Interactive Threat History Graph for Network Security Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems lack effective methods for extracting and presenting threat information in a way that allows for accurate identification, analysis, and reporting of threats, making it difficult to assess and improve security measures.

Innovation Solution

A system and method for extracting and processing threat information from firewall and historical logs, presenting it in an interactive historical graph, and allowing administrators to zoom into specific time periods for detailed analysis, with customizable graphical and tabular representations to facilitate threat identification and reporting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If threat information is extracted and presented in detailed tabular form, then measurement precision of threat analysis is improved, but device complexity and time consumption increase

Engineering Contradiction:
Improvethreat analysis precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments threat information presentation into two distinct views: a graphical overview mode showing aggregated threat data visually, and a detailed tabular mode showing comprehensive threat attributes. This segmentation allows users to switch between views based on their specific needs, obtaining detailed threat analysis precision when required while avoiding unnecessary complexity during routine monitoring.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements dynamic presentation that adapts to user interaction. The threat information is presented in a flexible manner that can transition between graphical summaries and detailed tables based on user selection. This dynamic approach optimizes the balance between analysis precision and system complexity by only displaying detailed information when explicitly requested.

Inventive Principle:
Principle #15Dynamics

2Reliability

If comprehensive threat logs are maintained and analyzed, then reliability of threat detection is improved, but loss of time in processing and presenting data increases

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoiddata processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts and presents only the most relevant threat information in the graphical overview, displaying aggregated statistics and key threat patterns without showing complete raw log data. This extraction approach maintains reliable threat detection by focusing on critical indicators while significantly reducing the time required to process and present threat information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements partial action by displaying a summarized view of threat information that includes the most important attributes and patterns. Rather than processing and presenting every single log entry in detail, the system focuses on representative samples and aggregated statistics, maintaining detection reliability while minimizing time consumption.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If interactive graphical presentation with zoom capability is implemented, then ease of operation for threat analysis is improved, but device complexity increases

Engineering Contradiction:
Improvethreat analysis easeVSAvoidinterface complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a nested presentation structure where a graphical overview serves as the outer layer, and detailed tabular information is nested within as an inner layer. Users can access detailed information by interacting with specific elements in the graphical view, creating a nested hierarchy that improves ease of operation while managing interface complexity through organized information layers.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The system adds an interactive dimension to threat presentation by implementing zoom and drill-down capabilities. This allows users to navigate from a high-level graphical overview to detailed tabular information through intuitive interactions, significantly improving ease of operation. The dimensional transition between overview and detail views is managed through standardized interface patterns that minimize the perceived complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9888023B2Presentation of threat history associated with network activity
Publication Date: 2018.02.06 FORTINET INC
  • US9888023B2 patent drawing
  • US9888023B2 patent drawing
  • US9888023B2 patent drawing

AI summary

Methods and systems for extracting, processing, displaying, and analyzing events that are associated with one or more threats are provided. According to one embodiment, threat information, including information from one or more of firewall logs and historical threat logs, is maintained in a database. Information regarding threat filtering parameters is received. Information regarding threats matching the threat filtering parameters are extracted from the database and is presented in a form of an interactive historical graph. Responsive to receiving from an administrator an indication regarding a selected subset of time in which to zoom into for further details, a list of threats within the selected subset is presented in tabular form.