Graph-Based Network Security Analytics for Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security approaches struggle to detect unknown threats and insider threats, and they lack scalability and network visibility, making it difficult to respond promptly to security incidents.
Innovation Solution
A data processing and analytics system that employs machine learning mechanisms for user behavioral analytics, enabling the detection of security-related anomalies and threats across time and entities, and providing risk ratings and supporting evidence for timely action.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security appliances are installed to monitor network traffic, then malware detection and intrusion detection capabilities are improved, but scalability and network visibility are worsened due to localized monitoring and difficulty in handling traffic increases
Solution Approach 1:
The patent merges data from multiple security appliances and network sources into a unified graph-based security model. This allows the system to combine localized detection capabilities with global network visibility, enabling comprehensive threat detection that leverages both appliance-level details and enterprise-wide context.
Solution Approach 2:
The patent transitions from traditional flat, appliance-centric security monitoring to a multi-dimensional graph-based representation that captures relationships across time, space, and entity types. This dimensional transformation enables the system to analyze security events in context, improving both detection reliability and network-wide visibility simultaneously.
2Reliability
If traditional security products are used to detect threats, then known malware detection is improved, but detection of unknown threats and insider threats is worsened due to reliance on signature-based approaches
Solution Approach 1:
The system performs preliminary actions by continuously building and updating relationship graphs that capture normal behavior patterns and entity relationships before threats occur. This pre-established contextual baseline enables the detection of anomalies and unknown threats by comparing current events against the pre-built knowledge graph, rather than relying solely on reactive signature matching.
Solution Approach 2:
The patent introduces a graph-based relationship model as an intermediary between raw security events and threat detection algorithms. This intermediary layer transforms discrete security events into contextualized relationship patterns, enabling the system to detect both known and unknown threats by analyzing structural anomalies in the graph that signify malicious activity regardless of whether specific malware signatures are present.
3Reliability
If security appliances are deployed to provide comprehensive monitoring, then threat detection coverage is improved, but system complexity and resource requirements are worsened
Solution Approach 1:
The patent segments the complex security monitoring task into distinct graph processing operations: graph construction from events, relationship extraction, pattern matching, and anomaly detection. This segmentation allows each component to be optimized independently and processed in parallel, reducing overall system complexity while maintaining comprehensive threat detection coverage across the enterprise network.
Data Source
AI summary
The disclosed techniques relate to a graph-based network security analytic framework to combine multiple sources of information and security knowledge in order to detect risky behaviors and potential threats. In some examples, the input can be anomaly events or simply regular events. The entities associated with the activities can be grouped into smaller time units, e.g., per day. The riskiest days of activity can be found by computing a risk score for each day and according to the features in the day. A graph can be built with links between the time units. The links can also receive scoring based on a number of factors. The resulting graph can be compared with known security knowledge for adjustments. Threats can be detected based on the adjusted risk score for a component (i.e., a group of linked entities) as well as a number of other factors.


