Cross-Domain IoC Identification Through Bipartite Network Graphs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing intrusion detection systems struggle to efficiently identify malicious network entities and command-and-control infrastructure due to the transient nature of cyber threats, requiring manual review and limited scalability, especially when direct communication between entities is not observed.

Innovation Solution

A bipartite graph-based approach is used to analyze network interactions, calculating a maliciousness score for candidate entities based on their connections to known malicious entities, with a scalable IoC retrieval algorithm that provides accurate identification and explanation for the decision.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual review is used to verify candidate entities before adding to malicious list, then reliability of malicious entity identification is improved, but productivity is worsened due to limited processing capacity

Engineering Contradiction:
Improvereliability of malicious entity identificationVSAvoidprocessing throughput of candidate entities
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an intermediary scoring mechanism that automatically evaluates candidate entities using graph-based analysis of network interactions. This intermediary system pre-ranks candidates by their maliciousness score, allowing human reviewers to focus only on high-probability cases rather than manually reviewing all candidates, thus maintaining reliability while dramatically improving productivity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the purely manual mechanical review process with an automated computational system that uses bipartite graphs, entity embeddings, and scoring algorithms. This substitution handles the initial filtering and ranking automatically, preserving human judgment for final verification while eliminating the bottleneck of manual processing for all candidates

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If direct communication between entities is required for identification, then measurement precision is improved, but adaptability is worsened as indirect malicious infrastructure cannot be detected

Engineering Contradiction:
Improveprecision of entity identificationVSAvoidability to detect indirect malicious infrastructure
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent transitions from analyzing direct entity-to-entity communication to analyzing entities within the context of their interaction networks. By constructing bipartite graphs that capture multi-hop relationships and using graph embeddings, the system detects malicious entities through their positional and relational characteristics in the network graph, enabling identification of indirect infrastructure without requiring direct communication evidence

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If comprehensive analysis of network interactions is performed, then adaptability to detect various threat types is improved, but device complexity is worsened

Engineering Contradiction:
Improveability to detect different cyber threatsVSAvoidcomplexity of analysis system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal graph-based framework that can analyze multiple types of network entities (domains, IPs, binaries, users) and their interactions through a single unified system. The bipartite graph structure and embedding approach provide a multi-functional platform that adapts to different threat detection scenarios without requiring separate specialized systems, managing complexity through conceptual unification

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If rapid identification of malicious entities is achieved through automated methods, then productivity is improved, but measurement precision is worsened due to lack of human validation

Engineering Contradiction:
Improvespeed of malicious entity identificationVSAvoidaccuracy of identification
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent performs preliminary automated analysis using graph embeddings and maliciousness scoring to pre-process and rank candidate entities before human review. This preliminary action filters out low-probability candidates and presents only high-confidence cases to human validators, enabling rapid automated processing while maintaining precision through targeted human validation of the most suspicious cases

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12373550B2Cross-domain indicator of compromise (IoC) identification
Publication Date: 2025.07.29 CISCO TECHNOLOGY INC
  • US12373550B2 patent drawing
  • US12373550B2 patent drawing
  • US12373550B2 patent drawing

AI summary

Techniques for identifying malicious actors across datasets of different origin. The techniques may include receiving input data indicative of network interactions between entities and modalities. Based at least in part on the input data, a maliciousness score associated with a first entity may be determined. In some instances, a value of the maliciousness score may be partially based on a number of the modalities that are interacting with the first entity and also interacting with one or more malicious entities. The techniques may further include determining whether the value of the maliciousness score exceeds a threshold value and, based at least in part on the value of the maliciousness score exceeding the threshold value, a request may be made to identify the first entity as a new malicious entity.