Cyber Knowledge Graph for Resilient IT Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems lack the capability to continuously monitor network traffic, detect anomalies, and reason about emerging threats in enterprise networks, leading to inadequate defense mechanisms against malicious attacks, especially in complex IT infrastructures with numerous devices and users.

Innovation Solution

The development of a system that utilizes a cyber knowledge graph to unify network traffic and event logs data, employing neural networks for anomaly detection and risk estimation, and a Deep Neural Network architecture for explaining attack pathways and recommending configuration changes to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cybersecurity monitoring methods are used, then system simplicity is maintained, but the capability to detect and reason about emerging threats in complex IT infrastructures is insufficient

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex cybersecurity monitoring task into distinct functional modules: a cyber knowledge graph construction module that models IT infrastructure entities and relationships, a neural network-based anomaly detection module that analyzes network traffic patterns, and a risk estimation module that evaluates potential threats. This segmentation allows each module to specialize in specific aspects of threat detection while working together to solve the overall problem.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a cyber knowledge graph as an intermediary data structure that bridges raw network traffic data and threat detection algorithms. The knowledge graph captures entities (devices, users, applications), their properties, and relationships within the IT infrastructure, serving as a mediator that transforms complex raw data into structured information that neural networks can effectively process for anomaly detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive monitoring of vast network data is implemented, then threat detection accuracy improves, but the time and resources required for analysis increase significantly

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-construing a cyber knowledge graph that models the normal structure and relationships of the IT infrastructure before actual threat detection begins. This pre-established knowledge base enables the neural network to quickly compare incoming network traffic against expected patterns, significantly reducing the time required for real-time anomaly detection while maintaining high accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional mechanical or rule-based analysis methods with neural network-based automated analysis. The neural network learns complex patterns and relationships from the cyber knowledge graph and network traffic data, automatically detecting anomalies without requiring manual analysis rules, thereby reducing both analysis time and human resource requirements while improving detection accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If proactive threat detection and reasoning capabilities are enhanced, then system resilience improves, but the complexity of the security system increases

Engineering Contradiction:
Improvesystem resilienceVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security functions into a unified system: the cyber knowledge graph construction integrates entity modeling and relationship mapping, the neural network-based detection combines pattern recognition and anomaly identification, and the risk estimation module integrates threat assessment and response prioritization. This merging creates a cohesive security system that provides proactive threat detection and reasoning capabilities while managing complexity through functional integration rather than separate discrete components.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10855706B2System and methods for automated detection, reasoning and recommendations for resilient cyber systems
Publication Date: 2020.12.01 BATTELLE MEMORIAL INST
  • US10855706B2 patent drawing
  • US10855706B2 patent drawing
  • US10855706B2 patent drawing

AI summary

A method for securing an IT (information technology) system using a set of methods for knowledge extraction, event detection, risk estimation and explanation for ranking cyber-alerts which includes a method to explain the relationship (or an attack pathway) from an entity (user or host) and an event context to another entity (a high-value resource) and an event context (attack or service failure).