WO2019046915A1 - System for monitoring data traffic and analysing the performance and usage of a communications network and of information technology systems using this network - Google Patents

System for monitoring data traffic and analysing the performance and usage of a communications network and of information technology systems using this network Download PDF

Info

Publication number
WO2019046915A1
WO2019046915A1 PCT/BR2017/050353 BR2017050353W WO2019046915A1 WO 2019046915 A1 WO2019046915 A1 WO 2019046915A1 BR 2017050353 W BR2017050353 W BR 2017050353W WO 2019046915 A1 WO2019046915 A1 WO 2019046915A1
Authority
WO
WIPO (PCT)
Prior art keywords
analysis
appliances
network
information
transactions
Prior art date
Application number
PCT/BR2017/050353
Other languages
French (fr)
Portuguese (pt)
Inventor
José Rodrigues
Original Assignee
Zerum Research And Technology Do Brasil Ltda
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Zerum Research And Technology Do Brasil Ltda filed Critical Zerum Research And Technology Do Brasil Ltda
Publication of WO2019046915A1 publication Critical patent/WO2019046915A1/en

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F13/00Interconnection of, or transfer of information or other signals between, memories, input/output devices or central processing units
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/18Protocol analysers
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/04Processing captured monitoring data, e.g. for logfile generation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/04Processing captured monitoring data, e.g. for logfile generation
    • H04L43/045Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data

Definitions

  • Utility to an improvement introduced in the set of appliances, notably a combination of hardware and software, capable of capturing, reconstructing and indexing transactions in several protocols, whose function consists basically in the analysis of system performance; forensic analysis; analysis of safety anomalies and breaches; analysis of the use and operation of systems; analysis of network usage.
  • the transactions are structured and made available in a Web interface that displays them intuitively, allowing the creation of alarms and customized screens to attend to each event.
  • FIELD OF APPLICATION The product was developed from the highest technology, with the purpose of supplying deficiencies, alleviating difficulties and solving problems previously encountered by users in the sector, more specifically, the information technology (IT) sector.
  • CHARACTERISTICS AND FUNCTIONALITY This improvement consists of two distinct appliances, currently called WDC and WDA. The first one has the function of capturing Ethernet network traffic; recognize data streams;
  • the WDA functions as a cluster and can store large amounts of information, without supply interval or power in the system, with the use of several similar devices in parallel.
  • the present improvement is essential to carry out its functions adequately, being: - Ethernet packets - Ethernet network packets mirrored from the network segments to be monitored;
  • Scalable real-time textual search engine for unstructured data to analyze extracted data
  • Platform applications also allow the creation of alarms (Transaction Performance, Network Usage, Network Errors) and Appliance Execution parameter management: Thresholds configuration, Network Mastering and Application Master.
  • Asynchronous Tasks Processes for managing tasks execution, such as: Alerts registered, Aggregation of data, Sending of notification by email, Storage of execution results.
  • this product represents an improvement in the ability to structure the selected data (eg HTTP header) and calculated (such as server response time) in text (JSON files) of captured transactions directly from Ethernet network; 2) store and index the information collected in search server that allows the rapid retrieval of information history; 3) visualization of the information in graphs and intuitive tables and creation of customized dashboards.
  • selected data eg HTTP header
  • calculated such as server response time
  • JSON files text
  • the product also provides broad visibility into all transactions performed on user systems, helping to possible problems in the IT operation, thus allowing the repair in less time and with less impact for system users, with an increasingly responsive response time.
  • FIGURES For a clear and objective understanding of the arrangements applied in the present improvement, a flow chart of data will be presented in a demonstrative manner, with references to the following report.
  • FIGURE 1 illustrates the data flow diagram (A), indicating ethemet Package (1); Network packet analysis (2); Preparation of data (3); Search engine (4); Data analyzer (5); Database (6); Web platform (7); Asynchronous tasks (8); Database (9) ⁇ 19.
  • A data flow diagram

Abstract

The present application for a utility model patent is characterized by an improvement made to a set of appliances (A), this being a combination of hardware and software (A), constituted by an ethernet packet (1); network packet analysis (2); data preparation (3); search engine (4); data analyser (5); database (6); web platform (7); asynchronous tasks (8); database (9); developed for the purpose of capturing, reconstructing and indexing transactions in diverse protocols, which consists in the analysis of system performance, forensic analysis, analysis of anomalies and security breaches, analysis of the usage and operation of systems, and analysis of network usage, in which transactions are structured and provided on a web interface.

