Cyber Knowledge Graph for Resilient IT Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity systems lack the capability to continuously monitor network traffic, detect anomalies, and reason about emerging threats in enterprise networks, leading to inadequate defense mechanisms against malicious attacks, especially in complex IT infrastructures with numerous devices and users.
Innovation Solution
The development of a system that utilizes a cyber knowledge graph to unify network traffic and event logs data, employing neural networks for anomaly detection and risk estimation, and a Deep Neural Network architecture for explaining attack pathways and recommending configuration changes to enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional cybersecurity monitoring methods are used, then system simplicity is maintained, but the capability to detect and reason about emerging threats in complex IT infrastructures is insufficient
Solution Approach 1:
The system segments the complex cybersecurity monitoring task into distinct functional modules: a cyber knowledge graph construction module that models IT infrastructure entities and relationships, a neural network-based anomaly detection module that analyzes network traffic patterns, and a risk estimation module that evaluates potential threats. This segmentation allows each module to specialize in specific aspects of threat detection while working together to solve the overall problem.
Solution Approach 2:
The patent introduces a cyber knowledge graph as an intermediary data structure that bridges raw network traffic data and threat detection algorithms. The knowledge graph captures entities (devices, users, applications), their properties, and relationships within the IT infrastructure, serving as a mediator that transforms complex raw data into structured information that neural networks can effectively process for anomaly detection.
2Measurement precision
If comprehensive monitoring of vast network data is implemented, then threat detection accuracy improves, but the time and resources required for analysis increase significantly
Solution Approach 1:
The system performs preliminary action by pre-construing a cyber knowledge graph that models the normal structure and relationships of the IT infrastructure before actual threat detection begins. This pre-established knowledge base enables the neural network to quickly compare incoming network traffic against expected patterns, significantly reducing the time required for real-time anomaly detection while maintaining high accuracy.
Solution Approach 2:
The patent replaces traditional mechanical or rule-based analysis methods with neural network-based automated analysis. The neural network learns complex patterns and relationships from the cyber knowledge graph and network traffic data, automatically detecting anomalies without requiring manual analysis rules, thereby reducing both analysis time and human resource requirements while improving detection accuracy.
3Reliability
If proactive threat detection and reasoning capabilities are enhanced, then system resilience improves, but the complexity of the security system increases
Solution Approach 1:
The patent merges multiple security functions into a unified system: the cyber knowledge graph construction integrates entity modeling and relationship mapping, the neural network-based detection combines pattern recognition and anomaly identification, and the risk estimation module integrates threat assessment and response prioritization. This merging creates a cohesive security system that provides proactive threat detection and reasoning capabilities while managing complexity through functional integration rather than separate discrete components.
Data Source
AI summary
A method for securing an IT (information technology) system using a set of methods for knowledge extraction, event detection, risk estimation and explanation for ranking cyber-alerts which includes a method to explain the relationship (or an attack pathway) from an entity (user or host) and an event context to another entity (a high-value resource) and an event context (attack or service failure).


