IP Library Patent Application 15173466
Patent Application
App. No. 15/173,466

PARALLEL COORDINATE CHARTS FOR FLOW EXPLORATION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/173,466
Abstract

Presenting data flows in a parallel coordinate chart. The parallel coordinate chart allows a user to search for data flows. Exploration occurs by providing visualization of a searched data flow(s) to ascertain the typical from the atypical flow. Each data flow represented in a parallel coordinate chart is measured against various attributes represented among parallel lines. A single chart could be used to visualize thousands of flows at once. Overlaying data flows in on top of each other in the parallel coordinate chart can reveal a concentration of flows. The concentration of flows allows a user to visualize, among other things, the relationship between the flows and observe typical and atypical flows. Additionally the user can filter specific dimensions (to observe joint distributions between a pair of dimensions—combined probabilities of what is occurring between two dimensions) or a specific window of time.

Claims (49)

1 . A method for visualizing a plurality of electronic communication flows comprising:

displaying a coordinate parallel chart representing a plurality of attributes as evenly spaced parallel lines; and

representing a plurality of flows in the chart, wherein each flow intersects each line of the evenly spaced parallel lines at a point representing a respective value associated with the flow for that attribute.

2 . The method of claim 1 , wherein the each attribute of the plurality of represented attributes is represented in units specific to the respective attribute.

3 . The method of claim 1 , comprising:

representing the first flow and second flow as a single line with an increased line weight when a first flow of the plurality of flows and a second flow of the plurality of flows both intersect the first attribute and a second attribute at the same respective values.

4 . The method of claim 1 , comprising:

receiving an input selecting one of the evenly spaced parallel lines, and repositioning the line among the evenly spaced parallel lines, thereby repositioning the representation of the respective attribute represented by the selected one of the evenly spaced parallel lines.

5 . The method of claim 1 , comprising:

searching data analyzed by an analytics engine configured to analyze flow data describing flows within, transmitted by, or received by one or more data centers for flows matching search criteria; and

returning the plurality of flows.

6 . The method of claim 1 , comprising:

receiving a selection of the plurality of attribute to be represented in the parallel coordinate chart as evenly spaced parallel lines.

7 . The method of claim 1 , comprising:

receiving a selection of at least one flow in the chart;

presenting detailed data specific to the flow from an analytics engine.

8 . The method of claim 1 , comprising:

graphically distinguishing flows labeled as potentially malicious from flows not labeled as potentially malicious.

9 . A system for representing a plurality of flows together in a chart in order to compare and identify anomalous characteristics of a subset of the plurality of flows, the system comprising:

a processor; and

a non-transitory computer readable medium storing processor executable instructions, the instructions effective to cause the processor to:

search data analyzed by an analytics engine configured to analyze flow data describing data flows to identify data flows matching search criteria;

display a coordinate parallel chart representing a plurality of attributes as evenly spaced parallel lines; and

represent a plurality of flows that match the search criteria in the chart, wherein each flow intersects each line of the evenly spaced parallel lines at a point representing a respective value associated with the flow for that attribute.

10 . The system of claim 9 , wherein the instructions effective to cause the processor to:

filter the plurality of flows based on a filter criteria; and

update the representation of the plurality of flows to represent a subset of the plurality of flows.

11 . The system of claim 9 , wherein the instructions effective to cause the processor to receive an input selecting one of the evenly spaced parallel lines, and repositioning the line among the evenly spaced parallel lines, thereby repositioning the representation of the respective attribute represented by the selected one of the evenly spaced parallel lines.

12 . The system of claim 9 , wherein the instructions effective to cause the processor to receive a selection of the plurality of attribute to be represented in the parallel coordinate chart as evenly spaced parallel lines.

13 . The system of claim 9 , wherein the instructions effective to cause the processor to:

receive a selection of at least one flow in the chart; and

present detailed data specific to the flow from an analytics engine.

14 . The system of claim 9 , wherein the instructions effective to cause the processor to:

graphically distinguishing flows labeled as potentially malicious from flows not labeled as potentially malicious.

15 . A non-transitory computer readable medium comprising instructions stored thereon, the instructions effective to cause the processor to:

receive a selection of the plurality of attributes to represent in a parallel coordinate chart;

display a coordinate parallel chart representing the selected plurality of attributes as evenly spaced parallel lines; and

represent a plurality of flows in the chart, wherein each flow intersects each line of the evenly spaced parallel lines at a point representing a respective value associated with the flow for that attribute.

16 . The non-transitory computer readable medium of claim 15 , wherein the instructions effective to cause the processor to:

filter the plurality of flows based on a filter criteria; and

update the representation of the plurality of flows to represent a subset of the plurality of flows.

17 . The non-transitory computer readable medium of claim 15 , wherein the instructions effective to cause the processor to receive an input selecting one of the evenly spaced parallel lines, and repositioning the line among the evenly spaced parallel lines, thereby repositioning the representation of the respective attribute represented by the selected one of the evenly spaced parallel lines.

18 . The non-transitory computer readable medium of claim 15 , wherein the instructions effective to cause the processor to

search data analyzed by an analytics engine configured to analyze flow data describing data flows to identify data flows matching search criteria.

19 . The non-transitory computer readable medium of claim 15 , wherein the instructions effective to cause the processor to:

receive a selection of at least one flow in the chart; and

present detailed data specific to the flow from an analytics engine.

20 . The non-transitory computer readable medium of claim 15 , wherein the instructions effective to cause the processor to:

graphically distinguishing flows labeled as potentially malicious from flows not labeled as potentially malicious.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2016
From: PANG, JACKSON NGOC KI; WATTS, MICHAEL STANDISH; PARANDEHGHEIBI, ALI
To: CISCO TECHNOLOGY, INC.
Reel/Frame 039824/0854 →