Cybersecurity Knowledge Graph Visualization via Threat-Based Entity Grouping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Security analysts face difficulties in interpreting and utilizing traditional knowledge graphs for cybersecurity incident visualization due to their complexity and lack of structured flow, making it challenging to identify breaches, affected assets, and threat types.
Innovation Solution
A method that groups related entities in a knowledge graph by type and threat impact, arranging them in visualization data to provide a clear, structured representation, allowing analysts to easily follow the path from the incident source to the threat, and enabling selective expansion of clusters for detailed insights.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If traditional knowledge graphs are used to visualize cybersecurity incidents, then comprehensive entity and relationship data can be displayed, but the visualization becomes too complex and difficult to interpret
Solution Approach 1:
The patent applies segmentation by dividing the complex knowledge graph into multiple organized panels including entity summary panel, entity detail panel, relationship panel, and path visualization panel. Each panel displays specific aspects of the security incident data separately, transforming the overwhelming single-graph view into manageable segmented sections that reduce visual complexity while maintaining comprehensive data coverage.
Solution Approach 2:
The patent transitions from a two-dimensional graph layout to a multi-dimensional panel-based interface with hierarchical organization. The entity summary panel provides high-level overview, while the entity detail panel and relationship panel provide deeper dimensions of analysis. This dimensional transformation allows analysts to navigate complex data through multiple viewing layers rather than attempting to comprehend all relationships in a single flat visualization.
2Loss of information
If all entities and relationships are displayed in a knowledge graph, then complete incident information is available, but there is no structured flow making it difficult to follow the incident path
Solution Approach 1:
The system performs preliminary action by automatically computing and displaying the incident path from source to impact through the path visualization panel before the analyst needs to trace it manually. The entity summary panel also pre-organizes entities by type and threat impact, performing the categorization work in advance so analysts don't need to mentally sort through all relationships to understand the incident flow.
Solution Approach 2:
The patent introduces intermediary elements including the entity summary panel that acts as a mediator between the raw knowledge graph data and the analyst's understanding. The path visualization panel serves as an intermediary that highlights and connects the incident flow path separately from other relationships, making the structured flow visible without hiding other important data. These intermediaries translate complex graph data into organized, easy-to-follow presentations.
3Quantity of substance
If knowledge graphs include hundreds of nodes and edges for moderately complicated incidents, then all security entities are captured, but the graphs become too complicated to interpret
Solution Approach 1:
The patent segments the hundreds of nodes and edges into organized groups displayed across multiple panels. The entity summary panel groups entities by type (e.g., internal hosts, external hosts, malware, threat actors) and by threat impact, creating categorical segments that reduce the perceived number of individual elements. The relationship panel segments connections by type, and the path visualization panel segments the critical incident flow from other background relationships, making the data interpretable despite capturing comprehensive entity information.
4Loss of information
If traditional knowledge graphs display all relationships between entities, then complete incident context is provided, but security analysts cannot quickly assess breaches or identify affected assets
Solution Approach 1:
The system performs preliminary action by pre-computing and displaying the incident path from source to impact in the path visualization panel, and by pre-organizing entities by threat impact in the entity summary panel. This allows analysts to immediately see which assets are affected and what the breach path is without having to manually trace through all relationships. The entity detail panel also pre-loads comprehensive entity information, so when analysts need detailed context about specific assets, it's already prepared and displayed, eliminating the time needed to gather this information.
Data Source
AI summary
Information for a knowledge graph is accessed. The knowledge graph has nodes and edges of a network and has information about security incident(s) in the network. Related entities from the knowledge graph are grouped together, where the related entities that are grouped together are determined not only by types of the entities, but also by threat(s) impacting the entities. The threat(s) correspond to the security incident(s). The grouped related entities are arranged in visualization data in order that the visualization data are configured to provide a visualization of the knowledge graph with the grouped related entities. The visualization data are output. Methods, apparatus, and computer program products are disclosed.


