Event Anomaly Analysis Using Probabilistic Graph Analytics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise environments face challenges in analyzing vast amounts of log files to detect cyber threats and anomalies in real-time due to the opaque nature of modern computing systems and the difficulty in correlating data from heterogeneous sources, leading to delayed detection of security incidents.
Innovation Solution
An event anomaly analysis and prediction apparatus that utilizes machine learning and graph analytics to model agent behaviors, detect anomalies, and provide real-time alerts by creating probabilistic event graphs, ranking events, and generating rules for anomaly detection and control, enabling proactive security measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If traditional log file analysis methods are used, then system complexity is low, but detection speed and real-time anomaly identification are slow
Solution Approach 1:
The patent replaces traditional mechanical log analysis methods with machine learning models and graph analytics algorithms. The system uses trained models to automatically detect anomalies in log files, transitioning from manual pattern matching to intelligent automated analysis, thereby significantly improving detection speed while managing complexity through algorithmic approaches.
Solution Approach 2:
The patent introduces graph analytics as an intermediary layer between raw log data and anomaly detection. By transforming log events into graph structures with nodes and edges representing entities and relationships, the system enables more efficient pattern recognition and real-time anomaly identification without requiring direct complex analysis of raw logs.
2Measurement precision
If comprehensive log data from heterogeneous sources is analyzed, then measurement precision improves, but difficulty of detecting and measuring increases
Solution Approach 1:
The patent segments heterogeneous log data from multiple sources into standardized graph structures. By dividing complex multi-source log data into discrete events represented as graph nodes and relationships as edges, the system maintains high measurement precision while reducing the difficulty of detecting and measuring correlations through structured representation.
Solution Approach 2:
The patent transforms raw log parameters into graph analytics parameters such as node attributes, edge weights, and path probabilities. This parameter transformation enables precise anomaly detection by converting heterogeneous data formats into a unified graph-based parameter system that facilitates efficient correlation analysis.
3Productivity
If machine learning and graph analytics are implemented, then productivity in anomaly detection improves, but device complexity increases
Solution Approach 1:
The patent implements preliminary action by pre-training machine learning models on historical log data and pre-computing graph analytics baselines. This allows the system to rapidly detect anomalies in real-time without performing complex computations during actual detection, thereby improving productivity while managing apparatus complexity through offline preparation.
Data Source
AI summary
According to an example, event anomaly analysis and prediction may include accessing a master directed graph that specifies known events and transitions between the known events, and ranking each of the known events. Each of the ranked known events may be clustered into a plurality of anomaly categories. A plurality of rules to analyze new events may be determined based on the plurality of anomaly categories. A determination may be made, based on an application of the plurality of rules to data that is to be analyzed for an anomaly, whether the data includes the anomaly. In response to a determination that the data includes the anomaly, a device associated with the data may be controlled.