Description

SISTEMA PARA MONITORAMENTO DO TRÁFEGO DE DADOS E ANÁLISE DO DESEMPENHO E DA UTILIZAÇÃO DE UMA REDE DE COMUNICAÇÕES E DOS SISTEMAS DE TECNOLOGIA DA SYSTEM FOR THE MONITORING OF DATA TRAFFIC AND ANALYSIS OF PERFORMANCE AND USE OF A COMMUNICATIONS NETWORK AND TECHNOLOGY SYSTEMS
INFORMAÇÃO QUE USAM ESTA REDE INFORMATION USING THIS NETWORK
1. BREVE INTRODUÇÃO: Refere-se o presente pedido de patente de Modelo de 1. BRIEF INTRODUCTION: This application relates to the Model
Utilidade, à um aperfeiçoamento introduzido em conjunto de appliances, notadamente, uma combinação de hardware e software, capaz de captar, reconstruir e indexar transações em diversos protocolos, cuja função consiste basicamente na análise de performance de sistemas; análise forense; análise de anomalias e brechas de segurança; análise do uso e operação de sistemas; análise de uso da rede.  Utility, to an improvement introduced in the set of appliances, notably a combination of hardware and software, capable of capturing, reconstructing and indexing transactions in several protocols, whose function consists basically in the analysis of system performance; forensic analysis; analysis of safety anomalies and breaches; analysis of the use and operation of systems; analysis of network usage.
2. Por sua vez, as transações são estruturadas e disponibilizas em uma interface Web que as exibe de forma intuitiva, permitindo a criação de alarmes e telas customizadas para atender à cada evento.  2. In turn, the transactions are structured and made available in a Web interface that displays them intuitively, allowing the creation of alarms and customized screens to attend to each event.
3. O referido aperfeiçoamento destaca-se fundamentalmente pela forma mais prática, rápida e segura no controle e gestão de dados, dotado de aspectos funcionais único, exclusivo e inovador, diferenciando-se dos modelos habituais e tradicionalmente conhecidos.  3. This improvement is fundamentally characterized by the most practical, fast and secure way in data control and management, with unique, exclusive and innovative functional aspects, differing from the usual and traditionally known models.
4. CAMPO DE APLICAÇÃO: O referido produto foi desenvolvido à partir da mais alta tecnologia, com o intuito de suprir deficiências, amenizar dificuldades e solucionar problemas até então encontrados pelos usuários do setor, mais especificamente, setor da tecnologia da informação (TI).  4. FIELD OF APPLICATION: The product was developed from the highest technology, with the purpose of supplying deficiencies, alleviating difficulties and solving problems previously encountered by users in the sector, more specifically, the information technology (IT) sector.
5. CARACTERÍSTICAS E FUNCIONALIDADE: O referido aperfeiçoamento é constituído por dois appliances distintos, atualmente chamados de WDC e WDA. O primeiro deles tem a função de capturar tráfego de rede Ethernet; reconhecer fluxos de dados;  5. CHARACTERISTICS AND FUNCTIONALITY: This improvement consists of two distinct appliances, currently called WDC and WDA. The first one has the function of capturing Ethernet network traffic; recognize data streams;
reconstruir transações e exportar as informações em forma de texto; enquanto o segundo tem a função de coletar as informações exportadas pelo WDC, armazená-las, indexá-las e permitir que sejam executados processos de análise dessas informações, com a menor latência possível.  rebuild transactions and export information in text form; while the second has the function of collecting the information exported by the WDC, storing them, indexing them and allowing processes to analyze that information to be executed, with the lowest possible latency.
6. O WDA funciona como cluster e pode armazenar grande volume de informação, sem intervalo de abastecimento ou alimentação no sistema, com a utilização de vários dispositivos similares em paralelo.  6. The WDA functions as a cluster and can store large amounts of information, without supply interval or power in the system, with the use of several similar devices in parallel.
7. O presente aperfeiçoamento constitui-se de elementos indispensáveis para desempenhar suas funções de maneira adequada, sendo, respectivamente: - Pacotes Ethernet - Pacotes de rede Ethernet espelhados dos segmentos da rede que se deseja realizar a monitoração; 7. The present improvement is essential to carry out its functions adequately, being: - Ethernet packets - Ethernet network packets mirrored from the network segments to be monitored;
