Hierarchical Directed Acyclic Graph for Network Intrusion Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies face challenges in detecting advanced persistent threats (APT) and other hacking methods, as they require manual analysis by experienced professionals, which is time-consuming and inefficient for large networks, and cannot provide real-time detection of system anomalies or intrusion threats.
Innovation Solution
An information security incident diagnosis system that includes an activities record collection device and a suspicious incident determination device, which collects and processes activity records to generate a discrete space metric tree, performs clustering, and creates a hierarchical directed acyclic graph (HDAG) to visually represent similar and differential features, aiding in the detection of intrusions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual analysis by experienced professionals is used, then detection accuracy is improved, but analysis time and productivity deteriorate
Solution Approach 1:
The patent introduces an automated analysis system that acts as an intermediary between raw activity records and expert analysts. The system includes modules for automated collection, processing, clustering, and visualization of computing device activities, providing pre-processed intelligence that reduces the time and effort required for manual analysis while maintaining high detection accuracy through structured data presentation.
Solution Approach 2:
The analysis system segments the complex detection task into distinct automated modules: activity record collection, data processing, clustering analysis, and visual presentation. This segmentation allows routine analysis functions to be automated while preserving expert judgment for final interpretation, thereby improving productivity without sacrificing detection accuracy.
2Reliability
If manual analysis methods are used for large networks, then comprehensive detection is improved, but time cost and productivity worsen
Solution Approach 1:
The system enables self-service automated analysis that continuously collects and processes activity records without requiring constant expert intervention. The automated clustering and visualization modules operate independently to provide ongoing security monitoring, ensuring comprehensive detection across large networks while minimizing time costs through continuous autonomous operation.
Solution Approach 2:
The system performs preliminary automated analysis actions on activity records before they reach human analysts. By pre-processing data, performing initial clustering, and generating visualizations in advance, the system reduces the time required for comprehensive detection while maintaining thoroughness through systematic automated examination of all records.
3Measurement precision
If conventional manual analysis is used, then detailed examination is improved, but real-time detection capability worsens
Solution Approach 1:
The patent replaces the mechanical manual analysis process with an automated computational system that uses algorithms for clustering and pattern recognition. This substitution maintains detailed examination capability through systematic data processing while achieving real-time detection speed through automated computation, eliminating the inherent delay between data collection and analysis.
Data Source
AI summary
The present invention provides an event visualization device configured to generate one or more directed acyclic graphs (DAGs) that can be used as a basis for diagnosing whether a target network system has been hacked according to a plurality of activities records. The plurality of activities records pertain to an event cluster associated with a suspicious event category. The event visualization device performs a graph generating operation on the plurality of activities records in a recursive manner to generate a hierarchical directed acyclic graph (HDAG). The graph generating operation includes: interpreting an activities record into a target DAG, and performing a hierarchical partial order alignment (HPOA) operation on the target DAG and a reference DAG to obtain a merging condition of each node; and merging the target DAG and the reference DAG into the HDAG according to the merging condition.


