Time Dimension Modeling for Faster, Adaptive Cyber Threat Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber threat analysis techniques lack efficient methods to analyze data in a unified time dimension, leading to low performance and inability to adapt to business changes due to asynchronous batch processing and complex data warehouse technologies.

Innovation Solution

A time data model is defined to establish a time dimension with specific attributes, enabling a relationship-based analysis by creating an association with a second data model, allowing for efficient and adaptable data analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If conventional data warehouse technology and multidimensional analysis data cube are used to analyze data in time dimension, then data analysis can be performed across different security tools, but processing performance is low due to asynchronous batch processing and scanning all data

Engineering Contradiction:
Improvedata analysis performanceVSAvoidprocessing time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent extracts the time dimension as a separate, independent entity from the data warehouse structure. By defining time as a distinct dimension with its own data model and attributes, the system eliminates the need to scan and process all data through complex multidimensional cubes, thereby improving analysis performance and reducing processing time.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the data analysis process by separating time-related operations from event-driven processing. The time dimension is divided into discrete time points with specific attributes, allowing targeted queries on time data without requiring full data scans, thus enhancing productivity and reducing time loss.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If complex data warehouse technology and multidimensional analysis data cube are used, then comprehensive data analysis is enabled, but the model cannot be updated on demand to meet new business requirements

Engineering Contradiction:
Improveadaptability to business changesVSAvoiddata warehouse complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a dynamic time dimension model where time points and their attributes can be added, modified, or removed based on changing business requirements. This dynamic structure allows the system to adapt to new security analysis needs without requiring complex data warehouse restructuring, thereby improving adaptability while managing complexity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The time dimension model serves multiple functions: it provides temporal context for security events, enables time-based queries, supports correlation analysis across different time points, and accommodates various business requirements. This universal approach eliminates the need for separate complex data warehouse structures for different analysis scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If data is queried via time parameters from different data sources and results are merged, then time-based analysis is achieved, but extensive querying and merging operations reduce efficiency

Engineering Contradiction:
Improvetime-based analysis accuracyVSAvoidquery processing efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent merges time data from different sources into a unified time dimension structure during the modeling phase, not during query execution. By consolidating time attributes and establishing relationships between time points in advance, the system eliminates the need for extensive querying and merging operations when performing time-based analysis, thereby improving efficiency while maintaining precision.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12381900B2Building a time dimension based on a time data model and creating an association relationship between the time dimension and a second data model for analyzing data in the time dimension
Publication Date: 2025.08.05 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12381900B2 patent drawing
  • US12381900B2 patent drawing
  • US12381900B2 patent drawing

AI summary

A computer-implemented method according to one approach includes defining a time data model and building a time dimension based on the time data model. The method further includes defining a second data model. An association relationship is created between the time dimension and the second data model for thereafter analyzing data of the second data model in the time dimension. A computer program product according to another approach includes a computer readable storage medium having program instructions embodied therewith. The program instructions are readable and/or executable by a computer to cause the computer to perform the foregoing method. A system according to another approach includes a processor, and logic integrated with the processor, executable by the processor, or integrated with and executable by the processor. The logic is configured to perform the foregoing method.