Enterprise Graph Threat Detection Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security architectures in cloud computing and enterprise networks face challenges in discerning significant security attacks amidst a deluge of alerts, as security information and event management (SIEM) tools often lose contextual relevance, making it difficult for IT professionals to prioritize threats effectively.

Innovation Solution

A method and system for analyzing security alerts by generating an enterprise graph to identify significant relationships between security alerts, using a fusion service to prioritize potential security incidents, and employing a kill chain interpreter to determine the likelihood of actual attacks, thereby focusing investigative efforts on critical threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If SIEM tools are used to detect security attacks, then the number of detected attacks increases, but the ability to discern significant attacks deteriorates

Engineering Contradiction:
Improvenumber of detected attacksVSAvoidability to discern significant attacks
Core Design Contradiction:
Quantity of substanceVSMeasurement precision

Solution Approach 1:

The patent segments the deluge of security alerts into meaningful groups by identifying relationships between alerts and organizing them into enterprise graphs. This segmentation transforms the overwhelming quantity of individual alerts into manageable clusters, allowing analysts to focus on significant attack patterns rather than individual noise events.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces enterprise graphs as an intermediary structure between raw security alerts and analyst interpretation. These graphs serve as a mediator that preserves contextual relationships among alerts, enabling meaningful analysis of significant attacks without being overwhelmed by the total volume of detected events.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security logs and alerts are collected for security purposes, then detection capability improves, but contextual relevance deteriorates

Engineering Contradiction:
Improvedetection capabilityVSAvoidcontextual relevance
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent adds a new dimension to security data by creating enterprise graphs that map relationships between alerts, logs, and contextual information. This dimensional transformation preserves contextual relevance by organizing data in a structured graph format that maintains connections between related security events, rather than losing context in flat log formats.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If IT professionals analyze all security alerts, then comprehensive security monitoring is achieved, but time efficiency deteriorates

Engineering Contradiction:
Improvecomprehensive security monitoringVSAvoidtime efficiency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by automatically generating enterprise graphs and identifying relationships among security alerts before analyst review. This preliminary processing organizes and prioritizes alerts based on their relationships and significance, allowing IT professionals to quickly focus on critical threats without manually analyzing every single alert.

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If relationship strength is used to prioritize security alerts, then identification of critical incidents improves, but system complexity increases

Engineering Contradiction:
Improveidentification of critical incidentsVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where the enterprise graph structure and relationship strength calculations continuously refine alert prioritization. The system analyzes relationships, calculates significance metrics, and uses this feedback to dynamically adjust the prioritization of security incidents, improving identification accuracy while managing complexity through iterative refinement.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3516574B1Enterprise graph method of threat detection
Publication Date: 2020.09.16 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3516574B1 patent drawingFigure 1
  • EP3516574B1 patent drawingFigure 2
  • EP3516574B1 patent drawingFigure 3

AI summary

Systems and methods for analyzing security alerts within an enterprise are provided. An enterprise graph is generated based on information such as operational intelligence regarding the enterprise. The enterprise graph identifies relationships between entities of the enterprise and a plurality of security alerts are produced by a plurality of security components of the enterprise. One or more significant relationships are identified between two or more of the plurality of security alerts based on a strength of a relationship identified in the enterprise graph. A significant relationship is utilized to identify a potential security incident between two or more of the security alerts.