Active Directory Activity Signatures for Event Granularity Clarity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Active Directory (AD) security analysis methods rely heavily on 'trial and error' due to limited visibility and clarity in AD event reporting, leading to costly and erroneous investigations, incorrect incident attribution, and over-representation of security-sensitive activities.

Innovation Solution

The use of activity signatures, represented as characteristic event segments or 'grouplets,' which aggregate information from individual AD events to identify and characterize high-level network activities, overcoming visibility and ambiguity issues by revealing roles of event-collection machines and involved actors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If AD events are designed to describe fine-grained activities, then detailed information about individual events is provided, but it becomes impossible to comprehend the big picture of activities and understand the roles of machines

Engineering Contradiction:
Improveevent detail granularityVSAvoidbig picture understanding
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent combines multiple fine-grained AD events into aggregated activity representations that preserve detailed event information while simultaneously providing high-level activity context. This merging approach allows analysts to see both individual event details and the overall activity picture without losing information at either level.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a new dimension of analysis by creating activity-level abstractions that operate above the individual event level. This dimensional shift enables comprehension of the big picture while maintaining access to fine-grained details through the activity structure, effectively adding a hierarchical layer to the analysis.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If AD events report inconclusive information about actors, then event parameters are ambiguous, but this causes incorrect incident attribution and overrepresentation of security-sensitive activities

Engineering Contradiction:
Improveevent reporting flexibilityVSAvoidincident attribution accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements feedback mechanisms where activity-level information is used to disambiguate and correct individual event interpretations. By continuously refining actor identification based on activity context and cross-referencing multiple events, the system improves incident attribution accuracy while maintaining the flexibility of AD event reporting.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces activity representations as intermediary entities between raw AD events and security analysis conclusions. These intermediaries resolve ambiguities in event parameters by synthesizing information from multiple events and providing confident actor attribution, thereby improving reliability without sacrificing reporting flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Quantity of substance

If state-of-the-art analysis relies on information from various sources and tracks per-event phenomena, then comprehensive event coverage is achieved, but it becomes very difficult to effectively use AD log data to characterize and observe activities

Engineering Contradiction:
Improveevent data coverageVSAvoidactivity characterization difficulty
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The patent merges information from multiple AD event sources into unified activity characterizations. By combining per-event data with activity-level context, the system maintains comprehensive event coverage while significantly easing the difficulty of characterizing and observing security-relevant activities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates activity representations that serve multiple functions simultaneously: they aggregate individual events, characterize security activities, enable observation of high-level patterns, and maintain links to underlying event data. This multi-functionality resolves the contradiction between comprehensive coverage and ease of operation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12298937B2Network activity identification and characterization based on characteristic active directory (AD) event segments
Publication Date: 2025.05.13 CISCO TECHNOLOGY INC
  • US12298937B2 patent drawing
  • US12298937B2 patent drawing
  • US12298937B2 patent drawing

AI summary

A system and method of obtaining and utilizing an activity signature that is representative of a specific category of network activities based on directory service (DS) log data. The activity signature may be determining by a learning process, including segmenting and pruning a training dataset into a plurality of event segments and matching them with activities based on DS log data of known activities. Once obtained, the activity signature can advantageously be utilized to analyze any DS log data and activities in actual deployment. Using activity signatures to analyze DS event log can reveal roles of event-collection machines, aggregate information dispersed across their component events to reveal actors involved in particular AD activities, augment visibility of DS by enabling various vantage points to better infer activities at other domain machines, and reveal macro activities so that logged information becomes easily interpretable to human analysts.