Graph-Based Multi-Stage Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity monitoring systems face challenges in presenting alerts in a meaningful way due to the arbitrary 24-hour resolution, failure to connect malicious activity across sessions, and the difficulty in evaluating the severity of alerts without a clear story, making it hard for analysts to detect multi-stage cyber threats effectively.

Innovation Solution

A graph-based system that classifies and groups alerts into tactic blocks, directionally connects them based on time, tactic, and matching criteria, and identifies threat scenarios across multiple users and sessions, presenting a cohesive story of the attack using the MITRE ATT&CK framework.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If alerts are analyzed using a per-user and per-24-hour session approach, then the analysis process is simplified, but the detection of multi-stage attacks spanning multiple sessions is compromised

Engineering Contradiction:
Improveease of alert analysisVSAvoiddetection accuracy of multi-stage attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the analysis window into multiple overlapping sessions with different time resolutions. Instead of using a single arbitrary 24-hour session boundary, the system creates multiple sessions with varying durations and overlap periods, allowing attack patterns to be detected across different time granularities. This segmentation enables both simplified analysis within each session and comprehensive detection across session boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a temporal dimension to the analysis by creating overlapping sessions with different time resolutions. Rather than analyzing alerts in a single fixed time window, the system analyzes alerts across multiple time dimensions simultaneously, allowing detection of attack patterns that span different time scales. This multi-dimensional temporal analysis resolves the contradiction between simplified analysis and accurate multi-stage attack detection.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Quantity of substance

If a large volume of alerts are generated daily, then comprehensive monitoring coverage is achieved, but the burden on analysts to investigate alerts individually increases

Engineering Contradiction:
Improvevolume of alerts monitoredVSAvoidanalyst workload
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The patent merges multiple overlapping sessions and their associated alerts into unified attack narratives. Instead of presenting analysts with separate, isolated alerts from different sessions, the system combines related alerts across session boundaries into cohesive attack stories. This merging reduces the effective number of discrete alerts analysts must evaluate while maintaining comprehensive monitoring coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a multi-functional analysis system that simultaneously performs multiple tasks: generating comprehensive alert coverage, detecting multi-stage attacks, and producing synthesized attack narratives. This universal system handles both the high-volume alert monitoring and the analytical synthesis in one integrated process, reducing analyst burden while maintaining thorough monitoring.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Quantity of substance

If alerts are presented as a random collection without contextual connections, then all alerts are captured, but the ability to understand attack severity and scope is reduced

Engineering Contradiction:
Improvenumber of alerts capturedVSAvoidcontextual information about attack story
Core Design Contradiction:
Quantity of substanceVSLoss of information

Solution Approach 1:

The patent introduces attack narratives as an intermediary layer between raw alerts and analyst interpretation. These narratives serve as mediators that connect dispersed alerts across session boundaries, providing contextual information about attack sequences, relationships between alerts, and overall attack scope. The narratives preserve all captured alerts while adding the missing contextual connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system generates attack narratives that provide feedback about the relationships and sequences among alerts. This feedback loop connects individual alerts to the broader attack context, allowing analysts to understand how individual alerts fit into the overall attack story. The narratives feed back contextual information that enriches the understanding of each individual alert's significance.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12063226B1Graph-based multi-staged attack detection in the context of an attack framework
Publication Date: 2024.08.13 EXABEAM INC
  • US12063226B1 patent drawing
  • US12063226B1 patent drawing
  • US12063226B1 patent drawing

AI summary

The present disclosure relates to a system, method, and computer program for graph-based multi-stage attack detection in which alerts are displayed in the context of tactics in an attack framework, such as the MITRE ATT&CK framework. The method enables the detection of cybersecurity threats that span multiple users and sessions and provides for the display of threat information in the context of a framework of attack tactics. Alerts spanning an analysis window are grouped into tactic blocks. Each tactic block is associated with an attack tactic and a time window. A graph is created of the tactic blocks, and threat scenarios are identified from independent clusters of directionally connected tactic blocks in the graph. The threat information is presented in the context of a sequence of attack tactics in the attack framework.