Causality Graph Log Analysis for Incident Cause Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing incident event cause identification systems face challenges in accurately determining whether an incident in control systems is due to a cyberattack or mechanical failure, as they often lack sufficient alert types for chain relationship creation and underutilize unmonitored device logs, relying heavily on analyst knowledge.
Innovation Solution
An incident event cause identification system that includes a device log information holding unit, a causality graph holding unit, an incident detection processing unit, a necessary log information determination processing unit, a necessary log information collection processing unit, a cause analysis processing unit, and an output unit, which extracts and analyzes necessary log information using a causality graph to efficiently identify incident causes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If all device log information is collected and analyzed, then the accuracy of incident cause identification is improved, but the information scrutiny time and processing complexity increase
Solution Approach 1:
The patent segments the large volume of device log information into structured categories using a causality graph framework. The causality graph divides incident causes into hierarchical levels (direct causes, indirect causes, root causes) and organizes log information according to these categories, enabling selective analysis of relevant logs rather than examining all logs uniformly. This segmentation reduces scrutiny time while maintaining identification accuracy.
Solution Approach 2:
The patent performs preliminary organization of device log information by constructing a causality graph that pre-establishes relationships between incident events and their potential causes. The causality graph is built in advance with defined causal relationships, so when an incident occurs, the system can quickly retrieve and analyze only the pre-organized relevant log information rather than searching through all logs from scratch, significantly reducing analysis time.
2Reliability
If comprehensive log information is stored, then the completeness of cause analysis is improved, but the information storage capacity requirements increase
Solution Approach 1:
The patent extracts only the essential causal relationships from comprehensive log information and stores them in a compact causality graph structure. Instead of storing and processing all raw log data, the system extracts key causal links and stores them in the graph, which requires minimal storage space. The full log information can be retained in compressed or summarized form, while the causality graph provides the structured framework needed for complete cause analysis.
3Productivity
If chain relationship of alerts is defined in advance, then the speed of incident classification is improved, but the adaptability to new incident types decreases
Solution Approach 1:
The patent implements a dynamic causality graph that can be updated and expanded as new incident types are discovered. The causality graph is not a static, fixed structure but can be dynamically modified to incorporate new causal relationships, new incident patterns, and emerging threat types. This dynamic nature allows the system to maintain fast classification speed for known incidents while simultaneously adapting to new incident types by updating the graph structure.
Solution Approach 2:
The system incorporates feedback mechanisms where analysis results from actual incidents are used to refine and update the causality graph. When new incident types or patterns are identified through analysis, this feedback loops back to update the causality graph, adding new causal relationships or modifying existing ones. This feedback-driven evolution enables the system to continuously improve its adaptability to new incident types while maintaining the efficiency benefits of pre-defined chain relationships for known patterns.
Data Source
AI summary
An incident event cause identification system includes a device log information holding unit that holds log information of a target device, a causality graph holding unit that holds a causality graph in which a relationship between an incident event and a cause thereof is associated, and an incident detection processing unit that detects an incident in the target device. A necessary log information determination processing unit extracts a causality graph of an associated type for the detected incident event and determines device log information necessary for cause identification on the basis of the extracted causality graph. A necessary log information collection processing unit collects the device log information determined by the necessary log information determination processing unit, and a cause analysis processing unit identifies a cause of the incident event by using the device log information collected by the necessary log information collection processing unit and the causality graph.


