administrator can determine the risk of the network system in units of departments, but the determination imposes a heavy burden on the administrator

Engineering Contradiction:
ImprovePrecision of departmental risk determinationVSAvoidTime burden on administrator
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements automatic visualization of alert occurrence tendencies by department using the thin client management server and the mapping information it maintains. Instead of requiring the administrator to manually analyze alerts and cross-reference them with department information, the system automatically performs this analysis and presents the results in a visual format. This self-service approach maintains precise departmental risk determination while eliminating the time burden on the administrator.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240356939A1Security analysis assistance apparatus, security analysis assistance method, and computer-readable recording medium
Publication Date: 2024.10.24 NEC CORP
  • US20240356939A1 patent drawing
  • US20240356939A1 patent drawing
  • US20240356939A1 patent drawing

AI summary

A security analysis assistance apparatus 10 is an apparatus for assisting security analysis in a network system of an organization. The security analysis assistance apparatus 10 includes: an analysis target obtaining unit 11 that obtains an alert generated in the network system; an information obtaining unit 12 that obtains organization address information specifying at least departments forming the organization and addresses used in the respective departments; an analysis unit 13 that compares the obtained alert with the organization address information, and analyzes the occurrence tendency of the alert for each department of the organization; and a visualization unit 14 that visualizes a result of the analysis performed by the analysis unit 13.