Cybersecurity Knowledge Graph Visualization via Threat-Based Entity Grouping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security analysts face difficulties in interpreting and utilizing traditional knowledge graphs for cybersecurity incident visualization due to their complexity and lack of structured flow, making it challenging to identify breaches, affected assets, and threat types.

Innovation Solution

A method that groups related entities in a knowledge graph by type and threat impact, arranging them in visualization data to provide a clear, structured representation, allowing analysts to easily follow the path from the incident source to the threat, and enabling selective expansion of clusters for detailed insights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If traditional knowledge graphs are used to visualize cybersecurity incidents, then comprehensive entity and relationship data can be displayed, but the visualization becomes too complex and difficult to interpret

Engineering Contradiction:
Improveamount of security incident data displayedVSAvoidcomplexity of knowledge graph visualization
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the complex knowledge graph into multiple organized panels including entity summary panel, entity detail panel, relationship panel, and path visualization panel. Each panel displays specific aspects of the security incident data separately, transforming the overwhelming single-graph view into manageable segmented sections that reduce visual complexity while maintaining comprehensive data coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a two-dimensional graph layout to a multi-dimensional panel-based interface with hierarchical organization. The entity summary panel provides high-level overview, while the entity detail panel and relationship panel provide deeper dimensions of analysis. This dimensional transformation allows analysts to navigate complex data through multiple viewing layers rather than attempting to comprehend all relationships in a single flat visualization.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Loss of information

If all entities and relationships are displayed in a knowledge graph, then complete incident information is available, but there is no structured flow making it difficult to follow the incident path

Engineering Contradiction:
Improvecompleteness of incident informationVSAvoidease of following incident path
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The system performs preliminary action by automatically computing and displaying the incident path from source to impact through the path visualization panel before the analyst needs to trace it manually. The entity summary panel also pre-organizes entities by type and threat impact, performing the categorization work in advance so analysts don't need to mentally sort through all relationships to understand the incident flow.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces intermediary elements including the entity summary panel that acts as a mediator between the raw knowledge graph data and the analyst's understanding. The path visualization panel serves as an intermediary that highlights and connects the incident flow path separately from other relationships, making the structured flow visible without hiding other important data. These intermediaries translate complex graph data into organized, easy-to-follow presentations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Quantity of substance

If knowledge graphs include hundreds of nodes and edges for moderately complicated incidents, then all security entities are captured, but the graphs become too complicated to interpret

Engineering Contradiction:
Improvenumber of security entities capturedVSAvoiddifficulty of interpreting security incident data
Core Design Contradiction:
Quantity of substanceVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the hundreds of nodes and edges into organized groups displayed across multiple panels. The entity summary panel groups entities by type (e.g., internal hosts, external hosts, malware, threat actors) and by threat impact, creating categorical segments that reduce the perceived number of individual elements. The relationship panel segments connections by type, and the path visualization panel segments the critical incident flow from other background relationships, making the data interpretable despite capturing comprehensive entity information.

Inventive Principle:
Principle #1Segmentation

4Loss of information

If traditional knowledge graphs display all relationships between entities, then complete incident context is provided, but security analysts cannot quickly assess breaches or identify affected assets

Engineering Contradiction:
Improvecompleteness of incident contextVSAvoidtime to assess breach and identify affected assets
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-computing and displaying the incident path from source to impact in the path visualization panel, and by pre-organizing entities by threat impact in the entity summary panel. This allows analysts to immediately see which assets are affected and what the breach path is without having to manually trace through all relationships. The entity detail panel also pre-loads comprehensive entity information, so when analysts need detailed context about specific assets, it's already prepared and displayed, eliminating the time needed to gather this information.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11663500B2Visualizing cybersecurity incidents using knowledge graph data
Publication Date: 2023.05.30 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11663500B2 patent drawing
  • US11663500B2 patent drawing
  • US11663500B2 patent drawing

AI summary

Information for a knowledge graph is accessed. The knowledge graph has nodes and edges of a network and has information about security incident(s) in the network. Related entities from the knowledge graph are grouped together, where the related entities that are grouped together are determined not only by types of the entities, but also by threat(s) impacting the entities. The threat(s) correspond to the security incident(s). The grouped related entities are arranged in visualization data in order that the visualization data are configured to provide a visualization of the knowledge graph with the grouped related entities. The visualization data are output. Methods, apparatus, and computer program products are disclosed.