Graph-Based Multi-Stage Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity monitoring systems face challenges in presenting alerts in a meaningful way due to the arbitrary 24-hour resolution, failure to connect malicious activity across sessions, and the difficulty in evaluating the severity of alerts without a clear story, making it hard for analysts to detect multi-stage cyber threats effectively.
Innovation Solution
A graph-based system that classifies and groups alerts into tactic blocks, directionally connects them based on time, tactic, and matching criteria, and identifies threat scenarios across multiple users and sessions, presenting a cohesive story of the attack using the MITRE ATT&CK framework.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If alerts are analyzed using a per-user and per-24-hour session approach, then the analysis process is simplified, but the detection of multi-stage attacks spanning multiple sessions is compromised
Solution Approach 1:
The patent segments the analysis window into multiple overlapping sessions with different time resolutions. Instead of using a single arbitrary 24-hour session boundary, the system creates multiple sessions with varying durations and overlap periods, allowing attack patterns to be detected across different time granularities. This segmentation enables both simplified analysis within each session and comprehensive detection across session boundaries.
Solution Approach 2:
The patent introduces a temporal dimension to the analysis by creating overlapping sessions with different time resolutions. Rather than analyzing alerts in a single fixed time window, the system analyzes alerts across multiple time dimensions simultaneously, allowing detection of attack patterns that span different time scales. This multi-dimensional temporal analysis resolves the contradiction between simplified analysis and accurate multi-stage attack detection.
2Quantity of substance
If a large volume of alerts are generated daily, then comprehensive monitoring coverage is achieved, but the burden on analysts to investigate alerts individually increases
Solution Approach 1:
The patent merges multiple overlapping sessions and their associated alerts into unified attack narratives. Instead of presenting analysts with separate, isolated alerts from different sessions, the system combines related alerts across session boundaries into cohesive attack stories. This merging reduces the effective number of discrete alerts analysts must evaluate while maintaining comprehensive monitoring coverage.
Solution Approach 2:
The patent creates a multi-functional analysis system that simultaneously performs multiple tasks: generating comprehensive alert coverage, detecting multi-stage attacks, and producing synthesized attack narratives. This universal system handles both the high-volume alert monitoring and the analytical synthesis in one integrated process, reducing analyst burden while maintaining thorough monitoring.
3Quantity of substance
If alerts are presented as a random collection without contextual connections, then all alerts are captured, but the ability to understand attack severity and scope is reduced
Solution Approach 1:
The patent introduces attack narratives as an intermediary layer between raw alerts and analyst interpretation. These narratives serve as mediators that connect dispersed alerts across session boundaries, providing contextual information about attack sequences, relationships between alerts, and overall attack scope. The narratives preserve all captured alerts while adding the missing contextual connections.
Solution Approach 2:
The system generates attack narratives that provide feedback about the relationships and sequences among alerts. This feedback loop connects individual alerts to the broader attack context, allowing analysts to understand how individual alerts fit into the overall attack story. The narratives feed back contextual information that enriches the understanding of each individual alert's significance.
Data Source
AI summary
The present disclosure relates to a system, method, and computer program for graph-based multi-stage attack detection in which alerts are displayed in the context of tactics in an attack framework, such as the MITRE ATT&CK framework. The method enables the detection of cybersecurity threats that span multiple users and sessions and provides for the display of threat information in the context of a framework of attack tactics. Alerts spanning an analysis window are grouped into tactic blocks. Each tactic block is associated with an attack tactic and a time window. A graph is created of the tactic blocks, and threat scenarios are identified from independent clusters of directionally connected tactic blocks in the graph. The threat information is presented in the context of a sequence of attack tactics in the attack framework.


