Graph Edge Context for Infrastructure Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional security solutions are inadequate in detecting and responding to infrastructure-wide attacks in real-time due to their unimodal nature, reliance on weak individual sensors, and inability to scale with evolving cloud-based infrastructure, leading to undetected attack progression and false positives.
Innovation Solution
A computer-implemented method using graph edge context to identify infrastructure attacks by constructing execution graphs from monitored behaviors across systems, applying tags based on temporal and spatial context, and determining actions to mitigate security risks, incorporating multimodal intelligent security middleware for real-time detection and visualization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security solutions use individual sensors and rules to detect attacks, then detection coverage is provided, but false positives increase and detection precision deteriorates
Solution Approach 1:
The patent combines multiple individual sensors and detection rules into a unified graph-based security system. Execution trails are constructed by merging events from multiple sources (process creation, network connections, file operations) into cohesive attack progression narratives, allowing the system to distinguish true threats from false positives through contextual analysis of combined evidence rather than isolated indicators.
Solution Approach 2:
The security system uses composite detection by creating execution trails that combine multiple types of security events and indicators. Each execution trail represents a composite structure of related events (process spawning, network communication, file manipulation) that together form a more reliable detection signal than any single event type alone, reducing false positives through multi-factor verification.
2Reliability
If traditional security solutions monitor multiple silo sources individually, then comprehensive coverage is achieved, but the ability to detect attack progression deteriorates
Solution Approach 1:
The patent merges data from multiple siloed security sources into unified execution trails that span across different systems and event types. The graph execution service consolidates events from process monitoring, network analysis, and file system watchers into coherent attack progression narratives, enabling detection of multi-stage attacks without requiring complex manual integration of separate security tools.
Solution Approach 2:
The graph execution trail system serves multiple functions simultaneously: it detects attack progression, visualizes attack paths, identifies affected systems, and provides forensic analysis capabilities. This multi-functional approach replaces multiple separate security analysis tools with a single unified platform that handles diverse security monitoring needs through a common graph-based framework.
3Loss of time
If security solutions focus on entry prevention and ex post facto forensics, then endpoint security is addressed, but real-time attack interception capability is lost
Solution Approach 1:
The system performs preliminary analysis by continuously constructing and analyzing execution trails in real-time as events occur, rather than waiting for attack completion or relying solely on pre-defined signatures. The graph execution service proactively identifies attack progression patterns as they develop, enabling early interception of malicious activities before they can cause significant damage while maintaining high detection reliability through contextual analysis.
Data Source
AI summary
Infrastructure attacks based on graph edge context are identified by receiving an execution graph constructed by a central service based on behaviors monitored by a plurality of agents deployed on respective systems including a first system. The execution graph comprises a plurality of execution trails. One or more tags are applied to each edge of an execution trail of the execution graph based on at least one of temporal context or spatial context associated with the edge. One or more behaviors associated with the edge of the execution trail happen across an enterprise infrastructure involving the first system. The execution trail enriched with the one or more tags is analyzed. An action that is performed to mitigate security risks in the execution graph is determined based on the analysis.


