Real-Time Threat Detection in High Volume Network Data Streams

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems are limited in detecting novel or non-signature based threats due to their narrow view and reliance on deterministic procedures, and they struggle with analyzing large, unwieldy data logs from protection devices like firewalls and proxies, making it impractical to identify threats in real time.

Innovation Solution

A high-speed threat detection system that includes a data analysis unit with a relational database engine to analyze network data in real time, package it into time-based slices, identify patterns, and output relevant patterns to operators, using methods like rate-detection and rare value detection to reduce data volumes and identify potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If protection devices (firewall, proxies) log data streams to detect threats, then threat detection capability is improved, but data log volume becomes excessively large and unwieldy for real time analysis

Engineering Contradiction:
Improvethreat detection capabilityVSAvoiddata log volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the relevant threat information from the massive data logs generated by protection devices. Instead of analyzing the entire log volume, the system extracts and focuses on specific patterns and anomalies that indicate threats, thereby reducing the effective data volume for analysis while maintaining detection capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary data processing layer between the protection devices and the analysis system. This intermediary layer pre-processes and filters the raw log data, transforming it into a more manageable format that highlights only the critical threat indicators, thus bridging the gap between high data volume and real-time analysis requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If known devices analyze data flow using signatures of known attack vectors, then deterministic threat identification is improved, but ability to detect novel or non-signature based threats deteriorates

Engineering Contradiction:
Improvethreat identification accuracyVSAvoiddetection of novel threats
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent employs dynamic analysis techniques that adapt to evolving threat patterns. Instead of relying on static signatures, the system dynamically learns from network behavior patterns and can identify anomalies that indicate novel threats. This dynamic approach allows the system to detect previously unknown attack vectors by recognizing deviations from normal behavior patterns.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the detection parameters from fixed signatures to statistical patterns and behavioral anomalies. By analyzing changes in network traffic parameters over time and identifying deviations from established baselines, the system can detect novel threats that do not match any known signature, thereby enhancing both precision and adaptability.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If network security systems log all data streams for analysis, then comprehensive threat coverage is improved, but processing time and system complexity increase

Engineering Contradiction:
Improvethreat coverageVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the data stream analysis into multiple stages: initial filtering of obviously malicious traffic, pattern recognition in remaining data, and detailed analysis only of suspected threats. This segmentation allows comprehensive threat coverage while reducing processing time by avoiding exhaustive analysis of all data streams.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary actions by pre-processing and filtering data streams before they enter the main analysis queue. By identifying and removing clearly benign or already-handled traffic in advance, the system reduces the volume of data requiring full analysis, thereby decreasing processing time while maintaining comprehensive coverage through the preliminary filtering stage.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7961633B2Method and system for real time detection of threats in high volume data streams
Publication Date: 2011.06.14 TRUSTWAVE HOLDINGS INC
  • US7961633B2 patent drawing
  • US7961633B2 patent drawing
  • US7961633B2 patent drawing

AI summary

A high speed detection system and method capable of generating audits of investigable patterns from log data using techniques for grouping and filtering the data so as to create vectors of patterns which can be then further analyzed by applying conditional filters to conclude that a threat may be active has been created to solve at least the above discussed problems.