Multi-Endpoint Event Graphs for Malware Root Cause Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies struggle to effectively identify the root cause of security compromises and distinguish malicious computing activity from legitimate processes, especially in complex computing environments, and there is a need for improved forensic analysis and malware detection techniques.
Innovation Solution
A multi-endpoint event graph is used to causally relate sequences of events among computing objects, allowing for the detection of malware by traversing the graph to identify root causes and potentially compromised objects, and implementing remediation measures based on security state evaluations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional malware detection methods are used, then simple detection is maintained, but the ability to identify root causes in complex computing environments deteriorates
Solution Approach 1:
The patent segments the complex computing environment into discrete computing objects (processes, files, registry keys, network connections) and their causal relationships. This segmentation allows the system to manage complexity by breaking down the environment into manageable units that can be individually tracked and analyzed in the event graph, enabling precise root cause identification without being overwhelmed by overall system complexity.
Solution Approach 2:
The patent introduces a temporal dimension to the analysis by ordering computing objects and events in chronological sequence. This temporal ordering adds a new dimension to the traditional static view of computing objects, allowing the system to analyze causal relationships over time and identify root causes by examining the sequence in which objects interact, thereby improving detection accuracy in complex environments.
2Reliability
If comprehensive monitoring of all computing objects is implemented, then detection capability is improved, but performance impact and resource consumption increase
Solution Approach 1:
The patent applies local quality by customizing the monitoring and analysis approach for different types of computing objects based on their specific characteristics and risk levels. Rather than treating all objects uniformly, the system adjusts its monitoring intensity and analysis depth according to the object type (e.g., processes, files, registry keys), allowing comprehensive monitoring of high-risk objects while maintaining acceptable performance for routine operations.
Solution Approach 2:
The patent implements partial action by focusing monitoring and analysis resources on the most critical computing objects and causal relationships rather than attempting to monitor everything equally. The system identifies and prioritizes objects based on their potential impact on security, applying enhanced monitoring only where necessary to maintain reliability while preserving overall system performance.
3Loss of time
If real-time analysis of all events is performed, then response time to security threats is improved, but processing overhead and latency increase
Solution Approach 1:
The patent applies preliminary action by pre-establishing the causal relationship framework and event graph structure before security incidents occur. The system prepares the analytical framework in advance, allowing rapid response to actual security events without the overhead of building analysis structures in real-time. This preliminary preparation enables fast response while minimizing processing overhead during actual incident response.
Solution Approach 2:
The patent uses copying by creating a virtual representation of the computing environment's causal relationships through the event graph. Instead of directly analyzing every event in detail, the system works with a copied model of the environment's state and relationships, allowing rapid analysis and response without the full processing overhead of direct real-time analysis of all events.
4Loss of information
If detailed tracking of causal relationships is implemented, then forensic analysis capability is improved, but data storage and processing requirements increase
Solution Approach 1:
The patent extracts only the essential causal relationships and key computing objects from the vast amount of data generated by comprehensive monitoring. By identifying and storing only the critical causal links and object information necessary for forensic analysis rather than all raw data, the system maintains forensic completeness while significantly reducing data volume and processing requirements.
Solution Approach 2:
The patent inverts the traditional approach by not storing all raw events and then filtering them during analysis. Instead, the system directly stores and indexes the causal relationships and key object information in a structured format, allowing rapid retrieval and analysis. This inverted approach reduces the quantity of data that needs to be stored and processed while maintaining complete forensic analysis capability.
Data Source
AI summary
A multi-endpoint event graph causally relates a sequence of events among a number of computing objects at a number of logical locations including multiple endpoints in an enterprise network. The multi-endpoint event graph is used to detect malware based on malicious software moving through the enterprise network.


