Graph-Based Alert Interpretation Engine for Enterprise Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intrusion detection systems face challenges in alert interpretation due to the generation of complex alerts that require specific technical knowledge, leading to labor-intensive and resource-intensive monitoring processes for personnel without technical backgrounds.

Innovation Solution

A computer-implemented method employing a graph-based alert interpretation engine using process-star graph models to automatically analyze alerts, determine their cause, aftermath, and baselines, and integrate this information into an alert interpretation graph for user interfaces, facilitating understanding and interpretation of alerts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If monitoring personnel manually analyze alerts using technical knowledge, then accurate intrusion detection is achieved, but enormous staffing resources and time are required

Engineering Contradiction:
Improveintrusion detection accuracyVSAvoidalert processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an alert interpretation module as an intermediary between the intrusion detection system and monitoring personnel. This module automatically generates natural language explanations for alerts, bridging the gap between complex technical alerts and human understanding. The module includes components that retrieve alert causes, trace aftermath events, and generate baseline comparisons, thereby reducing the need for highly skilled personnel while maintaining detection accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by automatically analyzing and interpreting alerts without requiring manual technical expertise. The alert interpretation module autonomously performs cause analysis, aftermath tracing, and baseline comparison, allowing the system to serve itself in understanding and explaining security events. This reduces dependency on specialized human resources for routine alert analysis.

Inventive Principle:
Principle #25Self-service

2Loss of information

If complex alert analysis is performed manually, then detailed intrusion information is obtained, but the process is tedious and labor intensive

Engineering Contradiction:
Improveintrusion information completenessVSAvoidalert processing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-computing and storing alert cause relationships, aftermath event patterns, and baseline normal behaviors in knowledge bases. When an alert occurs, the interpretation module quickly retrieves and combines this pre-prepared information rather than analyzing everything from scratch. This reduces processing time while maintaining information completeness.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The alert interpretation module provides feedback to monitoring personnel in the form of natural language explanations that include alert causes, aftermath events, and baseline comparisons. This feedback loop enables rapid understanding of intrusion details without requiring manual analysis, reducing both time loss and information loss by presenting comprehensive results instantly.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If specialized technical personnel are deployed for monitoring, then accurate alert interpretation is achieved, but enormous staffing resources are required

Engineering Contradiction:
Improvealert interpretation accuracyVSAvoidstaffing resources
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent replaces the mechanical system of human technical expertise with an automated alert interpretation module that uses computational algorithms to analyze alerts. The module substitutes human cognitive processes with automated information retrieval, cause analysis, aftermath tracing, and natural language generation, thereby maintaining interpretation accuracy while eliminating the need for specialized personnel.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The alert interpretation module serves multiple functions: it retrieves alert causes, traces aftermath events, compares against baselines, and generates natural language explanations. This multi-functional module replaces multiple specialized roles, reducing staffing requirements while maintaining comprehensive alert interpretation capabilities across different types of security events.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10915626B2Graph model for alert interpretation in enterprise security system
Publication Date: 2021.02.09 NEC CORP
  • US10915626B2 patent drawing
  • US10915626B2 patent drawing
  • US10915626B2 patent drawing

AI summary

A computer-implemented method for implementing alert interpretation in enterprise security systems is presented. The computer-implemented method includes employing a plurality of sensors to monitor streaming data from a plurality of computing devices, generating alerts based on the monitored streaming data, and employing an alert interpretation module to interpret the alerts in real-time, the alert interpretation module including a process-star graph constructor for retrieving relationships from the streaming data to construct process-star graph models and an alert cause detector for analyzing the alerts based on the process-star graph models to determine an entity that causes an alert.