Abstract Entity Models for Accurate Computer Network Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern computer networks are highly complex and dynamic, making it challenging for organizations to maintain accurate and up-to-date catalogues of interacting entities, which is crucial for effective IT management and cybersecurity. Existing tools often require manual interaction, are error-prone, and fail to provide a cohesive view of the network environment, leading to inaccurate data and increased cyber risks.
Innovation Solution
An extensible system that collects and correlates information from multiple sources with different data schemas, creating a cohesive abstract model of entities and their relationships, allowing users to interact with a unified view through an abstract query interface, thereby avoiding the need to understand the complex concrete models of individual sources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional manual approaches are used to maintain entity catalogues, then human users can play a role in the process, but the catalogue accuracy deteriorates and manual effort increases
Solution Approach 1:
The system enables self-service through automated entity discovery and tracking. The ingestion subsystem automatically discovers entities from multiple information sources, extracts their attributes, and maintains the entity relationship graph without requiring manual intervention. This resolves the contradiction by eliminating manual effort while maintaining high catalogue accuracy through automated processes.
Solution Approach 2:
The patent replaces manual mechanical processes with automated computational systems. The ingestion subsystem uses automated information extraction, entity resolution, and graph processing to substitute human users in maintaining entity catalogues. This substitution eliminates manual effort while improving reliability through consistent automated operation.
2Loss of information
If multiple information sources with different data schemas are integrated, then comprehensive entity information is obtained, but system complexity increases
Solution Approach 1:
The patent introduces an intermediary abstraction layer between multiple information sources and the entity relationship graph. The ingestion subsystem acts as a mediator that standardizes data from diverse sources with different schemas into a unified entity model. This intermediary approach maintains information completeness from all sources while hiding complexity from users through a standardized interface.
Solution Approach 2:
The entity relationship graph serves as a universal data structure that can represent entities and relationships from multiple information sources with different schemas. The system provides multi-functionality by handling diverse data sources through a single unified model, allowing comprehensive information integration without proportionally increasing system complexity.
3Measurement precision
If detailed attribute information is collected for all entities, then cyber risk assessment accuracy is enhanced, but data processing complexity increases
Solution Approach 1:
The patent segments entity information into structured attributes and relationships within the entity relationship graph. Each entity is divided into discrete properties that can be independently processed and analyzed. This segmentation enables precise risk assessment by allowing selective processing of relevant attributes while managing data processing complexity through modular organization.
Solution Approach 2:
The system applies local quality by collecting detailed attribute information only where necessary for specific risk assessment contexts. The ingestion subsystem extracts and stores detailed entity attributes in the graph structure, allowing precise risk assessment for specific entities or relationships while avoiding unnecessary processing complexity for the entire dataset.
Data Source
AI summary
An entity tracking system and method for a computer network employs proactive data collection and enrichment driven by configurable rules and workflows responsive to the discovery of new entities, changes to existing entities, and specifics about the entities' attributes. The data collection is used in conjunction with graph technologies to map interactions and relationships between various entities interacting in the computer environment and deduce interactions and relationships between the entities. The method and system provides for abstract entity types and collation nodes.


