Service Flow Rank Determination via Dependency Strength

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for analyzing computer networks fail to effectively determine service flow ranks based on flow dependencies, which is crucial for identifying critical services and dependencies, especially in the context of cyber-attacks, where mission assurance and resource allocation are critical.

Innovation Solution

A computer-implemented method and system that calculates service flow ranks by determining dependency sets and strengths among data flows, using source and destination IP addresses, start times, and associated services to generate scenarios and quantify dependency strengths, ultimately creating a resource dependency map for mission-critical asset monitoring and attack mitigation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If current methods for analyzing computer networks are used, then basic data flow tracking is possible, but service flow ranks based on flow dependencies cannot be effectively determined

Engineering Contradiction:
Improveservice flow rank determinationVSAvoidflow dependency information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent segments the network analysis process into distinct components: data flow identification, dependency relationship extraction, and service flow ranking. By dividing the complex analysis into manageable segments, the system can effectively determine service flow ranks based on flow dependencies that were previously lost in holistic analysis approaches.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary processing layer that captures and analyzes flow dependency information between data flows. This intermediary component extracts dependency relationships from network traffic and uses them to rank service flows, preventing the loss of critical dependency information that occurs in direct analysis methods.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive data flow analysis is performed to identify critical services, then mission assurance can be improved, but system complexity increases

Engineering Contradiction:
Improvemission assuranceVSAvoidanalysis system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by focusing analysis on specific flow dependency relationships rather than treating all network traffic uniformly. By identifying and analyzing only the critical dependency relationships that affect service flow ranks, the system achieves improved mission assurance without requiring exhaustive analysis of every network packet, thus reducing overall system complexity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the analysis parameters from comprehensive packet-level inspection to flow-level dependency analysis. By shifting the focus to higher-level flow characteristics and dependency relationships, the system achieves effective mission assurance with reduced computational complexity compared to detailed packet examination.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If detailed flow dependency tracking is implemented, then attack mitigation accuracy is improved, but processing time increases

Engineering Contradiction:
Improveattack mitigation accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary action by pre-identifying and storing flow dependency relationships before security analysis is needed. By establishing the dependency structure in advance, the system can quickly retrieve and use this information during attack mitigation without performing time-consuming real-time analysis, thus improving accuracy while reducing processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial action by focusing dependency tracking on only the most critical flow relationships that impact security decisions. Rather than tracking all possible dependencies equally, the system identifies and monitors the subset of dependencies that are most relevant to attack mitigation, achieving high accuracy with reduced processing overhead.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10547515B2Methods and systems for improved computer network analysis
Publication Date: 2020.01.28 THE BOEING CO
  • US10547515B2 patent drawing
  • US10547515B2 patent drawing
  • US10547515B2 patent drawing

AI summary

A computer-implemented method for determining service flow rank based on service flow dependency is provided. The method includes receiving a plurality of data flow information for a plurality of data flows. Each data flow of the plurality of data flows includes a source, a destination, a start time, and an associated service. The method also includes determining a plurality of dependency sets based on the plurality of data flow information. Each dependency set of the plurality of dependency sets includes at least a first data flow and a second data flow. The method further includes calculating a plurality of dependency strengths based on the plurality of dependency sets, calculating a plurality of total service scores based on the first data flows of the plurality of dependency sets, and calculating a plurality of service flow ranks based on the plurality of dependency strengths and the plurality of total service scores.