Graph Database for Cyber-Attack Visualization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security analysis tools struggle to provide a comprehensive visualization of computer network vulnerabilities and potential impacts on organizational mission functions, often overwhelming analysts with disparate data from multiple sources, which hinders effective threat assessment and response.

Innovation Solution

A system and method utilizing a graph database to model network vulnerabilities, incorporating network attributes, intrusion alerts, and mission dependencies, allowing for real-time visualization and prioritization of threats, and suggesting optimal responses to maintain mission readiness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security analysis tools are used to detect network intrusions, then detection capability is improved, but the complexity of analyzing and visualizing threats increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidanalysis complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security analysis tools and their outputs into a unified graph database model. The graph database integrates data from various security tools, network sensors, and mission dependency information into a single coherent representation of network vulnerabilities and attack paths, allowing analysts to view consolidated information rather than managing multiple separate tools and data sources.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The graph database serves as an intermediary layer between raw security data from multiple sources and the analyst's analytical needs. It transforms disparate data from multiple security tools into a standardized graph structure that represents vulnerabilities, attack paths, and mission impacts, simplifying the analysis process while maintaining comprehensive detection capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive network vulnerability analysis is performed, then security awareness is improved, but the time required to organize and analyze data increases

Engineering Contradiction:
Improvesecurity awarenessVSAvoiddata organization time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously maintaining the graph database model of network vulnerabilities and attack paths. The graph database is pre-populated with network topology, vulnerability information, and mission dependency relationships, so that when security events occur, the analytical framework is already in place and ready for immediate analysis without requiring time-consuming data organization during the analysis process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The graph database model maintains continuous updates of network vulnerability state and attack path relationships. The system continuously ingests security events, updates the graph model, and maintains the analytical picture alive, eliminating the need for repeated data organization and ensuring that security analysts always have access to current, organized information regardless of when analysis is performed.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If security analysts use multiple consoles from different tools, then detection coverage is improved, but situational awareness and decision-making effectiveness deteriorate

Engineering Contradiction:
Improvedetection coverageVSAvoidsituational awareness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The graph database provides a universal interface that serves multiple functions: it represents network topology, stores vulnerability information, models attack paths, and visualizes mission impacts. This single multi-functional system replaces the need for multiple specialized consoles, allowing security analysts to perform all their analytical tasks within a unified environment that maintains comprehensive detection coverage while improving situational awareness.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10313382B2System and method for visualizing and analyzing cyber-attacks using a graph model
Publication Date: 2019.06.04 THE MITRE CORPORATION
  • US10313382B2 patent drawing
  • US10313382B2 patent drawing
  • US10313382B2 patent drawing

AI summary

A system and method for implementing a graph database to analyze and monitor a status of an enterprise computer network is provided. In one example, a plurality of sensors can be inputted into sensor interface in which all of the data associated with the sensors in converted into a common data format. The data can be parsed into a data model that contains nodes and edges in order to generate a graph database model that can allow a network analyst to analyze the real-time status of a computer network. The graph database model can include multiple layers including an infrastructure layer, a cyber threats layer, a cyber posture layer, and a mission readiness layer. The graph database model can also be queried by a user using a domain-specific query language, so as to provide a user-friendly syntax in generating queries.