Multi-Endpoint Event Graphs for Malware Root Cause Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies struggle to effectively identify the root cause of security compromises and distinguish malicious computing activity from legitimate processes, especially in complex computing environments, and there is a need for improved forensic analysis and malware detection techniques.

Innovation Solution

A multi-endpoint event graph is used to causally relate sequences of events among computing objects, allowing for the detection of malware by traversing the graph to identify root causes and potentially compromised objects, and implementing remediation measures based on security state evaluations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional malware detection methods are used, then simple detection is maintained, but the ability to identify root causes in complex computing environments deteriorates

Engineering Contradiction:
Improveroot cause identification accuracyVSAvoidcomputing environment complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the complex computing environment into discrete computing objects (processes, files, registry keys, network connections) and their causal relationships. This segmentation allows the system to manage complexity by breaking down the environment into manageable units that can be individually tracked and analyzed in the event graph, enabling precise root cause identification without being overwhelmed by overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a temporal dimension to the analysis by ordering computing objects and events in chronological sequence. This temporal ordering adds a new dimension to the traditional static view of computing objects, allowing the system to analyze causal relationships over time and identify root causes by examining the sequence in which objects interact, thereby improving detection accuracy in complex environments.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If comprehensive monitoring of all computing objects is implemented, then detection capability is improved, but performance impact and resource consumption increase

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by customizing the monitoring and analysis approach for different types of computing objects based on their specific characteristics and risk levels. Rather than treating all objects uniformly, the system adjusts its monitoring intensity and analysis depth according to the object type (e.g., processes, files, registry keys), allowing comprehensive monitoring of high-risk objects while maintaining acceptable performance for routine operations.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by focusing monitoring and analysis resources on the most critical computing objects and causal relationships rather than attempting to monitor everything equally. The system identifies and prioritizes objects based on their potential impact on security, applying enhanced monitoring only where necessary to maintain reliability while preserving overall system performance.

Inventive Principle:
Principle #16Partial or excessive action

3Loss of time

If real-time analysis of all events is performed, then response time to security threats is improved, but processing overhead and latency increase

Engineering Contradiction:
Improveresponse time to security eventsVSAvoidprocessing overhead
Core Design Contradiction:
Loss of timeVSLoss of energy

Solution Approach 1:

The patent applies preliminary action by pre-establishing the causal relationship framework and event graph structure before security incidents occur. The system prepares the analytical framework in advance, allowing rapid response to actual security events without the overhead of building analysis structures in real-time. This preliminary preparation enables fast response while minimizing processing overhead during actual incident response.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating a virtual representation of the computing environment's causal relationships through the event graph. Instead of directly analyzing every event in detail, the system works with a copied model of the environment's state and relationships, allowing rapid analysis and response without the full processing overhead of direct real-time analysis of all events.

Inventive Principle:
Principle #26Copying

4Loss of information

If detailed tracking of causal relationships is implemented, then forensic analysis capability is improved, but data storage and processing requirements increase

Engineering Contradiction:
Improveforensic analysis completenessVSAvoiddata volume
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential causal relationships and key computing objects from the vast amount of data generated by comprehensive monitoring. By identifying and storing only the critical causal links and object information necessary for forensic analysis rather than all raw data, the system maintains forensic completeness while significantly reducing data volume and processing requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent inverts the traditional approach by not storing all raw events and then filtering them during analysis. Instead, the system directly stores and indexes the causal relationships and key object information in a structured format, allowing rapid retrieval and analysis. This inverted approach reduces the quantity of data that needs to be stored and processed while maintaining complete forensic analysis capability.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS12536280B2Tracking malicious software movement with an event graph
Publication Date: 2026.01.27 SOPHOS LTD
  • US12536280B2 patent drawing
  • US12536280B2 patent drawing
  • US12536280B2 patent drawing

AI summary

A multi-endpoint event graph causally relates a sequence of events among a number of computing objects at a number of logical locations including multiple endpoints in an enterprise network. The multi-endpoint event graph is used to detect malware based on malicious software moving through the enterprise network.