3D Threat Wells for Security Event Aggregation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Security Operation Center (SOC) analysts face overwhelming amounts of irrelevant and redundant information from multiple user interfaces, making it difficult to accurately and intuitively describe security issues, which delays the deployment of countermeasures due to inaccuracies in summarizing security threats.
Innovation Solution
A method and system that aggregates security events from various sources to represent threats as three-dimensional graphical objects, known as 'threat wells,' in a graphical user interface, allowing for intuitive visualization and prioritization of security threats based on their severity, enabling timely and effective countermeasures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple user interfaces from different vendors are used to monitor security threats, then comprehensive security coverage is improved, but information overload and analyst workload increase
Solution Approach 1:
The patent combines multiple security event sources and vendor interfaces into a single unified graphical display. Different event sources are aggregated and presented together in one interface, allowing analysts to view comprehensive security information without switching between multiple vendor-specific interfaces. This merging approach maintains complete security coverage while eliminating information overload.
Solution Approach 2:
The graphical interface serves multiple functions simultaneously: it aggregates events from different vendors, visualizes security threats, prioritizes incidents, and enables analyst response. This multi-functional interface replaces numerous specialized vendor interfaces with a single universal system that handles all security monitoring needs.
2Measurement precision
If detailed security event information is presented to analysts, then accuracy of threat assessment is improved, but time to process and prioritize threats increases
Solution Approach 1:
The graphical interface applies different visual properties to different aspects of security events based on their importance. Critical threat characteristics are highlighted with prominent visual cues, while less important details are subdued. This local differentiation allows analysts to quickly identify and assess critical threats without being overwhelmed by all available information.
Solution Approach 2:
The system uses color coding to indicate threat severity and priority levels. Different colors represent different threat levels, allowing analysts to immediately grasp the urgency and nature of each security event. This visual encoding maintains assessment accuracy by preserving detailed information while enabling rapid triage through intuitive color-based prioritization.
3Ease of operation
If traditional flat graphical interfaces are used to display security threats, then ease of operation is improved, but ability to convey threat severity and priority is insufficient
Solution Approach 1:
The patent transitions from flat two-dimensional interfaces to three-dimensional graphical representations. Threats are displayed as 3D objects with varying heights, volumes, and spatial positions that encode different aspects of threat severity. This dimensional enhancement preserves ease of graphical interaction while richly conveying threat information through spatial and visual properties.
Solution Approach 2:
The system uses spherical or rounded graphical objects to represent security threats instead of flat geometric shapes. These 3D forms provide intuitive visual metaphors where size, height, and position convey different threat attributes. The curved, volumetric representations maintain graphical intuitiveness while encoding substantially more threat information than flat interfaces.
Data Source
AI summary
A method, apparatus and computer program product for managing security threats to a distributed network. A set of events are aggregated from a plurality of event sources in the network for each of a set of security threats to the network. A magnitude of a characteristic of each of the set of security threats is determined. Each of the set of security threats is represented as a three dimensional graphical object in a three dimensional (3D) representation of the network according to the respective magnitude of the characteristic. A security action is taken based on the determined magnitude of one of the set of security threats.


