Execution Graphs for Real-Time Attack Progression Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional security solutions are unable to deterministically detect attack progression in real-time across enterprise infrastructure due to their unimodal nature, reliance on weak individual sensors prone to false positives, and inability to connect dispersed attack traces, leading to undetected stealthy attack phases.
Innovation Solution
A computer-implemented method using software agents deployed across the infrastructure to construct execution graphs from system-level activities, unify local trails into global execution trails, and determine risk scores, enabling real-time visualization and adaptive response to infrastructure-wide attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security solutions use individual sensors and rules to detect isolated behavioral indicators, then detection coverage is provided, but false positives increase and reliability decreases
Solution Approach 1:
The patent segments the attack detection process into distinct phases (initial entry, persistence, expansion, command and control, exfiltration) and models each phase with specific indicators. This segmentation allows the system to track attack progression through discrete, manageable stages rather than relying on monolithic detection rules, reducing false positives while maintaining comprehensive coverage.
Solution Approach 2:
The patent merges multiple isolated security sensors and data sources into a unified attack progression model. By combining indicators from endpoint detection, network monitoring, and other security tools into a cohesive graph model that tracks attack chains, the system achieves higher reliability through correlated evidence rather than isolated alerts.
2Reliability
If security solutions focus on entry prevention and ex post facto forensics, then endpoint security is addressed, but the critical stealthy progression phase remains undetected
Solution Approach 1:
The patent implements preliminary action by establishing baseline attack progression models and indicators before attacks occur. The system pre-defines what constitutes suspicious behavior at each attack stage (initial entry, persistence, expansion, etc.), enabling real-time detection during the stealthy progression phase rather than waiting for forensics after damage occurs.
Solution Approach 2:
The patent implements continuous feedback mechanisms that monitor attack progression in real-time and adjust detection sensitivity based on observed patterns. As the system tracks attack chains through the execution graph, it provides feedback loops that alert security operations when progression patterns match known attack methodologies, enabling timely intervention during the critical persistence phase.
3Reliability
If attackers spread campaigns over large environments and extended periods, then attack impact increases, but evidence removal opportunities increase
Solution Approach 1:
The patent segments attack evidence into phase-specific indicators distributed across multiple systems and time periods. By modeling attacks as sequences of discrete phases (initial entry on one system, persistence establishment, lateral expansion to other systems), the system can detect attack traces even when evidence is removed from individual systems, as the segmented progression pattern remains detectable across the infrastructure.
Solution Approach 2:
The patent creates a universal attack progression model that functions across diverse environments and attack types. The execution graph framework and phase-based indicators are designed to be environment-agnostic, allowing the system to track attack evidence across heterogeneous systems and extended time periods regardless of specific attack methodologies or infrastructure configurations.
4Productivity
If security operations teams manually analyze alerts through onion peeling, then individual alerts are investigated, but human capacity is exceeded and response efficiency decreases
Solution Approach 1:
The patent introduces an intermediary automated analysis layer between alert generation and human investigator review. The system uses the attack progression model and execution graph to automatically correlate alerts, identify attack chains, and prioritize findings before presenting them to security operations teams. This intermediary processing reduces the volume of manual analysis required while maintaining thorough investigation quality.
Data Source
AI summary
A novel enterprise security solution allows for precise interception and surgical response to attack progression, in real time, as it occurs across a distributed infrastructure. The solution includes a data monitoring and management framework that continually models system level host and network activities as mutually exclusive infrastructure wide execution sequences and bucketizes them into unique execution trails. A multimodal intelligent security middleware detects indicators of compromise in real-time on top of subsets of each unique execution trail using rule based behavioral analytics, machine learning based anomaly detection, and other sources. Each detection result dynamically contributes to aggregated risk scores at execution trail level granularities. These scores can be used to prioritize and identify highest risk attack trails to end users, along with steps that such end users can perform to mitigate further damage and progression of an attack.


