Graph-Based Alert Fusion Engine for Enterprise Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise networks face challenges in managing heterogeneous alerts from multiple detectors, with low accuracy and high false positives, and lack sufficient training data to distinguish between normal and unusual activity, hindering timely intrusion detection.
Innovation Solution
A graph-based alert fusion engine builds process and topology graphs to cluster alerts, compute trustworthiness scores, and filter out false alerts, integrating alerts in real-time without pre-defined models or training data, reducing false alert rates and improving detection accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple detectors are used to monitor enterprise networks, then detection coverage is improved, but false positive rate increases and alert management complexity increases
Solution Approach 1:
The patent merges heterogeneous alerts from multiple detectors by constructing unified process graphs and topology graphs that integrate data from network detectors, file detectors, and other security tools. The alert fusion engine combines these diverse alerts into a coherent security picture, reducing management complexity while maintaining comprehensive detection coverage.
Solution Approach 2:
The alert fusion engine serves multiple functions simultaneously: it clusters heterogeneous alerts, computes trustworthiness scores, identifies attack patterns, and prioritizes alerts for analyst review. This multi-functional system handles various detector types and alert formats through a single unified platform.
2Measurement precision
If manual labeling of alerts is performed to create training data, then model accuracy is improved, but time consumption and cost increase
Solution Approach 1:
The system performs self-service by automatically computing trustworthiness scores for alerts and automatically identifying attack patterns through the alert fusion engine. The system uses the process graphs and topology graphs to autonomously distinguish between normal and unusual activity without requiring manual labeling of training data.
Solution Approach 2:
The patent constructs process graphs and topology graphs in advance that capture normal network behavior and process relationships. These pre-built models enable the system to quickly assess new alerts against established baselines, eliminating the need for time-consuming manual labeling while maintaining high accuracy.
3Measurement precision
If alert clustering is performed to reduce false positives, then detection accuracy is improved, but processing time increases
Solution Approach 1:
The patent segments the alert fusion process into distinct stages: constructing process graphs from normal behavior, building topology graphs from network relationships, clustering alerts based on these graphs, and computing trustworthiness scores. This segmentation allows each stage to be optimized independently and processed efficiently.
Solution Approach 2:
The system performs preliminary construction of process graphs and topology graphs from historical normal behavior before alert clustering is needed. These pre-computed graphs enable rapid alert clustering and trustworthiness assessment without requiring real-time computation, thus reducing processing time while maintaining high detection accuracy.
Data Source
AI summary
Methods and systems for reporting anomalous events include building a process graph that models states of process-level events in a network. A topology graph is built that models source and destination relationships between connection events in the network. A set of alerts is clustered based on the process graph and the topology graph. Clustered alerts that exceed a threshold level of trustworthiness are reported.