- Análise de Pacotes de Rede - Processos de análise de pacotes de rede, ETL (Extract, Transform and Load) dos metadados das transações na camada de aplicação e busca no conteúdo;  - Network Packet Analysis - Network packet analysis, ETL (Extract, Transform and Load) processes of the metadata of the transactions in the application layer and search in the content;
- Preparação de dados: Processos de agregação de dados, enfileiramento de eventos para indexação e indexação de dados extraídos;  - Data preparation: Processes of data aggregation, queuing of events for indexing and indexing extracted data;
- Motor de Busca: Motor de busca textual em tempo real escalável de dados não estruturados para análise dos dados extraídos;  - Search Engine: Scalable real-time textual search engine for unstructured data to analyze extracted data;
- Plataforma Web: Plataforma de aplicativos para visualização, análise, manipulação e gerenciamento dos dados coletados.  - Web Platform: Application platform for visualization, analysis, manipulation and management of collected data.
8. Os aplicativos da plataforma permitem também a criação de alarmes (Performance de Transação, Uso da Rede, Erros de rede) e Gerenciamento dos parâmetros de execução do appliance: Configuração de thresholds, Cadastro de Redes e Cadastro de aplicações.  8. Platform applications also allow the creation of alarms (Transaction Performance, Network Usage, Network Errors) and Appliance Execution parameter management: Thresholds configuration, Network Mastering and Application Master.
9. Tarefas Assíncronas: Processos de gerenciamento de execução tarefas, como: Alertas cadastrados, Agregação de dados, Envio de notificação por e-mail, Armazenamento de resultados de execução.  9. Asynchronous Tasks: Processes for managing tasks execution, such as: Alerts registered, Aggregation of data, Sending of notification by email, Storage of execution results.
10. INOVAÇÃO: Em termos gerais, o referido produto representa uma melhoria no que diz respeito à capacidade de estruturar em texto (arquivos JSON) os dados selecionados (ex: cabeçalho HTTP) e calculados (como tempo de resposta do servidor) de transações capturadas diretamente de rede Ethernet; 2) armazenar e indexar as informações coletadas em servidor de busca que permite a rápida recuperação do histórico de informações; 3) visualização das informações em gráficos e tabelas intuitivos e criação de dashboards customizados.  10. INNOVATION: In general terms, this product represents an improvement in the ability to structure the selected data (eg HTTP header) and calculated (such as server response time) in text (JSON files) of captured transactions directly from Ethernet network; 2) store and index the information collected in search server that allows the rapid retrieval of information history; 3) visualization of the information in graphs and intuitive tables and creation of customized dashboards.
11. A sua utilização resultará em inúmeros benefícios ao consumidor, dentre eles destacamos a possibilidade em detectar falhas em aplicações e infraestrutura; detectar problemas de performance em aplicações, banco de dados, sistemas de armazenamento, webservices; realizar análise forens.  11. Its use will result in numerous benefits to the consumer, among them we highlight the possibility of detecting failures in applications and infrastructure; detect performance problems in applications, databases, storage systems, webservices; perform forensics analysis.
12. Além disso, o produto também provê ampla visibilidade sobre todas as transações executadas nos sistemas do usuário, ajudando a detectar de forma mais veloz a raiz de eventuais problemas na operação de TI, permitindo assim o reparo em menor tempo e com menor impacto para os usuários dos sistemas, com um tempo de resposta cada vez mais ágil.12. In addition, the product also provides broad visibility into all transactions performed on user systems, helping to possible problems in the IT operation, thus allowing the repair in less time and with less impact for system users, with an increasingly responsive response time.
13. DESCRIÇÃO DO ESTADO DA TÉCNICA: Durante o desenvolvimento do referido produto, foram realizadas inúmeras pesquisas para identificar a existência de eventuais anterioridades ou produtos afins. Tais levantamentos, contudo, não apontaram a existência de nenhum outro produto com as mesmas características técnicas preponderantes ou funcionais. 13. DESCRIPTION OF THE STATE OF THE TECHNIQUE: During the development of this product, numerous researches were carried out to identify the existence of possible antecedents or related products. Such surveys, however, did not point to the existence of any other product with the same preponderant or functional technical characteristics.
