Malicious Incident Visualization via Graph Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in efficiently detecting and visualizing malicious incidents on host devices, particularly due to the obfuscation of malware and the resource-intensive nature of manual detection processes.

Innovation Solution

A system that monitors host devices for potential malicious behavior, generates visual representations of detected incidents, and outputs these visualizations for analyst review, employing techniques such as incident scoring, graph generation, and correlation of event data across multiple devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual detection processes are used to determine whether a program is malware, then detection accuracy can be maintained, but the process becomes very time-consuming and resource-intensive

Engineering Contradiction:
Improvedetection accuracyVSAvoidtime-consuming
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the detection process into automated preprocessing (collecting event data, generating visualizations) and human expert analysis (interpreting visualizations). This divides the workload between machine efficiency and human judgment, reducing time consumption while maintaining accuracy through incident scoring and prioritization of critical events.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces visualizations as an intermediary between raw event data and analyst decision-making. These visual representations (graphs, timelines, maps) translate complex security data into intuitive formats, enabling faster analysis without sacrificing detection accuracy by preserving all relevant event relationships.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive monitoring of all events is performed to detect obfuscated malware, then detection capability is improved, but resource consumption increases significantly

Engineering Contradiction:
Improvedetection capabilityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the most relevant and suspicious events from the complete event stream by applying filtering criteria and incident scoring. Instead of analyzing all events equally, the system identifies and extracts high-priority incidents that warrant detailed examination, significantly reducing resource consumption while maintaining reliable detection of malicious activity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different levels of analysis intensity to different events based on their suspiciousness score. High-scoring incidents receive comprehensive visualized analysis, while low-scoring events are processed more efficiently or dismissed. This local differentiation of quality and effort optimizes resource allocation across the monitoring system.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If detailed analysis of all events is performed to confirm malicious behavior, then detection accuracy is maintained, but the complexity of the analysis process increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent transforms complex multi-dimensional event data into visual representations that add spatial and temporal dimensions to the analysis. Graphs show relationships between processes, timelines display sequence of events, and maps visualize network connections. This dimensional transformation makes complex patterns more perceivable and reduces analytical complexity while maintaining detection accuracy.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12323438B2Malicious incident visualization
Publication Date: 2025.06.03 CROWDSTRIKE
  • US12323438B2 patent drawing
  • US12323438B2 patent drawing
  • US12323438B2 patent drawing

AI summary

Techniques to provide visualizations of possible malicious incidents associated with an event on a host device may include causing presentation of graphics of a process or thread in a user interface. Information about detected events may be transmitted to a computing device that generates the visualizations for presentation to an analyst to verify the malicious incidents. Based on patterns and information conveyed in the visualizations, the computer device or host device may take action to protect operation of the host device caused by the event.