Automated Security Analytics Platform Using Active Memory
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network security tools are ineffective in providing real-time protection against malicious attacks due to their reliance on database analysis, which results in delayed threat detection and response, allowing cybercriminals to exploit vulnerabilities and access sensitive information.
Innovation Solution
An automated security analytics platform that utilizes an active memory to store and analyze network telemetry information in real-time, employing pluggable network security modules and visualization-agnostic selection linked portlets to detect and neutralize threats efficiently, while optimizing memory usage through incremental partial serialization and collaborative threat response across networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional database analysis is used to process network telemetry information, then comprehensive security analysis can be performed, but real-time threat detection is delayed
Solution Approach 1:
The patent segments network telemetry processing by dividing data into hot data (recent, high-priority) stored in active memory and cold data (historical, lower-priority) stored in database. This segmentation enables real-time analysis of critical data while maintaining comprehensive analysis capabilities for historical data, resolving the contradiction between detection speed and analysis completeness.
Solution Approach 2:
The patent introduces active memory as an intermediary layer between network sensors and database systems. This intermediary enables rapid access to recent telemetry data for immediate threat detection, while still allowing comprehensive database analysis for historical context, thus bridging the gap between real-time response and thorough analysis.
2Speed
If all network telemetry information is stored in active memory for real-time access, then fast threat detection is enabled, but memory resource consumption increases
Solution Approach 1:
The patent applies local quality by storing different types of data in different memory locations based on their access requirements. Hot data requiring fast access is stored in active memory, while cold data is stored in database. This localized optimization of storage quality enables fast access where needed without unnecessarily consuming active memory resources for all data.
Solution Approach 2:
The patent implements partial action by selectively loading only the most recent and critical telemetry data into active memory rather than storing all historical data there. This partial loading strategy provides sufficient data for real-time threat detection while avoiding excessive memory consumption that would result from storing complete historical datasets in active memory.
3Reliability
If network security modules continuously monitor all network activity, then comprehensive threat detection is achieved, but system performance degradation occurs
Solution Approach 1:
The patent merges security monitoring functions by consolidating multiple security modules into a unified architecture that shares common data structures and processing pipelines. This merging reduces redundant operations and improves overall system efficiency, maintaining comprehensive monitoring coverage while minimizing performance overhead through optimized resource utilization.
Data Source
AI summary
A network security platform stores network telemetry information in an active memory, such as DRAM, and analyzes the network telemetry information to detect and respond to network security threats. Using a common active memory to store sensed network telemetry information and analyze that information provides a real-time dataflow engine for detecting security threats and neutralizing detected threats.


