Graph-Based Threat Analysis Service for Early Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Complex computer systems face challenges in detecting attacks early due to the complexity of shared services and subsystems, making it difficult to mitigate and prevent severe system compromise.
Innovation Solution
A threat analysis service that monitors customer computing environments by analyzing diagnostic information from log entries, event logs, and other sources to identify anomalies by generating graphs that link event records based on attributes, deploying decoy elements to attract attackers, and using machine learning and graph-based anomaly detection to provide actionable intelligence.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional intrusion detection systems and firewalls are used to monitor complex computer systems, then basic security is maintained, but the ability to detect attacks early deteriorates due to system complexity
Solution Approach 1:
The patent segments the complex computer system into multiple subsystems and services, analyzing each separately through graph-based event correlation. By breaking down the system into manageable components and tracking events within each segment, the solution maintains detection capability while handling system complexity through structured decomposition of security monitoring tasks.
2Measurement precision
If comprehensive monitoring of all services and subsystems is implemented, then attack detection capability is improved, but the volume of benign activity alarms increases
Solution Approach 1:
The patent implements feedback mechanisms through graph-based event correlation that continuously learns from system behavior patterns. By establishing baseline normal behavior and comparing current events against these patterns, the system provides feedback that distinguishes genuine threats from benign activities, reducing false alarms while maintaining comprehensive monitoring coverage.
Solution Approach 2:
The patent uses visual metaphors of color-coded risk levels and anomaly scoring to represent different threat states. By categorizing events into risk levels (e.g., low, medium, high) and visualizing them differently, the system helps operators quickly distinguish between benign and malicious activities, reducing the impact of alarm volume through effective information presentation.
3Loss of information
If graph-based anomaly detection with machine learning is deployed, then actionable intelligence is improved, but computational resources required increase
Solution Approach 1:
The patent applies preliminary action by pre-processing and structuring event data into graph formats before analysis. Events are normalized, correlated, and organized into predefined graph structures in advance, which reduces the computational burden during actual anomaly detection. This preliminary structuring enables more efficient machine learning processing while maintaining high-quality actionable intelligence output.
Data Source
AI summary
A system acquires diagnostic information from event logs, trace files, and other diagnostic sources to reduce a set of event records. The event records are arranged in a graph based on correlations between individual event records. Correlations may be based on time, account, credentials, tags, instance identifiers, or other characteristics. The system analyzes the graph to identify anomalies such as data exfiltration anomalies, system compromises, or security events. In some implementations, the system deploys decoy resources within a customer computing environment. Interactions with the decoy resources are captured as event records and added to the graph.


