Cross-Domain IoC Identification Through Bipartite Network Graphs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing intrusion detection systems struggle to efficiently identify malicious network entities and command-and-control infrastructure due to the transient nature of cyber threats, requiring manual review and limited scalability, especially when direct communication between entities is not observed.
Innovation Solution
A bipartite graph-based approach is used to analyze network interactions, calculating a maliciousness score for candidate entities based on their connections to known malicious entities, with a scalable IoC retrieval algorithm that provides accurate identification and explanation for the decision.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual review is used to verify candidate entities before adding to malicious list, then reliability of malicious entity identification is improved, but productivity is worsened due to limited processing capacity
Solution Approach 1:
The patent introduces an intermediary scoring mechanism that automatically evaluates candidate entities using graph-based analysis of network interactions. This intermediary system pre-ranks candidates by their maliciousness score, allowing human reviewers to focus only on high-probability cases rather than manually reviewing all candidates, thus maintaining reliability while dramatically improving productivity
Solution Approach 2:
The patent replaces the purely manual mechanical review process with an automated computational system that uses bipartite graphs, entity embeddings, and scoring algorithms. This substitution handles the initial filtering and ranking automatically, preserving human judgment for final verification while eliminating the bottleneck of manual processing for all candidates
2Measurement precision
If direct communication between entities is required for identification, then measurement precision is improved, but adaptability is worsened as indirect malicious infrastructure cannot be detected
Solution Approach 1:
The patent transitions from analyzing direct entity-to-entity communication to analyzing entities within the context of their interaction networks. By constructing bipartite graphs that capture multi-hop relationships and using graph embeddings, the system detects malicious entities through their positional and relational characteristics in the network graph, enabling identification of indirect infrastructure without requiring direct communication evidence
3Adaptability or versatility
If comprehensive analysis of network interactions is performed, then adaptability to detect various threat types is improved, but device complexity is worsened
Solution Approach 1:
The patent implements a universal graph-based framework that can analyze multiple types of network entities (domains, IPs, binaries, users) and their interactions through a single unified system. The bipartite graph structure and embedding approach provide a multi-functional platform that adapts to different threat detection scenarios without requiring separate specialized systems, managing complexity through conceptual unification
4Productivity
If rapid identification of malicious entities is achieved through automated methods, then productivity is improved, but measurement precision is worsened due to lack of human validation
Solution Approach 1:
The patent performs preliminary automated analysis using graph embeddings and maliciousness scoring to pre-process and rank candidate entities before human review. This preliminary action filters out low-probability candidates and presents only high-confidence cases to human validators, enabling rapid automated processing while maintaining precision through targeted human validation of the most suspicious cases
Data Source
AI summary
Techniques for identifying malicious actors across datasets of different origin. The techniques may include receiving input data indicative of network interactions between entities and modalities. Based at least in part on the input data, a maliciousness score associated with a first entity may be determined. In some instances, a value of the maliciousness score may be partially based on a number of the modalities that are interacting with the first entity and also interacting with one or more malicious entities. The techniques may further include determining whether the value of the maliciousness score exceeds a threshold value and, based at least in part on the value of the maliciousness score exceeding the threshold value, a request may be made to identify the first entity as a new malicious entity.


