Security Log Visualization for Rapid Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security log analysis systems are ineffective for real-time monitoring and response to cyber attacks, requiring expertise and struggling with text-based security log data analysis, which hinders quick identification and response to potential threats.

Innovation Solution

A security information visualization device and method that preprocesses log data to calculate period data related to IP address information, providing visualization information that highlights IP addresses with high security danger, allowing non-expert administrators to quickly identify and respond to cyber incidents by visualizing log data amounts and changes over time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If security log data is analyzed using traditional text-based methods, then analysis accuracy may be maintained, but response time is too slow and requires expert knowledge

Engineering Contradiction:
Improveresponse timeVSAvoidease of use
Core Design Contradiction:
Loss of timeVSEase of operation

Solution Approach 1:

The patent transforms security log data from text format to structured numerical data by extracting features such as attack frequency, time of day, day of week, and source IP information. This parameter transformation enables quantitative analysis and visualization, allowing security administrators to quickly identify threats through graphical representations rather than manual text analysis.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary processing system that converts raw security log data into visualized numerical representations. This intermediary layer includes feature extraction modules, data processing modules, and visualization modules that translate complex text-based security logs into intuitive graphical formats, making the data accessible to non-expert administrators.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If security log data is visualized to improve ease of use, then non-expert administrators can understand the data, but the complexity of the visualization system increases

Engineering Contradiction:
Improveease of useVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent divides the security log analysis system into distinct functional modules: a feature extraction module that separates relevant information from raw logs, a data processing module that structures the extracted features, and a visualization module that presents the processed data. This segmentation allows each module to handle specific tasks independently, reducing overall system complexity while maintaining ease of use.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts only the essential security-relevant features from comprehensive security log data, such as attack frequency, temporal patterns, and source IP information. By taking out and focusing on these critical elements rather than processing all raw data, the system achieves simplicity and ease of use without sacrificing security analysis effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If detailed security log analysis is performed to improve detection accuracy, then cyber attacks can be identified, but the time required for analysis increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary feature extraction and data structuring on security log information before actual security analysis is needed. By pre-processing the data into structured numerical formats with extracted features like attack frequency and temporal patterns, the system eliminates time-consuming text analysis during incident response, achieving both high detection accuracy and rapid response.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual text-based analysis mechanisms with automated computational processing. Instead of security administrators manually examining text logs, the system uses automated feature extraction, data structuring, and visualization modules that rapidly process and present security information, maintaining high detection accuracy while dramatically reducing analysis time.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11876820B2Security information visualization device, security information visualization method, and storage medium for storing program for visualizing security information
Publication Date: 2024.01.16 KOREA INST OF SCI & TECH INFORMATION
  • US11876820B2 patent drawing
  • US11876820B2 patent drawing
  • US11876820B2 patent drawing

AI summary

A security information visualization method including the steps of: preprocessing log data extracted from a security device; calculating, from the pre-processed log data, periodic data of element information related to internet protocol (IP) address information about a security action; and providing visualization information visualizing the IP address information and the calculated periodic data of element information.