Hierarchical Event Stream Graph for Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security event management systems lack the ability to dynamically classify anomalous events and provide reference models for comparison, making it difficult for security analysts to create mental models of normal and abnormal system behavior, leading to inefficient resource allocation during anomaly investigations.

Innovation Solution

Implementing a system that generates a reference statistical model of an operational system and displays it as a hierarchical, segmented time series event stream graph, allowing for real-time anomaly detection by comparing current behavior with historical or predictive models, and providing contextual attributes to identify contributing factors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If conventional SEM systems display simple event count charts, then the system complexity is low, but the ability to detect and classify anomalies dynamically is insufficient

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The system segments event streams into hierarchical categories (e.g., authentication events, file system events, process events) and displays them as segmented time series graphs. This segmentation allows analysts to view both aggregated event counts and drill down into specific event types, improving anomaly detection while maintaining manageable complexity through organized classification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds temporal and hierarchical dimensions to traditional event count charts by displaying events as time series graphs with multiple levels of categorization. This dimensional expansion transforms simple 2D bar charts into multi-dimensional visualizations that show event frequency, timing patterns, and categorical relationships, enhancing anomaly detection capability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Loss of information

If no reference models are provided for comparison, then the system is simpler to operate, but security analysts cannot create mental models of normal and abnormal behavior

Engineering Contradiction:
Improvecontextual information for anomaly classificationVSAvoidease of creating mental models
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The system pre-computes and stores reference statistical models representing normal system behavior patterns before analysis. These reference models are generated from historical event data and automatically updated, providing analysts with pre-prepared baselines for comparison without requiring manual model creation, thus reducing operational complexity while improving information quality.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously comparing current event streams against reference statistical models and displaying discrepancies. This feedback mechanism automatically updates analysts on deviations from normal behavior, eliminating the need for manual mental model creation and providing continuous contextual information about system state.

Inventive Principle:
Principle #23Feedback

3Loss of information

If detailed hierarchical event information is always displayed, then complete information is provided, but the visual complexity and difficulty of identifying anomalies increases

Engineering Contradiction:
Improvecompleteness of event informationVSAvoidvisual complexity of display
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The display system dynamically adjusts its level of detail based on user interaction and anomaly detection needs. Analysts can drill down from aggregated event views to detailed hierarchical categories on demand, and the system adapts the visualization complexity accordingly. This dynamic adjustment maintains information completeness while managing visual complexity through user-controlled exploration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system segments the event information display into hierarchical levels, allowing analysts to view aggregated summaries at the top level and drill down into specific event categories as needed. This segmentation organizes information hierarchically, reducing visual complexity by only displaying relevant details at each level while maintaining access to complete information through systematic exploration.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8966392B2Event management apparatus, systems, and methods
Publication Date: 2015.02.24 MICRO FOCUS SOFTWARE INC
  • US8966392B2 patent drawing
  • US8966392B2 patent drawing
  • US8966392B2 patent drawing

AI summary

Apparatus, systems, and methods may operate to generate a reference statistical model of an operating system, such as a computer system, and display the reference statistical model as a hierarchical, segmented time series event stream graph, along with a graph representing current behavior of the system. The event stream graph may be derived from one or more streams of security events. Additional operations may include receiving requests to display further detail respecting discrepancies between the reference statistical model and the current behavior. Other apparatus, systems, and methods are disclosed.