ETD Network Graph for IT Security Entity Relationship Visualization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current enterprise threat detection systems struggle to visualize complex relationships among IT security-relevant entities and their roles in interesting events, making it difficult to determine relationships and understand the behavior of entities from raw log data.

Innovation Solution

The implementation of an ETD Network Graph that displays entities and their relationships in a graphical user interface, using filters to fetch relevant events, identify entities, determine relationships, and display them in a human-comprehensible format, with features like tooltips and Event Series Charts for further analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If all raw log-related data is listed in a table-like format, then complete data is presented, but it is difficult to determine relationships among Entities

Engineering Contradiction:
Improvecompleteness of data presentationVSAvoiddifficulty in determining entity relationships
Core Design Contradiction:
Loss of informationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent transforms the traditional table-like data presentation into a network graph visualization that adds spatial and relational dimensions. Entities are represented as nodes and relationships as edges in a graphical interface, allowing investigators to visually perceive connections and patterns that are invisible in tabular formats. This dimensional transformation resolves the contradiction by maintaining complete data while making relationships detectable through visual spatial arrangement.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent creates a visual copy or representation of the raw log data in network graph form. Instead of directly presenting raw tables, it generates a graphical model that copies the essential structural relationships among entities. This visual copy preserves the complete information while transforming it into a format where relationships are immediately apparent through node connections and graph topology.

Inventive Principle:
Principle #26Copying

2Difficulty of detecting and measuring

If only a few Entities with their associated attributes are shown, then relationships among Entities can be visualized, but complete data is not presented

Engineering Contradiction:
Improveease of determining entity relationshipsVSAvoidincompleteness of data presentation
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of information

Solution Approach 1:

The network graph visualization system serves multiple functions simultaneously: it displays individual entity attributes, visualizes relationships among entities, and presents the complete dataset in an integrated view. The graphical interface can show both summary views with fewer entities and detailed views with complete data, making the system universally applicable to different investigation needs without sacrificing completeness or relationship visualization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically adjusts the level of detail and scope of displayed entities based on user interaction and investigation needs. Investigators can navigate between different levels of aggregation, zoom into specific entity relationships, and filter data dynamically. This dynamic capability allows the system to present comprehensive data when needed while emphasizing key relationships when appropriate, resolving the contradiction between completeness and visualizability.

Inventive Principle:
Principle #15Dynamics

3Difficulty of detecting and measuring

If a network graph is implemented to visualize entity relationships, then relationships and roles are determined, but system complexity increases

Engineering Contradiction:
Improveability to determine entity relationshipsVSAvoidcomplexity of the detection system
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The system automatically performs the complex tasks of entity identification, relationship determination, and graph generation without requiring manual configuration or complex user intervention. The forensic analysis tool autonomously processes raw log data, identifies entities and their relationships, and constructs the network graph visualization. This self-service capability reduces the effective complexity burden on users while maintaining the advanced analytical functions needed to determine entity relationships.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10681064B2Analysis of complex relationships among information technology security-relevant entities using a network graph
Publication Date: 2020.06.09 SAP SE
  • US10681064B2 patent drawing
  • US10681064B2 patent drawing
  • US10681064B2 patent drawing

AI summary

A filter is selected from one or more filters defined for an ETD Network Graph. Events are fetched from the selected log files based on the selected filter and entities identified based on the fetched Events. Relationships are determined between the identified entities, and the determined relationships and identified entities are displayed in the ETD Network Graph. An identified entity is selected to filter data in an ETD Event Series Chart. An Event is selected in the ETD Event Series Chart to display Event Attributes in an Event Attribute Dialog. An Event Attribute is selected in the Event Attribute Dialog to filter Events in the ETD Event Series Chart.