Graph-Based Multi-Stage Attack Detection With Tactic Visualization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cybersecurity monitoring systems face challenges in connecting alerts across users and sessions, making it difficult for analysts to detect and understand multi-stage cyber threats due to arbitrary 24-hour resolution and slow-and-low attack detection, leading to a burdensome evaluation of seemingly random alerts without a clear story.

Innovation Solution

A graph-based system that groups cybersecurity alerts into tactic blocks, connects them based on time, tactic, and matching criteria, and identifies threat scenarios through connected components, enabling visualization of multi-stage attacks in the context of an attack framework.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If alerts are analyzed using a per-user and per-24-hour session approach, then the analysis process is simplified, but multi-stage attacks spanning multiple sessions and users cannot be detected

Engineering Contradiction:
Improvealert analysis processVSAvoidattack detection capability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the analysis window into multiple overlapping sessions (e.g., 1-hour, 6-hour, 12-hour, 24-hour sessions) instead of using a single 24-hour session. This segmentation allows attacks to be detected at multiple time granularities, capturing both rapid and slow-and-low attacks while maintaining manageable analysis complexity through structured session breakdown.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a temporal dimension by creating multiple overlapping sessions within the analysis window, transforming the single-dimension (24-hour) approach into a multi-dimensional temporal structure. This allows alerts to be correlated across different time scales simultaneously, enabling detection of attacks that span multiple traditional session boundaries without overwhelming analysts with a single massive dataset.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Duration of action of moving object

If a long analysis window is used to capture multi-stage attacks, then more attack stages are included, but the volume of alerts increases making analysis more difficult

Engineering Contradiction:
Improveattack detection windowVSAvoidnumber of alerts
Core Design Contradiction:
Duration of action of moving objectVSQuantity of substance

Solution Approach 1:

The patent divides the long analysis window (e.g., 30-60 days) into multiple overlapping sessions of varying durations. This segmentation breaks the large volume of alerts into smaller, manageable chunks that can be analyzed separately, while the overlapping nature ensures multi-stage attacks spanning the entire window are captured across multiple session analyses.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs alert analysis at multiple levels of granularity - analyzing alerts within each individual session as well as correlating across sessions. This partial action approach allows analysts to focus on specific time periods and attack stages independently, rather than being overwhelmed by the complete dataset, while still achieving comprehensive multi-stage attack detection through iterative analysis.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If alerts are presented as a random collection without contextual organization, then presentation simplicity is maintained, but analyst understanding and actionability are reduced

Engineering Contradiction:
Improvealert presentationVSAvoidattack story coherence
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent segments alerts into distinct sessions with clear temporal boundaries and organizational structures. Each session presents a coherent subset of alerts that can be independently analyzed, while the segmentation by session, user, and time period provides natural groupings that help analysts understand alert relationships without presenting overwhelming randomness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent organizes alerts across multiple dimensions including time (overlapping sessions), user identity, and attack stage. This multi-dimensional organization transforms a flat, random collection into a structured hierarchy where alerts are naturally grouped by contextual relationships, enabling analysts to follow attack narratives across multiple dimensions simultaneously while maintaining clear organizational structure.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12368729B1Graph-based multi-staged attack detection and visualization in the context of an attack framework
Publication Date: 2025.07.22 EXABEAM INC
  • US12368729B1 patent drawing
  • US12368729B1 patent drawing
  • US12368729B1 patent drawing

AI summary

The present disclosure relates to a system, method, and computer program for graph-based multi-stage attack detection in which alerts are graphically visualized in the context of tactics in an attack framework. The method enables the detection of cybersecurity threats that span multiple users and sessions and provides for the display of threat information in the context of a framework of attack tactics. Alerts spanning an analysis window are grouped into tactic blocks. Each tactic block is associated with an attack tactic and a time window. A graph is created of the tactic blocks, and threat scenarios are identified from independent clusters of directionally connected tactic blocks in the graph. The threat information is visualized graphically in the context of a sequence of attack tactics in the attack framework. A user can toggle between graphical visualizations of a cluster as a whole and the individual threat scenario paths in the cluster.