Time-Based Network Topology for Accurate Security Digital Twins
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems fail to create accurate digital twins of large and complex computer networks due to issues such as data volume, overlap, and noise in network data, and the failure to create a complete situational awareness and understanding of network data, and the failure to create a digital twin of a network due to large volumes of network data, overlap and duplication of information, sparse and/or noisy network data, multiple protocols, multiple data types, multi-layer networks, and the failure to create a digital twin of a network due to large volumes of network data, overlap and duplication of information, sparse and/or noisy network data, multiple data types, multi-layer networks, differentiation of device roles, etc., in creating a digital twin of a network.
Innovation Solution
A security system generates a time-based computer network topology by collecting raw network data, extracting metadata, updating a network database, correlating with structured metadata, and generating a network history update to create a digital twin of the network, providing a visualization of network assets and events over time, enabling operational visibility and situational awareness.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If conventional systems attempt to create a digital twin of a large network, then complete situational awareness and understanding of network systems and behaviors is achieved, but the system fails due to large volumes of network data, overlap and duplication of information, sparse and/or noisy network data, multiple protocols, multiple data types, multi-layer networks, and differentiation of device roles
Solution Approach 1:
The patent segments the complex network data processing task into distinct functional modules: a data collection module that gathers raw network data from multiple sources, a data processing module that cleans and structures the data, and a digital twin generation module that creates the virtual representation. This segmentation allows each module to handle specific aspects of the complexity independently, making the overall system manageable despite the large volumes and diversity of network data.
Solution Approach 2:
The patent introduces an intermediary data processing layer that acts as a mediator between the raw network data and the digital twin generation process. This intermediary module standardizes and structures the diverse network data from multiple protocols and data types, converting it into a unified format that can be processed by the digital twin generation module, thereby resolving the complexity arising from multiple protocols and data types.
2Measurement precision
If the system collects and processes all raw network data to create an accurate digital twin, then measurement precision of network state is improved, but the data volume and processing complexity increase significantly
Solution Approach 1:
The patent extracts only the essential and relevant features from the large volumes of raw network data through a data processing module that identifies and extracts key network parameters, device states, and behavioral patterns. This extraction process filters out redundant and noisy information, maintaining measurement precision of the network state while significantly reducing the data volume that needs to be stored and processed for digital twin creation.
Solution Approach 2:
The patent applies partial action by selectively processing and collecting specific network data that is most relevant to creating an accurate digital twin, rather than processing all available network data equally. The system identifies and focuses on critical network parameters and events that provide the necessary measurement precision while avoiding the processing overhead of excessive or redundant data.
3Speed
If the system processes network data in real-time to provide operational visibility, then the speed of detection of anomalous activities is improved, but the processing time and computational resources increase
Solution Approach 1:
The patent implements preliminary action by pre-processing and structuring network data as it is collected, organizing it into standardized formats and identifying key patterns before the digital twin generation process begins. This preliminary structuring of data reduces the computational burden during real-time processing, enabling faster detection of anomalous activities without sacrificing detection speed, as the data is already prepared and organized for rapid analysis.
Data Source
AI summary
Time-based computer network topology for network security is described. Network metadata is extracted from raw network data from one or more collection points on a network to form structured metadata. A network database is updated with the structured metadata. A network topology update is generated that is associated with a first time period based in part on the structured metadata and a prior network topology update. The network topology update is correlated with the structured metadata to generate network history update. The network history update is recorded in the network database to form a complete network history. A visualization is generated of a time-based computer network topology of the network for a target time within a range of time (including the first time period) using the complete network history. The visualization is provided to an administrative client.


