Event Correlation Across Heterogeneous Network Domains

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems face challenges in detecting and analyzing multi-step, multi-domain threat scenarios across heterogeneous network operations, particularly in integrating IT and OT networks, leading to false alarms and incomplete threat detection.

Innovation Solution

A method for transforming network activity data into a directed graph, analyzing potential attack paths, assigning scores based on spatial, temporal, and importance components, and ranking these paths to identify and filter out non-threatening activities, thereby reducing false alarms and enhancing detection of complex threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional security systems analyze network events separately, then system complexity is reduced, but detection precision of multi-step threats deteriorates

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the analysis process into distinct components: event collection from multiple sources, graph construction from segmented event data, attack path identification through graph traversal, and scoring/ranking of identified paths. This segmentation allows complex multi-domain threat analysis to be broken into manageable steps, improving detection precision without overwhelming system complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a graph data structure as an intermediary representation layer between raw network events and threat detection algorithms. Events from IT and OT networks are transformed into graph nodes and edges, enabling standardized analysis of multi-step attack paths across heterogeneous domains while maintaining system modularity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security systems integrate IT and OT networks, then detection capability for complex threats improves, but false alarm rate increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidfalse alarm rate
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback through a scoring and ranking mechanism that evaluates identified attack paths based on multiple criteria (number of events, time span, domain crossings). This feedback loop allows the system to prioritize high-confidence threats while filtering out low-probability false alarms, maintaining high detection capability across integrated IT-OT networks

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent changes the analysis parameters by considering multiple dimensions simultaneously: spatial (number of domains crossed), temporal (time span of events), and quantitative (number of related events). This multi-parameter approach enables differentiation between genuine multi-step attacks and isolated false alarm events, improving reliability while reducing false positives

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If all communication events are analyzed in detail, then threat detection completeness improves, but processing time increases

Engineering Contradiction:
Improvethreat detection completenessVSAvoidprocessing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by constructing the complete graph representation of network events before initiating attack path analysis. This pre-processing step organizes all communication events into a structured format with defined nodes and edges, enabling efficient traversal and path identification algorithms to run faster on the pre-organized data structure

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs dynamic attack path identification through graph traversal algorithms that adaptively explore the event graph based on detected patterns. The system dynamically identifies and scores attack paths in real-time as new events are added to the graph, maintaining complete threat detection capability while optimizing processing time through adaptive exploration rather than exhaustive analysis

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10148685B2Event correlation across heterogeneous operations
Publication Date: 2018.12.04 ACCENTURE GLOBAL SERVICES LTD
  • US10148685B2 patent drawing
  • US10148685B2 patent drawing
  • US10148685B2 patent drawing

AI summary

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for determining a network security threat response. A data structure that represents communication events between computing devices of two or more network domains is received. The data structure is analyzed and a threat scenario that is based on a chain of communication events that indicates a potential attack path is determined. The chain of communication events include a sequence of communication events between computing devices proceeding from an originating computing device to a destination computing device, wherein the originating computing device and the destination computing device exist on different network domains. Attack pattern data, for the threat scenario and from a threat intelligence data source, that is associated with communications between computing devices that occurred during one or more prior attacks is received. Based on the threat scenario and the attack pattern data, one or more courses of action for responding to the threat scenario is determined, and information associated with the one or more courses of action is provided.