Cybersecurity Platform Graph Analysis for Attack Chain Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional cybersecurity approaches often result in a high number of false positives, leading to important alerts being removed and potentially missing significant security threats, as they over-optimize the model to filter out false positives.
Innovation Solution
A cybersecurity platform that collects and processes data from various sources to generate security events with contextual information, forming graph data structures to identify chains of related events rather than individual alerts, thereby reducing false positives and focusing on actual threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional approaches over-optimize the model to remove false positives, then the number of false positives is reduced, but important security alerts are removed and significant threats are missed
Solution Approach 1:
The patent combines multiple individual security alerts into graph structures that represent chains of related events. By merging isolated alerts into contextual chains, the system preserves important security information that would otherwise be filtered out as false positives, while maintaining reliability through the contextual relationships shown in the graphs.
Solution Approach 2:
The patent introduces graph structures as an intermediary layer between raw security alerts and final security decisions. These graphs serve as mediators that contextualize individual alerts, allowing the system to distinguish between true threats and false positives without losing important security information.
2Productivity
If individual alerts are filtered to reduce false positives, then alert volume is reduced, but complex intrusions are missed
Solution Approach 1:
The patent merges individual alerts into graph structures that reveal patterns of complex intrusions. By combining related alerts into contextual chains, the system maintains high detection reliability for sophisticated attacks while improving productivity through more efficient analysis of consolidated graph representations.
Solution Approach 2:
The patent transitions from analyzing individual alerts in isolation to analyzing chains of events in a graphical dimension. This dimensional shift from point-to-pattern analysis enables detection of complex intrusions while improving analytical efficiency through visual pattern recognition.
Data Source
AI summary
A cybersecurity platform is described that processes collected data using a data model to identify and link anomalies and in order to identify generate security events and intrusions. The platform generates graph data structures using the security anomalies extended using additional data. The graph data structures represent links between nodes, the links being events, the nodes being machines and user accounts. The platform processes the graph data structures by combining similar nodes or grouping security events with common features to behaviour indicative of a single or multiple security events to identify chains of events which together represent an attack.


