Visual Spreadsheet for Network Log Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity solutions, such as SIEMs and log management systems, are complex, costly, and require significant technical expertise, making it difficult for security analysts to efficiently ingest, normalize, and analyze large volumes of network security data for threat hunting and incident response, especially due to limitations in handling historical data and integrating new data sources.

Innovation Solution

A networking data analysis system with a spreadsheet-like interface that automates data transformation, enrichment, and visualization, using machine learning for advanced threat detection, and allowing easy import and exploration of multi-million row datasets, with features like automatic time-based summarization and threat intelligence integration, reducing the need for extensive setup and configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional SIEMs and log management systems are used for network security data analysis, then data analysis capability is improved, but system complexity and cost increase significantly

Engineering Contradiction:
Improvedata analysis capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a simplified copy of spreadsheet functionality tailored for security log analysis. Instead of requiring analysts to master complex SIEM systems, the invention replicates the familiar spreadsheet interface and behavior, allowing users to analyze security data with simple formulas and visual tools that mimic conventional spreadsheet applications.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent employs lightweight, easily deployable components rather than heavy enterprise systems. The solution uses simple spreadsheet-based files that can be created, modified, and shared without complex infrastructure, replacing the need for expensive, permanent SIEM installations with flexible, disposable analysis templates.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Measurement precision

If traditional SIEMs and log management systems are used for network security data analysis, then data analysis capability is improved, but cost increases significantly

Engineering Contradiction:
Improvedata analysis capabilityVSAvoidcost
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent replaces expensive enterprise software licenses and hardware infrastructure with inexpensive spreadsheet files and standard computing platforms. The solution uses readily available tools that organizations already possess, eliminating the need for costly specialized security analysis systems while maintaining effective data analysis capabilities.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Measurement precision

If traditional SIEMs and log management systems are used for network security data analysis, then data analysis capability is improved, but ease of operation deteriorates due to technical expertise requirements

Engineering Contradiction:
Improvedata analysis capabilityVSAvoidease of operation
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent copies the familiar spreadsheet user interface and interaction patterns into the security analysis domain. Analysts can use known spreadsheet functions, formulas, and visual elements to analyze security logs, eliminating the need to learn proprietary SIEM query languages and complex system configurations.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent enables analysts to perform their own data analysis without requiring specialized system administrators or expensive consultant intervention. The spreadsheet-based system allows users to independently ingest, normalize, and analyze security data using familiar tools, making the system self-sufficient and easy to operate.

Inventive Principle:
Principle #25Self-service

4Speed

If traditional SIEMs and log management systems are used for network security data analysis, then real-time analysis capability is improved, but historical data analysis capability deteriorates

Engineering Contradiction:
Improvereal-time analysis capabilityVSAvoidhistorical data analysis capability
Core Design Contradiction:
SpeedVSDuration of action of stationary object

Solution Approach 1:

The patent creates a universal analysis platform that handles both real-time and historical security data effectively. The spreadsheet-based system can process live log streams as well as analyze archived historical data with equal efficiency, eliminating the trade-off between speed and historical analysis capability that plagues traditional SIEM systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11356345B2Networking data analysis in a visual spreadsheet
Publication Date: 2022.06.07 GIGASHEET INC
  • US11356345B2 patent drawing
  • US11356345B2 patent drawing
  • US11356345B2 patent drawing

AI summary

In an embodiment, a method comprises, by a networking data analysis system: receiving, from a client device, computer files, each computer file comprising log data; transforming each of the computer files, the transforming comprising: converting the log data associated with the computer files into a structured tabular representation of the log data; parsing the structured tabular representation of the log data to extract data elements associated with the log data and to identify data types associated with the data elements; creating a columnar representation of the log data based on the identified data types; storing the columnar representation of the log data in a columnar database; executing computer-implemented functions on the columnar representation of the log data to identify key networking security metrics; sending, to the client device, instructions for displaying the identified key networking security metrics associated with the log data of the one or more computer files.