Execution Graphs for Real-Time Attack Progression Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security solutions are unable to deterministically detect attack progression in real-time across enterprise infrastructure due to their unimodal nature, reliance on weak individual sensors prone to false positives, and inability to connect dispersed attack traces, leading to undetected stealthy attack phases.

Innovation Solution

A computer-implemented method using software agents deployed across the infrastructure to construct execution graphs from system-level activities, unify local trails into global execution trails, and determine risk scores, enabling real-time visualization and adaptive response to infrastructure-wide attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security solutions use individual sensors and rules to detect isolated behavioral indicators, then detection coverage is provided, but false positives increase and reliability decreases

Engineering Contradiction:
Improveattack detection reliabilityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the attack detection process into distinct phases (initial entry, persistence, expansion, command and control, exfiltration) and models each phase with specific indicators. This segmentation allows the system to track attack progression through discrete, manageable stages rather than relying on monolithic detection rules, reducing false positives while maintaining comprehensive coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges multiple isolated security sensors and data sources into a unified attack progression model. By combining indicators from endpoint detection, network monitoring, and other security tools into a cohesive graph model that tracks attack chains, the system achieves higher reliability through correlated evidence rather than isolated alerts.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If security solutions focus on entry prevention and ex post facto forensics, then endpoint security is addressed, but the critical stealthy progression phase remains undetected

Engineering Contradiction:
Improveattack progression detectionVSAvoidattack response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by establishing baseline attack progression models and indicators before attacks occur. The system pre-defines what constitutes suspicious behavior at each attack stage (initial entry, persistence, expansion, etc.), enabling real-time detection during the stealthy progression phase rather than waiting for forensics after damage occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous feedback mechanisms that monitor attack progression in real-time and adjust detection sensitivity based on observed patterns. As the system tracks attack chains through the execution graph, it provides feedback loops that alert security operations when progression patterns match known attack methodologies, enabling timely intervention during the critical persistence phase.

Inventive Principle:
Principle #23Feedback

3Reliability

If attackers spread campaigns over large environments and extended periods, then attack impact increases, but evidence removal opportunities increase

Engineering Contradiction:
Improveattack trace detectionVSAvoidattack evidence availability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments attack evidence into phase-specific indicators distributed across multiple systems and time periods. By modeling attacks as sequences of discrete phases (initial entry on one system, persistence establishment, lateral expansion to other systems), the system can detect attack traces even when evidence is removed from individual systems, as the segmented progression pattern remains detectable across the infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal attack progression model that functions across diverse environments and attack types. The execution graph framework and phase-based indicators are designed to be environment-agnostic, allowing the system to track attack evidence across heterogeneous systems and extended time periods regardless of specific attack methodologies or infrastructure configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If security operations teams manually analyze alerts through onion peeling, then individual alerts are investigated, but human capacity is exceeded and response efficiency decreases

Engineering Contradiction:
Improvealert analysis efficiencyVSAvoidanalysis process complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary automated analysis layer between alert generation and human investigator review. The system uses the attack progression model and execution graph to automatically correlate alerts, identify attack chains, and prioritize findings before presenting them to security operations teams. This intermediary processing reduces the volume of manual analysis required while maintaining thorough investigation quality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10630704B1Methods and systems for identifying infrastructure attack progressions
Publication Date: 2020.04.21 XM CYBER LTD
  • US10630704B1 patent drawing
  • US10630704B1 patent drawing
  • US10630704B1 patent drawing

AI summary

A novel enterprise security solution allows for precise interception and surgical response to attack progression, in real time, as it occurs across a distributed infrastructure. The solution includes a data monitoring and management framework that continually models system level host and network activities as mutually exclusive infrastructure wide execution sequences and bucketizes them into unique execution trails. A multimodal intelligent security middleware detects indicators of compromise in real-time on top of subsets of each unique execution trail using rule based behavioral analytics, machine learning based anomaly detection, and other sources. Each detection result dynamically contributes to aggregated risk scores at execution trail level granularities. These scores can be used to prioritize and identify highest risk attack trails to end users, along with steps that such end users can perform to mitigate further damage and progression of an attack.