Hierarchical Event Stream Graph for Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security event management systems lack the ability to dynamically classify anomalous events and provide reference models for comparison, making it difficult for security analysts to create mental models of normal and abnormal system behavior, leading to inefficient resource allocation during anomaly investigations.
Innovation Solution
Implementing a system that generates a reference statistical model of an operational system and displays it as a hierarchical, segmented time series event stream graph, allowing for real-time anomaly detection by comparing current behavior with historical or predictive models, and providing contextual attributes to identify contributing factors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If conventional SEM systems display simple event count charts, then the system complexity is low, but the ability to detect and classify anomalies dynamically is insufficient
Solution Approach 1:
The system segments event streams into hierarchical categories (e.g., authentication events, file system events, process events) and displays them as segmented time series graphs. This segmentation allows analysts to view both aggregated event counts and drill down into specific event types, improving anomaly detection while maintaining manageable complexity through organized classification.
Solution Approach 2:
The system adds temporal and hierarchical dimensions to traditional event count charts by displaying events as time series graphs with multiple levels of categorization. This dimensional expansion transforms simple 2D bar charts into multi-dimensional visualizations that show event frequency, timing patterns, and categorical relationships, enhancing anomaly detection capability.
2Loss of information
If no reference models are provided for comparison, then the system is simpler to operate, but security analysts cannot create mental models of normal and abnormal behavior
Solution Approach 1:
The system pre-computes and stores reference statistical models representing normal system behavior patterns before analysis. These reference models are generated from historical event data and automatically updated, providing analysts with pre-prepared baselines for comparison without requiring manual model creation, thus reducing operational complexity while improving information quality.
Solution Approach 2:
The system implements feedback by continuously comparing current event streams against reference statistical models and displaying discrepancies. This feedback mechanism automatically updates analysts on deviations from normal behavior, eliminating the need for manual mental model creation and providing continuous contextual information about system state.
3Loss of information
If detailed hierarchical event information is always displayed, then complete information is provided, but the visual complexity and difficulty of identifying anomalies increases
Solution Approach 1:
The display system dynamically adjusts its level of detail based on user interaction and anomaly detection needs. Analysts can drill down from aggregated event views to detailed hierarchical categories on demand, and the system adapts the visualization complexity accordingly. This dynamic adjustment maintains information completeness while managing visual complexity through user-controlled exploration.
Solution Approach 2:
The system segments the event information display into hierarchical levels, allowing analysts to view aggregated summaries at the top level and drill down into specific event categories as needed. This segmentation organizes information hierarchically, reducing visual complexity by only displaying relevant details at each level while maintaining access to complete information through systematic exploration.
Data Source
AI summary
Apparatus, systems, and methods may operate to generate a reference statistical model of an operating system, such as a computer system, and display the reference statistical model as a hierarchical, segmented time series event stream graph, along with a graph representing current behavior of the system. The event stream graph may be derived from one or more streams of security events. Additional operations may include receiving requests to display further detail respecting discrepancies between the reference statistical model and the current behavior. Other apparatus, systems, and methods are disclosed.


