Graph-Based Alert Fusion Engine for Enterprise Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise networks face challenges in managing heterogeneous alerts from multiple detectors, with low accuracy and high false positives, and lack sufficient training data to distinguish between normal and unusual activity, hindering timely intrusion detection.

Innovation Solution

A graph-based alert fusion engine builds process and topology graphs to cluster alerts, compute trustworthiness scores, and filter out false alerts, integrating alerts in real-time without pre-defined models or training data, reducing false alert rates and improving detection accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple detectors are used to monitor enterprise networks, then detection coverage is improved, but false positive rate increases and alert management complexity increases

Engineering Contradiction:
Improvedetection coverageVSAvoidalert management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges heterogeneous alerts from multiple detectors by constructing unified process graphs and topology graphs that integrate data from network detectors, file detectors, and other security tools. The alert fusion engine combines these diverse alerts into a coherent security picture, reducing management complexity while maintaining comprehensive detection coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The alert fusion engine serves multiple functions simultaneously: it clusters heterogeneous alerts, computes trustworthiness scores, identifies attack patterns, and prioritizes alerts for analyst review. This multi-functional system handles various detector types and alert formats through a single unified platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If manual labeling of alerts is performed to create training data, then model accuracy is improved, but time consumption and cost increase

Engineering Contradiction:
Improvemodel accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs self-service by automatically computing trustworthiness scores for alerts and automatically identifying attack patterns through the alert fusion engine. The system uses the process graphs and topology graphs to autonomously distinguish between normal and unusual activity without requiring manual labeling of training data.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent constructs process graphs and topology graphs in advance that capture normal network behavior and process relationships. These pre-built models enable the system to quickly assess new alerts against established baselines, eliminating the need for time-consuming manual labeling while maintaining high accuracy.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If alert clustering is performed to reduce false positives, then detection accuracy is improved, but processing time increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the alert fusion process into distinct stages: constructing process graphs from normal behavior, building topology graphs from network relationships, clustering alerts based on these graphs, and computing trustworthiness scores. This segmentation allows each stage to be optimized independently and processed efficiently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary construction of process graphs and topology graphs from historical normal behavior before alert clustering is needed. These pre-computed graphs enable rapid alert clustering and trustworthiness assessment without requiring real-time computation, thus reducing processing time while maintaining high detection accuracy.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10476752B2Blue print graphs for fusing of heterogeneous alerts
Publication Date: 2019.11.12 CLOUD BYTE LLC
  • US10476752B2 patent drawing
  • US10476752B2 patent drawing
  • US10476752B2 patent drawing

AI summary

Methods and systems for reporting anomalous events include building a process graph that models states of process-level events in a network. A topology graph is built that models source and destination relationships between connection events in the network. A set of alerts is clustered based on the process graph and the topology graph. Clustered alerts that exceed a threshold level of trustworthiness are reported.