Threat Incident Visualization via 3D Spatial Modelling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cyber-security threat incident evaluation systems face challenges in efficiently and accurately assessing large-scale threats due to the overwhelming number of false alerts and the difficulty in visualizing relationships between incidents, leading to resource misallocation and potential network breaches.
Innovation Solution
A system and method that uses graphical objects on a touch interface to represent cyber-security threat incidents, allowing for real-time risk scoring and targeted mitigation actions by selecting subsets of incidents through continuous touch inputs, thereby reducing false alerts and optimizing resource deployment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If text-based rows of TIF records are displayed to evaluate cyber-security threat incidents, then the system can handle large volumes of security events, but it becomes difficult to visualize relationships between incidents and increases the possibility of errors
Solution Approach 1:
The patent transforms the traditional text-based row display into a visual spatial representation where incidents are displayed as graphical objects in a two-dimensional or three-dimensional space. This dimensional change allows security analysts to see relationships between incidents spatially, such as grouping related incidents together or visualizing attack patterns across multiple dimensions, thereby recovering the lost relationship information while maintaining the ability to process large volumes of security events.
Solution Approach 2:
The patent creates visual copies of security event data in the form of graphical objects that represent incidents. Instead of displaying raw text records, the system generates visual representations that can be manipulated and analyzed in space. These graphical copies maintain the essential information of the original incidents while enabling new ways to perceive and understand relationships between them through spatial arrangement and visual patterns.
2Reliability
If more monitoring devices are deployed to detect anomalous events, then the system can detect more security threats, but the number of false alerts increases and computing resources are misallocated
Solution Approach 1:
The patent merges multiple individual incident evaluations into a collective risk assessment. By displaying incidents as graphical objects in spatial arrangement, the system allows analysts to evaluate groups of related incidents together rather than individually. This merging approach helps distinguish true threats from false alerts by observing patterns across multiple incidents, thereby reducing resource misallocation caused by treating false alerts as genuine threats.
Solution Approach 2:
The visual spatial representation provides immediate feedback to security analysts about incident relationships and patterns. The system enables analysts to see how incidents cluster or distribute in space, providing intuitive feedback about the nature and scope of threats. This feedback mechanism helps analysts make more accurate assessments and avoid deploying resources to false alerts by revealing the contextual relationships between incidents.
3Measurement precision
If security analysts review each row of TIF records individually, then detailed assessment of each incident is possible, but the evaluation process becomes time-consuming and inefficient
Solution Approach 1:
The patent segments the evaluation process into different visual scales. Analysts can first overview multiple incidents simultaneously in a broad spatial view to identify obvious patterns or threats, then selectively focus on specific groups or individual incidents that require detailed examination. This segmentation allows efficient screening of large numbers of incidents while maintaining the ability to perform detailed assessment when needed, significantly reducing the time required for comprehensive incident evaluation.
Solution Approach 2:
The system enables analysts to perform partial evaluation by visually scanning groups of incidents without examining each one in detail. The spatial representation allows analysts to quickly assess overall threat levels and incident relationships through visual patterns, applying detailed analysis only to specific incidents or groups that warrant further investigation. This partial action approach maintains sufficient assessment accuracy while dramatically reducing the time investment required compared to reviewing every incident individually.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system and method for evaluating cyber-security threat incidents of a computer network is described in this document. In particular, it is described that cyber-security threat incidents of a computer network may be visualized by displaying these threat incidents as a plurality of graphical objects on a display of a device. A subset of these graphical objects or threat incidents may then be selected by applying a single continuous touch input to a touch interface of the device. A risk score will then be generated and displayed based on the threat incidents that are contained within the subset of graphical objects. Mitigation actions addressing the cyber-security threats that triggered these threat incidents are then implemented by the device.