Graph-Based Multi-Stage Attack Detection With Tactic Visualization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cybersecurity monitoring systems face challenges in connecting alerts across users and sessions, making it difficult for analysts to detect and understand multi-stage cyber threats due to arbitrary 24-hour resolution and slow-and-low attack detection, leading to a burdensome evaluation of seemingly random alerts without a clear story.
Innovation Solution
A graph-based system that groups cybersecurity alerts into tactic blocks, connects them based on time, tactic, and matching criteria, and identifies threat scenarios through connected components, enabling visualization of multi-stage attacks in the context of an attack framework.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If alerts are analyzed using a per-user and per-24-hour session approach, then the analysis process is simplified, but multi-stage attacks spanning multiple sessions and users cannot be detected
Solution Approach 1:
The patent segments the analysis window into multiple overlapping sessions (e.g., 1-hour, 6-hour, 12-hour, 24-hour sessions) instead of using a single 24-hour session. This segmentation allows attacks to be detected at multiple time granularities, capturing both rapid and slow-and-low attacks while maintaining manageable analysis complexity through structured session breakdown.
Solution Approach 2:
The patent adds a temporal dimension by creating multiple overlapping sessions within the analysis window, transforming the single-dimension (24-hour) approach into a multi-dimensional temporal structure. This allows alerts to be correlated across different time scales simultaneously, enabling detection of attacks that span multiple traditional session boundaries without overwhelming analysts with a single massive dataset.
2Duration of action of moving object
If a long analysis window is used to capture multi-stage attacks, then more attack stages are included, but the volume of alerts increases making analysis more difficult
Solution Approach 1:
The patent divides the long analysis window (e.g., 30-60 days) into multiple overlapping sessions of varying durations. This segmentation breaks the large volume of alerts into smaller, manageable chunks that can be analyzed separately, while the overlapping nature ensures multi-stage attacks spanning the entire window are captured across multiple session analyses.
Solution Approach 2:
The patent performs alert analysis at multiple levels of granularity - analyzing alerts within each individual session as well as correlating across sessions. This partial action approach allows analysts to focus on specific time periods and attack stages independently, rather than being overwhelmed by the complete dataset, while still achieving comprehensive multi-stage attack detection through iterative analysis.
3Ease of operation
If alerts are presented as a random collection without contextual organization, then presentation simplicity is maintained, but analyst understanding and actionability are reduced
Solution Approach 1:
The patent segments alerts into distinct sessions with clear temporal boundaries and organizational structures. Each session presents a coherent subset of alerts that can be independently analyzed, while the segmentation by session, user, and time period provides natural groupings that help analysts understand alert relationships without presenting overwhelming randomness.
Solution Approach 2:
The patent organizes alerts across multiple dimensions including time (overlapping sessions), user identity, and attack stage. This multi-dimensional organization transforms a flat, random collection into a structured hierarchy where alerts are naturally grouped by contextual relationships, enabling analysts to follow attack narratives across multiple dimensions simultaneously while maintaining clear organizational structure.
Data Source
AI summary
The present disclosure relates to a system, method, and computer program for graph-based multi-stage attack detection in which alerts are graphically visualized in the context of tactics in an attack framework. The method enables the detection of cybersecurity threats that span multiple users and sessions and provides for the display of threat information in the context of a framework of attack tactics. Alerts spanning an analysis window are grouped into tactic blocks. Each tactic block is associated with an attack tactic and a time window. A graph is created of the tactic blocks, and threat scenarios are identified from independent clusters of directionally connected tactic blocks in the graph. The threat information is visualized graphically in the context of a sequence of attack tactics in the attack framework. A user can toggle between graphical visualizations of a cluster as a whole and the individual threat scenario paths in the cluster.


