Information Graphs for Cybersecurity Investigation Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity investigation methods are inefficient and lack automation, leading to alert fatigue, insufficient attention to alerts, and the inability to effectively uncover and investigate advanced cyber threats due to the sheer volume of alerts and the need for specialized expertise.

Innovation Solution

Implementing cybersecurity investigation tools that utilize information graphs to intelligently gather and link investigative data, employing novel functions and graph schema to identify patterns and threats, thereby automating parts of the investigation process and enhancing human-machine collaboration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual triage and investigation methods are used, then analysts can perform detailed security analysis, but the sheer volume of alerts leads to alert fatigue and insufficient attention to alerts

Engineering Contradiction:
Improvesecurity analysis qualityVSAvoidalert processing capacity
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system segments the alert investigation process into automated data gathering and pattern recognition components, separating routine analysis tasks from human analyst review. Information graphs automatically compile relevant data and identify patterns, allowing analysts to focus on high-value decision-making rather than manual data collection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The information graph acts as an intermediary between raw security data and human analysts. It automatically gathers investigative data from multiple sources, links related information, and presents structured findings to analysts, reducing the cognitive load and improving both throughput and analysis quality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If more analysts are deployed to handle increased alert volume, then more alerts can be reviewed, but the need for specialized expertise remains a bottleneck

Engineering Contradiction:
Improvealert processing capacityVSAvoidexpertise requirement
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs self-service by automatically gathering investigative data, linking related information, and identifying patterns without human intervention. This automation handles the complex tasks of data synthesis and pattern recognition, allowing less specialized personnel to effectively process alerts while maintaining high analytical standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces manual mechanical analysis processes with automated computational methods. Information graphs use algorithmic pattern recognition and data linking to perform complex security analysis tasks that previously required specialized human expertise, thereby increasing productivity without proportionally increasing expertise requirements.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If automated tools are implemented to increase processing capacity, then more alerts can be handled, but the system complexity and development requirements increase

Engineering Contradiction:
Improveinvestigation automationVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The information graph framework provides universal functionality by serving multiple purposes: data gathering, information linking, pattern recognition, and investigation orchestration. This multi-functional approach consolidates what would otherwise require multiple separate automated tools, reducing overall system complexity while maintaining high automation capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system is designed to be dynamic and adaptive, allowing the information graph schema and data gathering functions to evolve based on emerging threats and investigative needs. This flexibility enables the system to handle diverse security scenarios without requiring complete redesign, managing complexity through adaptability rather than rigid structure.

Inventive Principle:
Principle #15Dynamics

4Reliability

If comprehensive data gathering is performed for each alert, then thorough investigation is achieved, but the time required to process each alert increases

Engineering Contradiction:
Improveinvestigation thoroughnessVSAvoidinvestigation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-gathering and organizing investigative data into information graphs before analyst review. Related data from multiple sources is collected and linked in advance, so when an alert requires investigation, the comprehensive data is already structured and ready for analysis, eliminating the need for time-consuming data collection during the investigation itself.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The information graph maintains continuous useful action by keeping investigative data organized and up-to-date even between alerts. As new data becomes available or relationships are discovered, the graph automatically updates, ensuring that thorough investigation capability is continuously maintained without requiring repeated manual data gathering for each alert.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS20240348628A1Cybersecurity investigation tools utilizing information graphs
Publication Date: 2024.10.17 MAGENTA SECURITY HOLDINGS LLC
  • US20240348628A1 patent drawing
  • US20240348628A1 patent drawing
  • US20240348628A1 patent drawing

AI summary

Example apparatus disclosed herein iteratively link data from one or more cybersecurity tools based on a graph schema to generate an information graph. Disclosed example apparatus also cause presentation of a first pattern detected in the information graph. Disclosed example apparatus further update the information graph based on data from at least one of the cybersecurity tools, the at least one of the cybersecurity tools selected based on a second pattern, the second pattern associated with a known cyberattack technique.