14. Naturalmente, se tem o pleno conhecimento da existência de outros produtos no mercado, que apresentam suas respectivas funções, como veremos nos casos à seguir: Fluke Truview, Extrahop e Riverbed Steelcenter, que, apesar de coletar e reconstruir as informações diretamente da rede, esses sistemas não são capazes de disponibilizar os dados em sistema de busca por texto (apenas buscas estruturadas, com campos pré-definidos). 14. Of course, you are fully aware of the existence of other products on the market that present their respective functions, as we will see in the following cases: Fluke Truview, Extrahop and Riverbed Steelcenter, which, despite collecting and rebuilding information directly from the network , these systems are not able to make the data available in a text search system (structured searches only, with predefined fields).
15. Sob a ótica técnica, ao comparar as particularidades dos respectivos produtos (embora pertençam ao mesmo titular), ambos, apresentam diferenças expressivas em seu manejo, operação e funcionalidade. 15. From the technical point of view, when comparing the particularities of the respective products (although they belong to the same owner), both present significant differences in their handling, operation and functionality.
16. Diante dessa necessidade e oportunidade comercial, criou-se o referido produto, mais precisamente um conjunto de appliances desenvolvido para captar, reconstruir e indexar transações diversas, estruturadas e disponibilizas em uma interface Web que as exibe de forma intuitiva, permitindo a criação de alarmes e telas customizadas, figurando, portanto, como um produto único, que certamente será um grande diferencial para este segmento que dia após dia tem apresentado um crescimento exponencial, e com um público alvo cada vez mais exigente.  16. Given this need and commercial opportunity, the product was created, more precisely a set of appliances developed to capture, reconstruct and index various transactions, structured and made available in a Web interface that displays them in an intuitive way, allowing the creation of alarms and custom screens, and is therefore a unique product, which will certainly be a great differential for this segment that has been growing exponentially day after day and with an increasingly demanding target audience.
17. FIGURAS: Visando uma compreensão clara e objetiva acerca das disposições aplicadas no presente aperfeiçoamento, serão apresentados diagrama de fluxo de dados em caráter demonstrativo, fazendo referências ao relatório que se segue.  17. FIGURES: For a clear and objective understanding of the arrangements applied in the present improvement, a flow chart of data will be presented in a demonstrative manner, with references to the following report.
18. A FIGURA 1 ilustra o diagrama de fluxo de dados (A), indicando Pacote ethemet (1); Análise pacote de rede (2); Preparação de dados (3); Motor de busca (4); Analisador de dados (5); Base de dados (6); Plataforma web (7); Tarefas assíncronas (8); Base de dados (9)· 19. O presente pedido agora é descrito mais plenamente com referência ao diagrama anexo, em que uma realização ilustrada do presente aperfeiçoamento é mostrado em sequência. FIGURE 1 illustrates the data flow diagram (A), indicating ethemet Package (1); Network packet analysis (2); Preparation of data (3); Search engine (4); Data analyzer (5); Database (6); Web platform (7); Asynchronous tasks (8); Database (9) · 19. The present application is now more fully described with reference to the accompanying diagram, wherein an illustrated embodiment of the present improvement is shown in sequence.
20. Cabe esclarecer que o diagrama de fluxo de dados acima relacionado, o ilustra em carater demonstrativo e não restritivo, cuja concepção poderá variar em suas particularidades técnicas, sem fugir logicamente, do esposo principal cuja proteção é reivindicada.  20. It should be pointed out that the above-mentioned data flow diagram illustrates this in a demonstrative and non-restrictive manner, the conception of which may vary in its technical characteristics, without departing logically, from the principal spouse whose protection is claimed.
21. Logo, em conformidade com o artigo 9o da Lei da Propriedade Industrial n° 9.279/96 e por todos os aspectos apresentados neste relatório, o objeto do presente pedido de patente se faz merecedor da proteção como Modelo de Utilidade, que ora se pleiteia. 21. Therefore, in accordance with Article 9 of the Industrial Property Law No. 9,279 / 96 and for all aspects in this report, the object of this patent application is worthy of protection as a utility model, which we hereby pleiteia

