Graph Edge Context for Infrastructure Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security solutions are inadequate in detecting and responding to infrastructure-wide attacks in real-time due to their unimodal nature, reliance on weak individual sensors, and inability to scale with evolving cloud-based infrastructure, leading to undetected attack progression and false positives.

Innovation Solution

A computer-implemented method using graph edge context to identify infrastructure attacks by constructing execution graphs from monitored behaviors across systems, applying tags based on temporal and spatial context, and determining actions to mitigate security risks, incorporating multimodal intelligent security middleware for real-time detection and visualization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security solutions use individual sensors and rules to detect attacks, then detection coverage is provided, but false positives increase and detection precision deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidfalse positives
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent combines multiple individual sensors and detection rules into a unified graph-based security system. Execution trails are constructed by merging events from multiple sources (process creation, network connections, file operations) into cohesive attack progression narratives, allowing the system to distinguish true threats from false positives through contextual analysis of combined evidence rather than isolated indicators.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security system uses composite detection by creating execution trails that combine multiple types of security events and indicators. Each execution trail represents a composite structure of related events (process spawning, network communication, file manipulation) that together form a more reliable detection signal than any single event type alone, reducing false positives through multi-factor verification.

Inventive Principle:
Principle #40Composite materials

2Reliability

If traditional security solutions monitor multiple silo sources individually, then comprehensive coverage is achieved, but the ability to detect attack progression deteriorates

Engineering Contradiction:
Improveattack progression detectionVSAvoidsystem integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges data from multiple siloed security sources into unified execution trails that span across different systems and event types. The graph execution service consolidates events from process monitoring, network analysis, and file system watchers into coherent attack progression narratives, enabling detection of multi-stage attacks without requiring complex manual integration of separate security tools.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The graph execution trail system serves multiple functions simultaneously: it detects attack progression, visualizes attack paths, identifies affected systems, and provides forensic analysis capabilities. This multi-functional approach replaces multiple separate security analysis tools with a single unified platform that handles diverse security monitoring needs through a common graph-based framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of time

If security solutions focus on entry prevention and ex post facto forensics, then endpoint security is addressed, but real-time attack interception capability is lost

Engineering Contradiction:
Improveresponse timeVSAvoidattack detection capability
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The system performs preliminary analysis by continuously constructing and analyzing execution trails in real-time as events occur, rather than waiting for attack completion or relying solely on pre-defined signatures. The graph execution service proactively identifies attack progression patterns as they develop, enabling early interception of malicious activities before they can cause significant damage while maintaining high detection reliability through contextual analysis.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11397808B1Attack detection based on graph edge context
Publication Date: 2022.07.26 XM CYBER LTD
  • US11397808B1 patent drawing
  • US11397808B1 patent drawing
  • US11397808B1 patent drawing

AI summary

Infrastructure attacks based on graph edge context are identified by receiving an execution graph constructed by a central service based on behaviors monitored by a plurality of agents deployed on respective systems including a first system. The execution graph comprises a plurality of execution trails. One or more tags are applied to each edge of an execution trail of the execution graph based on at least one of temporal context or spatial context associated with the edge. One or more behaviors associated with the edge of the execution trail happen across an enterprise infrastructure involving the first system. The execution trail enriched with the one or more tags is analyzed. An action that is performed to mitigate security risks in the execution graph is determined based on the analysis.