ETD Network Graph for IT Security Entity Relationship Visualization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current enterprise threat detection systems struggle to visualize complex relationships among IT security-relevant entities and their roles in interesting events, making it difficult to determine relationships and understand the behavior of entities from raw log data.
Innovation Solution
The implementation of an ETD Network Graph that displays entities and their relationships in a graphical user interface, using filters to fetch relevant events, identify entities, determine relationships, and display them in a human-comprehensible format, with features like tooltips and Event Series Charts for further analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If all raw log-related data is listed in a table-like format, then complete data is presented, but it is difficult to determine relationships among Entities
Solution Approach 1:
The patent transforms the traditional table-like data presentation into a network graph visualization that adds spatial and relational dimensions. Entities are represented as nodes and relationships as edges in a graphical interface, allowing investigators to visually perceive connections and patterns that are invisible in tabular formats. This dimensional transformation resolves the contradiction by maintaining complete data while making relationships detectable through visual spatial arrangement.
Solution Approach 2:
The patent creates a visual copy or representation of the raw log data in network graph form. Instead of directly presenting raw tables, it generates a graphical model that copies the essential structural relationships among entities. This visual copy preserves the complete information while transforming it into a format where relationships are immediately apparent through node connections and graph topology.
2Difficulty of detecting and measuring
If only a few Entities with their associated attributes are shown, then relationships among Entities can be visualized, but complete data is not presented
Solution Approach 1:
The network graph visualization system serves multiple functions simultaneously: it displays individual entity attributes, visualizes relationships among entities, and presents the complete dataset in an integrated view. The graphical interface can show both summary views with fewer entities and detailed views with complete data, making the system universally applicable to different investigation needs without sacrificing completeness or relationship visualization.
Solution Approach 2:
The system dynamically adjusts the level of detail and scope of displayed entities based on user interaction and investigation needs. Investigators can navigate between different levels of aggregation, zoom into specific entity relationships, and filter data dynamically. This dynamic capability allows the system to present comprehensive data when needed while emphasizing key relationships when appropriate, resolving the contradiction between completeness and visualizability.
3Difficulty of detecting and measuring
If a network graph is implemented to visualize entity relationships, then relationships and roles are determined, but system complexity increases
Solution Approach 1:
The system automatically performs the complex tasks of entity identification, relationship determination, and graph generation without requiring manual configuration or complex user intervention. The forensic analysis tool autonomously processes raw log data, identifies entities and their relationships, and constructs the network graph visualization. This self-service capability reduces the effective complexity burden on users while maintaining the advanced analytical functions needed to determine entity relationships.
Data Source
AI summary
A filter is selected from one or more filters defined for an ETD Network Graph. Events are fetched from the selected log files based on the selected filter and entities identified based on the fetched Events. Relationships are determined between the identified entities, and the determined relationships and identified entities are displayed in the ETD Network Graph. An identified entity is selected to filter data in an ETD Event Series Chart. An Event is selected in the ETD Event Series Chart to display Event Attributes in an Event Attribute Dialog. An Event Attribute is selected in the Event Attribute Dialog to filter Events in the ETD Event Series Chart.


