Event Correlation Graphs for Enterprise Security Kill Chains

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing rule/feature-based approaches for detecting advanced persistent threats (APT) in enterprise networks suffer from high false-positive rates and fail to provide a comprehensive view of attack chains, as they only detect isolated phases of attacks, making it difficult to identify real APT attacks amidst a high volume of false positives.

Innovation Solution

A two-stage framework that constructs an event correlation graph from system monitoring logs to generate kill chains, which characterize events in an attack path over time, using Hawkes processes to model event triggering correlations and learn behavioral characteristics of processes, thereby reducing false positives and identifying well-organized attack chains automatically without prior knowledge or labeled datasets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If rule/feature-based approaches are used for APT detection, then detection capability is provided, but false positive rate increases and comprehensive attack chain view is lost

Engineering Contradiction:
Improvedetection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent merges multiple isolated detection rules and features into a unified event correlation graph that models the temporal and causal relationships between events. This combines fragmented detection capabilities into a comprehensive attack chain analysis system, reducing false positives by evaluating events in context rather than isolation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a temporal dimension to traditional rule-based detection by constructing event correlation graphs that track event sequences over time. This transforms static rule matching into dynamic temporal pattern recognition, enabling the system to distinguish between isolated false alarms and genuine attack chains.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If rule/feature-based approaches detect isolated attack phases, then some attack detection is achieved, but high-level picture of whole attack is not provided

Engineering Contradiction:
Improveattack detection capabilityVSAvoidcomprehensive attack chain information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments attack detection into two complementary stages: (1) constructing event correlation graphs from individual events, and (2) generating kill chains from correlated events. This segmentation allows detailed event-level analysis while synthesizing high-level attack chain patterns, preserving both granular detection capability and holistic attack understanding.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a nested structure where event correlation graphs (containing detailed event data) are embedded within kill chain representations (providing high-level attack patterns). This nested organization allows the system to maintain comprehensive attack chain information while providing both detailed and summarized views of attacks.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Extent of automation

If automated kill chain generation is implemented, then administrator intervention is reduced, but system complexity increases

Engineering Contradiction:
Improveautomated security managementVSAvoidsystem complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent implements self-service automation where the system automatically constructs event correlation graphs and generates kill chains without administrator intervention. The system serves itself by autonomously learning attack patterns from data and generating security insights, reducing manual workload while managing complexity through automated processes.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10298607B2Constructing graph models of event correlation in enterprise security systems
Publication Date: 2019.05.21 CLOUD BYTE LLC
  • US10298607B2 patent drawing
  • US10298607B2 patent drawing
  • US10298607B2 patent drawing

AI summary

Methods and systems for detecting anomalous events include detecting anomalous events in monitored system data. An event correlation graph is generated by determining a tendency for a first process to access a system target, including an innate tendency of the first process to access the system target, an influence of previous events from the first process, and an influence of processes other than the first process. Kill chains are generated from the event correlation graph that characterize events in an attack path over time. A security management action is performed based on the kill chains.