Claims

REIVINDICAÕES
1. APERFEIÇOAMENTO INTRODUZIDO EM CONJUNTO DE APPLIANCES - O presente pedido de patente de Modelo de Utilidade é caracterizado por uma combinação de hardware e software e conjunto de appliances (A), para captar, reconstruir e indexar transações, para promover análise de performance de sistemas, análise forense, análise de anomalias e brechas de segurança, análise do uso e operação de sistemas análise de uso da rede, constituído por Pacote ethemet (1); Análise pacote de rede (2); Preparação de dados (3); Motor de busca (4); Analisador de dados (5); Base de dados (6); Plataforma web (7); Tarefas assíncronas (8); Base de dados (9);  1. A utility model patent application is characterized by a combination of hardware and software and appliances (A) to capture, reconstruct and index transactions to promote system performance analysis , forensic analysis, analysis of anomalies and breaches of security, analysis of the use and operation of systems network usage analysis, consisting of ethemet Package (1); Network packet analysis (2); Preparation of data (3); Search engine (4); Data analyzer (5); Database (6); Web platform (7); Asynchronous tasks (8); Database (9);
2. APERFEIÇOAMENTO INTRODUZIDO EM CONJUNTO DE APPLIANCES - O referido elemento (A) é caracterizado por dois appliances, com a função de capturar tráfego de rede Ethernet; reconhecer fluxos de dados; reconstruir transações e exportar as informações em forma de texto; e função de coletar as informações exportadas pelo WDC, armazená-las, indexá-las e permitir que sejam executados processos de análise;  2. IMPROVEMENT INTRODUCED IN A SET OF APPLIANCES - The said element (A) is characterized by two appliances, with the function of capturing Ethernet network traffic; recognize data streams; rebuild transactions and export information in text form; and the function of collecting the information exported by the WDC, storing them, indexing them and allowing the analysis processes to be executed;
3. APERFEIÇOAMENTO INTRODUZIDO EM CONJUNTO DE APPLIANCES - Caracterizado por estruturar em texto, os dados selecionados e calculados de transações capturadas diretamente de rede Ethernet;  3. PERFORMANCE INTRODUCED INTO A SET OF APPLIANCES - Characterized by text structure, the selected and calculated data of transactions captured directly from the Ethernet network;
4. APERFEIÇOAMENTO INTRODUZIDO EM CONJUNTO DE APPLIANCES - Caracterizado por armazenar e indexar as informações coletadas em servidor de busca que permite a recuperação do histórico de informações;  4. PERFORMANCE INTRODUCED IN A SET OF APPLIANCES - Characterized by storing and indexing the information collected in a search server that allows the retrieval of information history;
5. APERFEIÇOAMENTO INTRODUZIDO EM CONJUNTO DE APPLIANCES - Caracterizado pela visualização das informações em gráficos e tabelas intuitivos e criação de dashboards customizados.  5. IMPROVEMENT IN APPLIANCES - Characterized by the visualization of the information in graphs and intuitive tables and creation of customized dashboards.
PCT/BR2017/050353 2017-09-11 2017-11-22 System for monitoring data traffic and analysing the performance and usage of a communications network and of information technology systems using this network WO2019046915A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
BR202017019310-7U BR202017019310U2 (en) 2017-09-11 2017-09-11 IMPROVEMENT INTRODUCED IN SET OF APPLIANCES
BRBR2020170193107 2017-09-11

Publications (1)

