Time-Based Network Topology for Accurate Security Digital Twins

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems fail to create accurate digital twins of large and complex computer networks due to issues such as data volume, overlap, and noise in network data, and the failure to create a complete situational awareness and understanding of network data, and the failure to create a digital twin of a network due to large volumes of network data, overlap and duplication of information, sparse and/or noisy network data, multiple protocols, multiple data types, multi-layer networks, and the failure to create a digital twin of a network due to large volumes of network data, overlap and duplication of information, sparse and/or noisy network data, multiple data types, multi-layer networks, differentiation of device roles, etc., in creating a digital twin of a network.

Innovation Solution

A security system generates a time-based computer network topology by collecting raw network data, extracting metadata, updating a network database, correlating with structured metadata, and generating a network history update to create a digital twin of the network, providing a visualization of network assets and events over time, enabling operational visibility and situational awareness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If conventional systems attempt to create a digital twin of a large network, then complete situational awareness and understanding of network systems and behaviors is achieved, but the system fails due to large volumes of network data, overlap and duplication of information, sparse and/or noisy network data, multiple protocols, multiple data types, multi-layer networks, and differentiation of device roles

Engineering Contradiction:
Improvecomplete situational awarenessVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent segments the complex network data processing task into distinct functional modules: a data collection module that gathers raw network data from multiple sources, a data processing module that cleans and structures the data, and a digital twin generation module that creates the virtual representation. This segmentation allows each module to handle specific aspects of the complexity independently, making the overall system manageable despite the large volumes and diversity of network data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary data processing layer that acts as a mediator between the raw network data and the digital twin generation process. This intermediary module standardizes and structures the diverse network data from multiple protocols and data types, converting it into a unified format that can be processed by the digital twin generation module, thereby resolving the complexity arising from multiple protocols and data types.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If the system collects and processes all raw network data to create an accurate digital twin, then measurement precision of network state is improved, but the data volume and processing complexity increase significantly

Engineering Contradiction:
Improvenetwork state accuracyVSAvoiddata volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential and relevant features from the large volumes of raw network data through a data processing module that identifies and extracts key network parameters, device states, and behavioral patterns. This extraction process filters out redundant and noisy information, maintaining measurement precision of the network state while significantly reducing the data volume that needs to be stored and processed for digital twin creation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by selectively processing and collecting specific network data that is most relevant to creating an accurate digital twin, rather than processing all available network data equally. The system identifies and focuses on critical network parameters and events that provide the necessary measurement precision while avoiding the processing overhead of excessive or redundant data.

Inventive Principle:
Principle #16Partial or excessive action

3Speed

If the system processes network data in real-time to provide operational visibility, then the speed of detection of anomalous activities is improved, but the processing time and computational resources increase

Engineering Contradiction:
Improvedetection speedVSAvoidprocessing time
Core Design Contradiction:
SpeedVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-processing and structuring network data as it is collected, organizing it into standardized formats and identifying key patterns before the digital twin generation process begins. This preliminary structuring of data reduces the computational burden during real-time processing, enabling faster detection of anomalous activities without sacrificing detection speed, as the data is already prepared and organized for rapid analysis.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12519699B1Time-based computer network topology for network security
Publication Date: 2026.01.06 CYBERSPATIAL INC
  • US12519699B1 patent drawing
  • US12519699B1 patent drawing
  • US12519699B1 patent drawing

AI summary

Time-based computer network topology for network security is described. Network metadata is extracted from raw network data from one or more collection points on a network to form structured metadata. A network database is updated with the structured metadata. A network topology update is generated that is associated with a first time period based in part on the structured metadata and a prior network topology update. The network topology update is correlated with the structured metadata to generate network history update. The network history update is recorded in the network database to form a complete network history. A visualization is generated of a time-based computer network topology of the network for a target time within a range of time (including the first time period) using the complete network history. The visualization is provided to an administrative client.