Hierarchical Directed Acyclic Graph for Network Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies face challenges in detecting advanced persistent threats (APT) and other hacking methods, as they require manual analysis by experienced professionals, which is time-consuming and inefficient for large networks, and cannot provide real-time detection of system anomalies or intrusion threats.

Innovation Solution

An information security incident diagnosis system that includes an activities record collection device and a suspicious incident determination device, which collects and processes activity records to generate a discrete space metric tree, performs clustering, and creates a hierarchical directed acyclic graph (HDAG) to visually represent similar and differential features, aiding in the detection of intrusions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual analysis by experienced professionals is used, then detection accuracy is improved, but analysis time and productivity deteriorate

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent introduces an automated analysis system that acts as an intermediary between raw activity records and expert analysts. The system includes modules for automated collection, processing, clustering, and visualization of computing device activities, providing pre-processed intelligence that reduces the time and effort required for manual analysis while maintaining high detection accuracy through structured data presentation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The analysis system segments the complex detection task into distinct automated modules: activity record collection, data processing, clustering analysis, and visual presentation. This segmentation allows routine analysis functions to be automated while preserving expert judgment for final interpretation, thereby improving productivity without sacrificing detection accuracy.

Inventive Principle:
Principle #1Segmentation

2Reliability

If manual analysis methods are used for large networks, then comprehensive detection is improved, but time cost and productivity worsen

Engineering Contradiction:
Improvedetection comprehensivenessVSAvoidanalysis time cost
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service automated analysis that continuously collects and processes activity records without requiring constant expert intervention. The automated clustering and visualization modules operate independently to provide ongoing security monitoring, ensuring comprehensive detection across large networks while minimizing time costs through continuous autonomous operation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary automated analysis actions on activity records before they reach human analysts. By pre-processing data, performing initial clustering, and generating visualizations in advance, the system reduces the time required for comprehensive detection while maintaining thoroughness through systematic automated examination of all records.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If conventional manual analysis is used, then detailed examination is improved, but real-time detection capability worsens

Engineering Contradiction:
Improveexamination detailVSAvoidreal-time detection speed
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The patent replaces the mechanical manual analysis process with an automated computational system that uses algorithms for clustering and pattern recognition. This substitution maintains detailed examination capability through systematic data processing while achieving real-time detection speed through automated computation, eliminating the inherent delay between data collection and analysis.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12086241B2Event visualization device for generating hierarchical directed acyclic graph and related computer program product
Publication Date: 2024.09.10 CYCARRIER TECH CO LTD
  • US12086241B2 patent drawing
  • US12086241B2 patent drawing
  • US12086241B2 patent drawing

AI summary

The present invention provides an event visualization device configured to generate one or more directed acyclic graphs (DAGs) that can be used as a basis for diagnosing whether a target network system has been hacked according to a plurality of activities records. The plurality of activities records pertain to an event cluster associated with a suspicious event category. The event visualization device performs a graph generating operation on the plurality of activities records in a recursive manner to generate a hierarchical directed acyclic graph (HDAG). The graph generating operation includes: interpreting an activities record into a target DAG, and performing a hierarchical partial order alignment (HPOA) operation on the target DAG and a reference DAG to obtain a merging condition of each node; and merging the target DAG and the reference DAG into the HDAG according to the merging condition.