3D Threat Wells for Security Event Aggregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security Operation Center (SOC) analysts face overwhelming amounts of irrelevant and redundant information from multiple user interfaces, making it difficult to accurately and intuitively describe security issues, which delays the deployment of countermeasures due to inaccuracies in summarizing security threats.

Innovation Solution

A method and system that aggregates security events from various sources to represent threats as three-dimensional graphical objects, known as 'threat wells,' in a graphical user interface, allowing for intuitive visualization and prioritization of security threats based on their severity, enabling timely and effective countermeasures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple user interfaces from different vendors are used to monitor security threats, then comprehensive security coverage is improved, but information overload and analyst workload increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidinformation volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent combines multiple security event sources and vendor interfaces into a single unified graphical display. Different event sources are aggregated and presented together in one interface, allowing analysts to view comprehensive security information without switching between multiple vendor-specific interfaces. This merging approach maintains complete security coverage while eliminating information overload.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The graphical interface serves multiple functions simultaneously: it aggregates events from different vendors, visualizes security threats, prioritizes incidents, and enables analyst response. This multi-functional interface replaces numerous specialized vendor interfaces with a single universal system that handles all security monitoring needs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If detailed security event information is presented to analysts, then accuracy of threat assessment is improved, but time to process and prioritize threats increases

Engineering Contradiction:
Improvethreat assessment accuracyVSAvoidthreat processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The graphical interface applies different visual properties to different aspects of security events based on their importance. Critical threat characteristics are highlighted with prominent visual cues, while less important details are subdued. This local differentiation allows analysts to quickly identify and assess critical threats without being overwhelmed by all available information.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system uses color coding to indicate threat severity and priority levels. Different colors represent different threat levels, allowing analysts to immediately grasp the urgency and nature of each security event. This visual encoding maintains assessment accuracy by preserving detailed information while enabling rapid triage through intuitive color-based prioritization.

Inventive Principle:
Principle #32Color changes

3Ease of operation

If traditional flat graphical interfaces are used to display security threats, then ease of operation is improved, but ability to convey threat severity and priority is insufficient

Engineering Contradiction:
Improveinterface usabilityVSAvoidthreat severity information
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent transitions from flat two-dimensional interfaces to three-dimensional graphical representations. Threats are displayed as 3D objects with varying heights, volumes, and spatial positions that encode different aspects of threat severity. This dimensional enhancement preserves ease of graphical interaction while richly conveying threat information through spatial and visual properties.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The system uses spherical or rounded graphical objects to represent security threats instead of flat geometric shapes. These 3D forms provide intuitive visual metaphors where size, height, and position convey different threat attributes. The curved, volumetric representations maintain graphical intuitiveness while encoding substantially more threat information than flat interfaces.

Inventive Principle:
Principle #14Spheroidality (Curvature)

Data Source

PatentUS11228619B2Security threat management framework
Publication Date: 2022.01.18 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11228619B2 patent drawing
  • US11228619B2 patent drawing
  • US11228619B2 patent drawing

AI summary

A method, apparatus and computer program product for managing security threats to a distributed network. A set of events are aggregated from a plurality of event sources in the network for each of a set of security threats to the network. A magnitude of a characteristic of each of the set of security threats is determined. Each of the set of security threats is represented as a three dimensional graphical object in a three dimensional (3D) representation of the network according to the respective magnitude of the characteristic. A security action is taken based on the determined magnitude of one of the set of security threats.