Visual Analysis of Network Traffic Flow Logs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network traffic flow log data analysis is limited by its text-based format, making deep-level analysis difficult and costly, and lacks efficient methods for visualizing network system structures and communication modes, which are essential in the big data age.
Innovation Solution
A visual analytical method and system that preprocesses network traffic flow logs, uses visualization technologies like chord diagrams and bubble graphs to analyze network nodes, and presents communication modes through pie diagram matrices, enabling intuitive and interactive analysis of server and client interactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If network traffic flow log data is stored in pure text form with simple statistical operations, then implementation is simple, but deep-level analysis cannot be performed and analysis efficiency is low
Solution Approach 1:
The patent transforms network traffic flow log data from pure text format into structured data with multiple dimensions (source IP, destination IP, protocol, port, traffic volume, time, etc.). This parameter transformation enables the data to be processed by visualization systems, allowing deep-level analysis while maintaining implementation feasibility through standardized data structuring.
Solution Approach 2:
The patent introduces a visualization system as an intermediary between the raw network logs and the analyst. This intermediary automatically performs complex queries, aggregations, and pattern recognition, transforming simple text lookup into intelligent visual analysis that reveals network behaviors, anomalies, and communication patterns without requiring manual deep-dive into text logs.
2Quantity of substance
If network traffic flow logs are continuously accumulated in text form, then data volume increases for better coverage, but query and analysis become difficult with high cost and long time
Solution Approach 1:
The patent performs preliminary structuring and dimensioning of network traffic data as it is generated, organizing it into standardized fields (source IP, destination IP, protocol, port, traffic volume, timestamps, etc.) before accumulation. This preliminary organization enables efficient querying and visualization later, allowing analysts to quickly retrieve and analyze specific time periods, IP addresses, or protocols without searching through unstructured text logs.
Solution Approach 2:
The patent replaces manual text-based analysis mechanisms with automated visualization systems that can rapidly query, aggregate, and display network traffic patterns. The system automatically processes large volumes of structured log data, generating visual representations (charts, graphs, heat maps) that reveal network behaviors instantaneously, substituting the mechanical process of manual text scanning with intelligent automated analysis.
3Loss of information
If visualization technology is used to process network traffic flow logs, then data expression becomes intuitive and deep-level analysis is enabled, but system complexity increases
Solution Approach 1:
The patent segments the network traffic analysis into distinct functional modules: data collection module, data structuring module, visualization rendering module, and interaction module. Each module handles specific tasks, allowing the complex visualization system to be built and maintained through manageable components. The data is also segmented into meaningful dimensions (IP addresses, protocols, time periods, traffic types) that can be independently analyzed and visualized.
4Device complexity
If manual analysis of network traffic logs is performed, then system requirements are simple, but only simple statistical operations can be performed without deep-level analysis
Solution Approach 1:
The visualization system performs self-service analysis by automatically querying structured network traffic data, identifying patterns, and generating visual representations without requiring manual intervention for each analysis task. The system can autonomously detect network behaviors, communication patterns, and anomalies, providing deep-level insights while keeping the user interface simple and easy to operate.
Data Source
AI summary
The present disclosure provides a visual analytical method for a network system structure and a network communication mode including following steps: pre-processing network traffic flow log data; dividing and analyzing network nodes by utilizing a visualization technology according to the pre-processed data, and combining a user interaction to determine server nodes and client nodes in the network nodes; performing a visual analysis on traffic flow and an access situation of the server nodes to determine a server function category according to the determined server nodes; and presenting and analyzing the network communication mode through the visualization technology according to the determined server nodes, the client nodes and the server function category. The present disclosure further provides a visual analytical system for the network system structure and the network communication mode.


