Graph-Based Machine Learning for Multistage Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems struggle to detect complex multistage attacks and attack chains in computer environments, often missing these threats due to their focus on individual services, which can be engineered by advanced adversaries.

Innovation Solution

The implementation of adaptive graph-based machine-learning solutions that incorporate rules and supervised/unsupervised learning to detect multistage attacks by constructing graphs from event, detection, and behavior data, identifying and ranking subgraphs for likelihood of actual attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If existing systems focus on detecting individual services, then detection simplicity is maintained, but detection capability against multistage attacks deteriorates

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent segments the attack detection problem into multiple stages corresponding to different phases of the kill chain (reconnaissance, weaponization, delivery, exploitation, installation, command and control, actions on objectives). Each stage is detected and analyzed separately, then integrated to form a comprehensive multistage attack detection capability. This segmentation allows the system to handle complex multistage attacks while maintaining manageable detection processes for each individual stage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from traditional single-service detection to a multi-dimensional detection approach by incorporating temporal, spatial, and contextual dimensions. The system analyzes attacks across multiple services and time periods, building attack graphs that represent relationships between different attack stages, services, and targets. This dimensional expansion enables detection of sophisticated multistage attacks that span multiple services while maintaining systematic analysis through graph-based representations.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If systems analyze comprehensive attack chains, then detection accuracy improves, but processing time increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-defining kill chain stages and attack patterns based on known threat intelligence and historical data. The system pre-processes security events and pre-builds attack graphs for common attack scenarios, enabling faster real-time analysis when actual attacks occur. This preliminary preparation allows the system to maintain high detection accuracy for complex multistage attacks while reducing processing time during incident response.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating simplified representations of attack chains through attack graphs and models. Instead of analyzing every raw security event in detail, the system creates condensed graphical models that capture the essential relationships and patterns of multistage attacks. These copied representations enable rapid analysis and comparison against known attack patterns, maintaining high detection accuracy while significantly reducing processing time for comprehensive attack chain analysis.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11194910B2Intelligent system for detecting multistage attacks
Publication Date: 2021.12.07 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11194910B2 patent drawing
  • US11194910B2 patent drawing
  • US11194910B2 patent drawing

AI summary

Provided herein are methods, systems, and computer program products for intelligent detection of multistage attacks which may arise in computer environments. Embodiments herein leverage adaptive graph-based machine-learning solutions that can incorporate rules as well as supervised learning for detecting multistage attacks. Multistage attacks and attack chains may be detected or identified by collecting data representing events, detections, and behaviors, determining relationships among various data, and analyzing the data and associated relationships. A graph of events, detections, and behaviors which are connected by edges representing relationships between nodes of the graph may be constructed and then subgraphs of the possibly enormous initial graph may be identified which represent likely attacks.