Cybersecurity Alert Bucketing for Attack Graph Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of cybersecurity attacks leads to a surge in data collection, resulting in higher rates of false-positive cybersecurity alerts, which can cause analyst fatigue.

Innovation Solution

An apparatus and method that utilize a processor to receive cybersecurity alerts, identify associated buckets in a hash table, update sets of alerts, generate attack graphs, and determine maliciousness scores to automatically trigger remedial actions when scores exceed a predetermined range.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data collection is increased to monitor complex cybersecurity attacks, then detection capability is improved, but the number of false-positive alerts increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidfalse-positive alerts
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent segments cybersecurity alerts into different buckets based on their attributes (e.g., IP address, port number, protocol). This segmentation allows the system to process and analyze alerts in organized groups rather than as a monolithic stream, enabling more precise correlation and reducing false positives while maintaining comprehensive monitoring capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary correlation analysis layer that processes alerts through multiple stages: initial alert generation, bucket assignment, correlation analysis, and final attack graph construction. This intermediary processing layer filters and refines alerts before final detection, reducing false positives while preserving true threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the number of cybersecurity alerts is increased to monitor complex attacks, then monitoring coverage is improved, but analyst fatigue increases

Engineering Contradiction:
Improvemonitoring coverageVSAvoidanalyst fatigue
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements self-service through automated correlation analysis and attack graph generation. The system automatically processes alerts, identifies patterns, constructs attack graphs, and prioritizes threats without requiring manual analyst intervention for each alert. This automation reduces analyst fatigue while maintaining comprehensive monitoring coverage.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where the system continuously learns from alert patterns and adjusts its correlation analysis. The attack graph construction provides feedback about the severity and context of alerts, allowing the system to prioritize truly malicious activities while filtering benign noise, thereby reducing analyst workload.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If correlation analysis is performed on all cybersecurity alerts, then attack detection accuracy is improved, but processing time increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments alerts into buckets based on their attributes before performing correlation analysis. This segmentation reduces the correlation analysis from processing all alerts against each other to processing only relevant alerts within each bucket, significantly reducing processing time while maintaining detection accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial correlation analysis by focusing correlation efforts on alerts that share common attributes or are located in the same bucket, rather than performing exhaustive correlation on all alerts. This partial action approach maintains sufficient detection accuracy while dramatically reducing processing time.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12339961B2Apparatus and method for monitoring of data for attack detection and prevention
Publication Date: 2025.06.24 ARCTIC WOLF NETWORKS INC
  • US12339961B2 patent drawing
  • US12339961B2 patent drawing
  • US12339961B2 patent drawing

AI summary

A stream of cybersecurity alerts is received. Each cybersecurity alert from the stream of cybersecurity alerts is associated with a set of attributes. Each cybersecurity alert from the stream of cybersecurity alerts is associated, based on the set of attributes and as that cybersecurity alert is received, to a bucket from a set of buckets. Each bucket from the set of buckets is associated with (1) an attribute from the set of attributes different than remaining buckets from the set of buckets and (2) a set cybersecurity alerts from the stream of cybersecurity alerts having the attribute. For each bucket from the set of buckets, a set of correlations between cybersecurity alerts included in the set of cybersecurity alerts for that bucket are determined, based on the set of cybersecurity alerts for that bucket, to generate an attack graph associated with that bucket.