Graph-Based Threat Analysis Service for Early Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Complex computer systems face challenges in detecting attacks early due to the complexity of shared services and subsystems, making it difficult to mitigate and prevent severe system compromise.

Innovation Solution

A threat analysis service that monitors customer computing environments by analyzing diagnostic information from log entries, event logs, and other sources to identify anomalies by generating graphs that link event records based on attributes, deploying decoy elements to attract attackers, and using machine learning and graph-based anomaly detection to provide actionable intelligence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional intrusion detection systems and firewalls are used to monitor complex computer systems, then basic security is maintained, but the ability to detect attacks early deteriorates due to system complexity

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex computer system into multiple subsystems and services, analyzing each separately through graph-based event correlation. By breaking down the system into manageable components and tracking events within each segment, the solution maintains detection capability while handling system complexity through structured decomposition of security monitoring tasks.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If comprehensive monitoring of all services and subsystems is implemented, then attack detection capability is improved, but the volume of benign activity alarms increases

Engineering Contradiction:
Improveattack detection precisionVSAvoidbenign activity alarms
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The patent implements feedback mechanisms through graph-based event correlation that continuously learns from system behavior patterns. By establishing baseline normal behavior and comparing current events against these patterns, the system provides feedback that distinguishes genuine threats from benign activities, reducing false alarms while maintaining comprehensive monitoring coverage.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent uses visual metaphors of color-coded risk levels and anomaly scoring to represent different threat states. By categorizing events into risk levels (e.g., low, medium, high) and visualizing them differently, the system helps operators quickly distinguish between benign and malicious activities, reducing the impact of alarm volume through effective information presentation.

Inventive Principle:
Principle #32Color changes

3Loss of information

If graph-based anomaly detection with machine learning is deployed, then actionable intelligence is improved, but computational resources required increase

Engineering Contradiction:
Improveactionable intelligence qualityVSAvoidcomputational resource consumption
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The patent applies preliminary action by pre-processing and structuring event data into graph formats before analysis. Events are normalized, correlated, and organized into predefined graph structures in advance, which reduces the computational burden during actual anomaly detection. This preliminary structuring enables more efficient machine learning processing while maintaining high-quality actionable intelligence output.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10521584B1Computer threat analysis service
Publication Date: 2019.12.31 AMAZON TECH INC
  • US10521584B1 patent drawing
  • US10521584B1 patent drawing
  • US10521584B1 patent drawing

AI summary

A system acquires diagnostic information from event logs, trace files, and other diagnostic sources to reduce a set of event records. The event records are arranged in a graph based on correlations between individual event records. Correlations may be based on time, account, credentials, tags, instance identifiers, or other characteristics. The system analyzes the graph to identify anomalies such as data exfiltration anomalies, system compromises, or security events. In some implementations, the system deploys decoy resources within a customer computing environment. Interactions with the decoy resources are captured as event records and added to the graph.