Tracker Engine for Network Entity Visualization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Diagnostic tools in networked environments struggle to effectively visualize and analyze the multitude of operations across entities, leading to potentially vulnerable points being overlooked due to raw data not being easily consumable and analyzed by administrators.
Innovation Solution
A tracker engine generates a graphical and interactive visualization of entities and operations, aggregating information on file, user, process, and communication activities, allowing for the identification of relationships and pinpointing vulnerabilities through a user interface with features like pinning, tagging, and pivoting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If a diagnostic tool logs and displays raw data of entities and operations in delimited or list format, then complete information is recorded, but the data is not easily consumable and analyzed by administrators
Solution Approach 1:
The patent transforms flat, one-dimensional raw data into a two-dimensional graphical visualization where entities are represented as nodes and operations as edges connecting them. This dimensional transformation allows administrators to perceive relationships and patterns that are invisible in traditional list formats, making the data both complete and easily analyzable simultaneously
Solution Approach 2:
The patent introduces an intermediary processing layer between data collection and administration. This intermediary automatically aggregates raw logs, identifies relationships among entities, and generates visual representations, thereby bridging the gap between complete data recording and easy data analysis without losing information
2Reliability
If a tracker engine aggregates information on multiple entities and operations, then network vulnerabilities can be identified, but the system complexity increases
Solution Approach 1:
The patent segments the complex network monitoring task into distinct functional modules: entity identification, operation tracking, relationship aggregation, and visual presentation. Each module handles a specific aspect of the monitoring process, making the overall system more manageable and maintainable while preserving comprehensive vulnerability detection capabilities
Solution Approach 2:
The tracker engine is designed as a universal system that can monitor multiple entity types (users, files, processes, devices) and operation types (read, write, execute, communicate) through a single integrated platform. This multi-functionality reduces system complexity by consolidating what would otherwise require multiple separate tools into one unified solution
Data Source
AI summary
Provided herein are systems and methods of investigating an entity or a potential incident. A tracker engine may receive an identification of a first entity in a networked environment. The tracker engine may display, in a user interface responsive to receiving the identification, a representation of the first entity, and representations of a plurality of entities associated with the first entity. The plurality of associated entities may include: a network connection, a file, a process, a user or a computing device. The tracker engine may receive, via the user interface, a selection of a second entity from the plurality of associated entities. The tracker engine may update, responsive to receiving the selection, the user interface to display a representation of the second entity graphically linked to the representation of the first entity, and representations of a plurality of entities associated with the second entity.