Publication Number Publication Date
WO2019046915A1 true WO2019046915A1 (en) 2019-03-14

Family

ID=65633293

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/BR2017/050353 WO2019046915A1 (en) 2017-09-11 2017-11-22 System for monitoring data traffic and analysing the performance and usage of a communications network and of information technology systems using this network

Country Status (2)

Country Link
BR (1) BR202017019310U2 (en)
WO (1) WO2019046915A1 (en)

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20120182891A1 (en) * 2011-01-19 2012-07-19 Youngseok Lee Packet analysis system and method using hadoop based parallel computation
US8510830B2 (en) * 2011-06-03 2013-08-13 Fluke Corporation Method and apparatus for efficient netflow data analysis
US9178824B2 (en) * 2013-10-29 2015-11-03 Solana Networks Inc. Method and system for monitoring and analysis of network traffic flows
US9590877B2 (en) * 2014-10-09 2017-03-07 Splunk Inc. Service monitoring interface
US20170250997A1 (en) * 2016-02-29 2017-08-31 Palo Alto Networks, Inc. Alerting and tagging using a malware analysis platform for threat intelligence made actionable

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20120182891A1 (en) * 2011-01-19 2012-07-19 Youngseok Lee Packet analysis system and method using hadoop based parallel computation
US8510830B2 (en) * 2011-06-03 2013-08-13 Fluke Corporation Method and apparatus for efficient netflow data analysis
US9178824B2 (en) * 2013-10-29 2015-11-03 Solana Networks Inc. Method and system for monitoring and analysis of network traffic flows
US9590877B2 (en) * 2014-10-09 2017-03-07 Splunk Inc. Service monitoring interface
US20170250997A1 (en) * 2016-02-29 2017-08-31 Palo Alto Networks, Inc. Alerting and tagging using a malware analysis platform for threat intelligence made actionable

Also Published As

Publication number Publication date
BR202017019310U2 (en) 2019-03-26

Similar Documents

Publication Publication Date Title
US8839036B2 (en) System and method for root cause analysis
US20160063845A1 (en) Automatic configuration of alarm aggregations
US20110187488A1 (en) Alarm consolidation system and method
BR112017000970B1 (en) METHOD PERFORMED ON A COMPUTING DEVICE, COMPUTING DEVICE AND HARDWARE COMPUTER READABLE MEMORY DEVICE
Küçükkeçeci et al. Big data model simulation on a graph database for surveillance in wireless multimedia sensor networks
US20170124501A1 (en) System for automated capture and analysis of business information for security and client-facing infrastructure reliability
He et al. Large-scale IP network behavior anomaly detection and identification using substructure-based approach and multivariate time series mining
Dickinson et al. On graphs with unique node labels
Kim et al. Multivariate network traffic analysis using clustered patterns
WO2019046915A1 (en) System for monitoring data traffic and analysing the performance and usage of a communications network and of information technology systems using this network
Song et al. Design of anomaly detection and visualization tool for IoT blockchain
Wang et al. FNETVision: A WAMS big data knowledge discovery system
US20210011793A1 (en) Determining root-cause of failures based on machine-generated textual data
Schörgenhumer et al. Can We Predict Performance Events with Time Series Data from Monitoring Multiple Systems?
US11023350B2 (en) Technique for incremental and flexible detection and modeling of patterns in time series data
CN102708035A (en) Cluster system monitoring system based on pattern matching
Le Ngoc et al. Early phase warning solution about system security based on log analysis
CN106254130B (en) A kind of data processing method and device
Tang et al. A visualization method based on graph database in security logs analysis
Mukherjee et al. Using phasor data for visualization and data mining in smart-grid applications
US10228825B1 (en) Display and analysis of information related to monitored elements of a computer system
Li Fractal-Based Outlier Detection Algorithm over RFID Data Streams.
Aniello et al. Big data in critical infrastructures security monitoring: Challenges and opportunities
CN109474618A (en) Recognition methods, system, medium and the terminal of anomalous video equipment operation signaling
Thurner Statistical Mechanics ofComplex Networks

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17924150

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 17924150

Country of ref document: EP

Kind code of ref document: A1