Data Investigation Knowledge Graphs for Reproducible Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data investigation processes are labor-intensive, imprecise, difficult to scale, non-exhaustive, and difficult to document, requiring manual querying and correlation of information across multiple data sources, leading to challenges in accurately reproducing investigations.
Innovation Solution
A data investigation system utilizing microservices to automate querying across multiple data sources, generating a knowledge graph that visually depicts relationships between entities and events, and storing investigation steps for documentation and reproduction.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual querying and correlation of information is used across multiple data sources, then flexibility in investigation approach is maintained, but labor intensity and time consumption increase significantly
Solution Approach 1:
The patent introduces an automated investigation system that acts as an intermediary between analysts and multiple data sources. The system automatically queries, retrieves, and correlates information from diverse data sources based on investigation parameters, eliminating manual labor while preserving analytical flexibility through configurable investigation workflows and visual exploration capabilities.
Solution Approach 2:
The patent replaces the mechanical manual process of querying and correlating data with an automated computational system. The system uses algorithms to automatically retrieve data from multiple sources, correlate information, and generate visual representations, substituting human manual operations with automated mechanical processes that maintain flexibility through programmable parameters.
2Adaptability or versatility
If manual investigation processes are used, then adaptability to different investigation scenarios is maintained, but documentation and reproduction of investigations become difficult
Solution Approach 1:
The patent implements automated documentation that provides feedback about investigation processes and results. The system automatically records investigation parameters, data sources queried, and correlation methods used, creating a complete audit trail that enables reproduction of investigations while maintaining adaptability through configurable investigation templates and parameters.
Solution Approach 2:
The patent creates automated copies of investigation processes and results in structured digital formats. The system generates visual representations and data structures that capture the essence of investigations, enabling easy reproduction and review while maintaining adaptability through parameter-based configuration that allows the same investigation template to be applied to different scenarios.
3Measurement precision
If comprehensive querying of multiple data sources is performed, then investigation accuracy and completeness improve, but system complexity and configuration difficulty increase
Solution Approach 1:
The patent implements a universal investigation system that can query multiple different data sources through a single unified interface. The system uses standardized protocols and adapters to interact with diverse data sources, maintaining investigation accuracy through comprehensive data retrieval while reducing configuration complexity by providing a common framework that works across different data source types.
Solution Approach 2:
The patent segments the complex task of querying multiple data sources into manageable components, with each data source handled by dedicated adapters or connectors. This segmentation allows the system to maintain high investigation accuracy by thoroughly querying each source while reducing overall configuration complexity by organizing data source connections into modular, independently-configurable units.
Data Source
AI summary
Data investigations are performed by querying a plurality of data sources. A system receives an investigation input and queries a plurality of data sources in accordance with the received input. The system receives, in response to the querying, response data from the plurality of data sources, and generates and stores a data structure representing relationships between the first investigation input and the first response data. The data structure may be in the form of a knowledge graph. The system may generate and display a visualization of the data structure. The system may generate and store a record of investigation steps used to generate the data structure, such that the investigation steps may be applied in future instances, for example using different inputs, to generate new data structures.


