EDR Interface Attack Chain Visualization for Incident Investigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Endpoint Detection and Response (EDR) systems have complex user interfaces that hinder efficient interaction and decision-making for users, particularly in identifying and responding to security incidents.

Innovation Solution

A method for generating an innovative user interface for EDR systems, which includes detecting actions on a computing device, identifying source and target objects, determining malicious objects, and visually representing an attack chain with branches showing source, target, and action identifiers, along with a severity level and attack summary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional EDR user interfaces are used, then comprehensive security monitoring and analysis capabilities are provided, but the interface complexity increases and user interaction efficiency decreases

Engineering Contradiction:
Improveuser interaction efficiencyVSAvoidinterface complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the complex security incident information into structured attack chains with distinct components (source objects, target objects, actions, artifacts). Each component is visually separated and organized hierarchically, allowing users to comprehend complex security events through divided, manageable visual units rather than overwhelming monolithic displays.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms flat, two-dimensional data presentation into a multi-dimensional visual structure using attack chains that extend across multiple spatial dimensions. The attack chain visualization incorporates hierarchical levels (different chain types), temporal sequences, and spatial relationships, creating a rich visual language that encodes complex information in an intuitive multi-axis framework.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If comprehensive security data is collected and analyzed, then detection accuracy improves, but the time required for analysis and response increases

Engineering Contradiction:
Improveincident detection accuracyVSAvoidanalysis and response time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary analysis by automatically constructing attack chains from raw security events before user interaction. The system pre-organizes scattered security logs into structured narratives with identified source objects, target objects, actions, and artifacts, so that when users view the interface, the analytical work is already complete and they only need to interpret the prepared visualization.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The attack chain visualization serves as an intermediary layer between raw security data and user decision-making. Instead of presenting users with unprocessed logs requiring manual analysis, the system introduces attack chains as a mediating representation that translates complex data into intuitive visual narratives, bridging the gap between comprehensive data collection and rapid user response.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If detailed security event information is displayed, then incident understanding improves, but information overload occurs and decision-making slows down

Engineering Contradiction:
Improveincident information completenessVSAvoiddecision-making speed
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The patent applies local quality by differentiating visual presentation based on information importance. Critical elements like malicious source objects and high-impact target objects receive prominent visual treatment (color coding, sizing, positioning), while less critical information is subdued. This selective visual emphasis allows users to quickly identify what matters most without being overwhelmed by equally prominent but less important details.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent utilizes color changes to encode different aspects of security incidents efficiently. Different colors represent different chain types (lateral movement, execution, etc.), object roles (source, target, artifact), and severity levels. This color-coding system allows users to rapidly categorize and understand incident characteristics at a glance, processing information faster than reading text descriptions would allow.

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS20250156530A1Systems and methods for generating an innovative user interface for endpoint detection and response (EDR) systems
Publication Date: 2025.05.15 ACRONIS INT
  • US20250156530A1 patent drawing
  • US20250156530A1 patent drawing
  • US20250156530A1 patent drawing

AI summary

Disclosed herein are systems and method for generating an innovative user interface for endpoint detection and response (EDR) systems. In one aspect, a method may include detecting a plurality of actions performed on a computing device; for each respective action of the plurality of actions: identifying a source object performing the respective action and a target object on which the respective action is performed; determining whether any of the source object and the target object is a malicious object; in response to detecting at least one malicious object, generating, for display on a graphical user interface, an attack chain including a plurality of branches associated with the at least one malicious; and visually marking, on the graphical user interface, the at least one malicious object on the attack chain.