Attack Graph Variation for Multi-Stage Network Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting multi-stage cyber-attacks struggle to efficiently link and examine a plurality of events within a network, particularly when alternative sequences of attack events occur, leading to delayed detection and increased difficulty in creating comprehensive attack graphs manually.

Innovation Solution

A computer-implemented method generates a set of additional attack graphs based on predetermined variation properties, including prerequisites and optional events, to cover various sequences of cyber-attack events, using a processor to determine and store these graphs for real-time monitoring and alert generation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual creation of comprehensive attack graphs is performed to cover all possible attack sequences, then detection accuracy improves, but device complexity and time consumption increase significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoidattack graph complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the attack detection process by generating multiple specialized attack graphs, where each graph focuses on a specific attack sequence or pattern. Instead of creating one comprehensive graph that becomes unmanageably complex, the system divides the detection task into multiple smaller, more manageable graphs that can be processed independently and efficiently

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary analysis to identify potential attack sequences and patterns before generating the attack graphs. By pre-processing event data and identifying likely attack paths in advance, the system reduces the complexity of graph generation while maintaining high detection accuracy for the most relevant attack scenarios

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If multiple attack graphs are generated to cover alternative attack sequences, then detection coverage improves, but processing time and computational resources increase

Engineering Contradiction:
Improvedetection coverageVSAvoidprocessing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent creates attack graphs that are designed to be universally applicable to multiple attack scenarios. Each graph is constructed to detect a family of related attack patterns rather than single specific sequences, allowing the system to maintain high detection coverage across diverse attack types while reducing the total number of graphs that need to be processed

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system varies key parameters in the attack graphs such as event sequences, node connections, and detection thresholds to create multiple graphs that cover different attack patterns. By systematically changing these parameters rather than creating entirely separate graphs for each scenario, the system achieves broad coverage while optimizing processing efficiency

Inventive Principle:
Principle #35Parameter changes

3Speed

If real-time monitoring of multiple event sequences is performed, then attack detection speed improves, but system complexity and false alert rates increase

Engineering Contradiction:
Improvedetection speedVSAvoidmonitoring system complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent extracts and focuses monitoring resources on the most critical attack sequences and high-risk event patterns. Instead of monitoring all possible event sequences equally, the system identifies and extracts the most dangerous attack paths for specialized monitoring, reducing overall system complexity while maintaining fast detection speed for the most important threats

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements feedback mechanisms where detection results from one attack graph inform the monitoring of other graphs. When certain events are detected in one graph, the system can adjust monitoring intensity or focus in related graphs, reducing false alerts and simplifying the overall monitoring complexity while maintaining rapid detection capability

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4490881B1Network monitoring with multiple attack graphs
Publication Date: 2026.02.18 BRITISH TELECOM PLC
  • EP4490881B1 patent drawingFigure 1
  • EP4490881B1 patent drawingFigure 2~3
  • EP4490881B1 patent drawingFigure 4

AI summary

A computer-implemented method for monitoring a computer network is provided, the method comprising: storing a first attack graph, the attack graph comprising a plurality of nodes each representing an event that may occur within the computer network; storing one or more predetermined variation properties of one or more of the events represented by the nodes, the variation properties being indicative of possible changes to the nodes within the first attack graph; determining a plurality of possible alternative sequences of the nodes in the first attack graph based on the variation properties; generating a plurality of additional attack graphs, each of the additional attack graphs comprising a plurality of the nodes of the first attack graph arranged in one of the possible sequences; and monitoring events within the network to detect a set of events occurring in a sequence that corresponds to one of the additional attack graphs to identify a potential security attack. A computer system including at least one processor and memory storing computer program code configured to perform the said method, and a computer program or computer readable medium comprising instructions that when executed by a computer system cause the computer system to perform the said method are also provided.