Enterprise Relationship Graphs for Low-Overhead Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security solutions for detecting malicious activities in computer networks are expensive and resource-intensive, requiring significant computational resources that could be better utilized for other tasks.
Innovation Solution
Utilizing graph theory to generate relationship graphs based on digital footprints of associates and events within an enterprise system, enabling efficient detection of anomalies and potential threats by analyzing relationships between nodes and edges in a graph data structure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security appliances and software are deployed to detect malicious activities, then detection capability is improved, but computational resource consumption and cost increase significantly
Solution Approach 1:
The patent replaces traditional hardware-based security appliances and resource-intensive software with a graph theory-based computational model. This model uses mathematical graph structures to represent and analyze relationships between entities, substituting mechanical security infrastructure with algorithmic relationship analysis that requires minimal computational resources while maintaining detection effectiveness
Solution Approach 2:
The patent transforms the security detection approach by changing the fundamental parameters from analyzing raw security data and logs to analyzing graph-based relationship metrics. By representing entities as nodes and relationships as edges, the system detects anomalies through graph structural properties rather than traditional signature-based or behavior-based analysis, significantly reducing computational overhead
2Reliability
If traditional security hardware and software are deployed, then detection capability is improved, but system cost increases significantly
Solution Approach 1:
The patent replaces expensive, long-lived security hardware appliances with lightweight, software-based graph analysis models that can be rapidly deployed and updated. The graph-based detection system uses inexpensive computational resources and can be implemented as disposable or temporary analysis instances, eliminating the need for costly dedicated security hardware infrastructure
Solution Approach 2:
The patent substitutes physical security hardware and complex software installations with a mathematical graph theory framework that runs on existing infrastructure. This substitution eliminates manufacturing, deployment, and maintenance costs associated with traditional security appliances while providing equivalent or superior detection capabilities through relationship analysis
Data Source
AI summary
Embodiments discussed herein include systems, devices, methods, and techniques to process data, generate one or more graphs, and utilize the one or more graphs to detect anomalies.


