Enterprise Graph Threat Detection Prioritization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security architectures in cloud computing and enterprise networks face challenges in discerning significant security attacks amidst a deluge of alerts, as security information and event management (SIEM) tools often lose contextual relevance, making it difficult for IT professionals to prioritize threats effectively.
Innovation Solution
A method and system for analyzing security alerts by generating an enterprise graph to identify significant relationships between security alerts, using a fusion service to prioritize potential security incidents, and employing a kill chain interpreter to determine the likelihood of actual attacks, thereby focusing investigative efforts on critical threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If SIEM tools are used to detect security attacks, then the number of detected attacks increases, but the ability to discern significant attacks deteriorates
Solution Approach 1:
The patent segments the deluge of security alerts into meaningful groups by identifying relationships between alerts and organizing them into enterprise graphs. This segmentation transforms the overwhelming quantity of individual alerts into manageable clusters, allowing analysts to focus on significant attack patterns rather than individual noise events.
Solution Approach 2:
The patent introduces enterprise graphs as an intermediary structure between raw security alerts and analyst interpretation. These graphs serve as a mediator that preserves contextual relationships among alerts, enabling meaningful analysis of significant attacks without being overwhelmed by the total volume of detected events.
2Reliability
If security logs and alerts are collected for security purposes, then detection capability improves, but contextual relevance deteriorates
Solution Approach 1:
The patent adds a new dimension to security data by creating enterprise graphs that map relationships between alerts, logs, and contextual information. This dimensional transformation preserves contextual relevance by organizing data in a structured graph format that maintains connections between related security events, rather than losing context in flat log formats.
3Reliability
If IT professionals analyze all security alerts, then comprehensive security monitoring is achieved, but time efficiency deteriorates
Solution Approach 1:
The patent performs preliminary actions by automatically generating enterprise graphs and identifying relationships among security alerts before analyst review. This preliminary processing organizes and prioritizes alerts based on their relationships and significance, allowing IT professionals to quickly focus on critical threats without manually analyzing every single alert.
4Measurement precision
If relationship strength is used to prioritize security alerts, then identification of critical incidents improves, but system complexity increases
Solution Approach 1:
The patent implements feedback mechanisms where the enterprise graph structure and relationship strength calculations continuously refine alert prioritization. The system analyzes relationships, calculates significance metrics, and uses this feedback to dynamically adjust the prioritization of security incidents, improving identification accuracy while managing complexity through iterative refinement.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems and methods for analyzing security alerts within an enterprise are provided. An enterprise graph is generated based on information such as operational intelligence regarding the enterprise. The enterprise graph identifies relationships between entities of the enterprise and a plurality of security alerts are produced by a plurality of security components of the enterprise. One or more significant relationships are identified between two or more of the plurality of security alerts based on a strength of a relationship identified in the enterprise graph. A significant relationship is utilized to identify a potential security incident between two or more of the security alerts.