Intelligence Graph Construction for Automated Threat Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for information security threat assessment are inadequate in linking diverse computer security data from various sources into a comprehensive framework that can automatically identify and predict attacks, and provide effective countermeasures.

Innovation Solution

The implementation of an intelligence graph construction method that links fundamental data and document data into a graph structure, allowing for the automatic identification of attacks and the suggestion or implementation of countermeasures by matching sub-graphs to known attack patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If diverse computer security data from various sources are collected and linked into a comprehensive framework, then the ability to automatically identify and predict attacks improves, but the complexity of data integration and graph construction increases

Engineering Contradiction:
Improveattack identification accuracyVSAvoidgraph construction complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex task of security threat analysis into distinct components: fundamental data extraction, document data processing, node creation, and edge relationship establishment. Each component handles a specific aspect of data integration, making the overall system more manageable despite the complexity of linking diverse security data sources.

Inventive Principle:
Principle #1Segmentation

2Productivity

If manual analysis methods are used for security threat assessment, then the complexity of automated systems is reduced, but the productivity and speed of threat identification decrease

Engineering Contradiction:
Improvethreat assessment efficiencyVSAvoidautomated analysis level
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The system enables self-service automated threat identification by allowing the graph structure to automatically match patterns against known attack signatures. The automated intelligence graph construction and pattern matching processes operate independently to identify threats without requiring continuous manual intervention, thereby improving productivity while maintaining appropriate automation levels.

Inventive Principle:
Principle #25Self-service

3Loss of information

If comprehensive fundamental data and document data are integrated into the graph structure, then the information completeness for threat analysis improves, but the time required for data processing and graph construction increases

Engineering Contradiction:
Improveinformation completenessVSAvoiddata processing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-processing and structuring fundamental data and document data into standardized node formats before integration. This preliminary organization of data into comparable structures accelerates the subsequent graph construction and pattern matching processes, reducing overall processing time while maintaining information completeness.

Inventive Principle:
Principle #10Preliminary action

4Speed

If pattern matching is performed continuously upon graph updates, then the speed of attack detection improves, but the computational energy consumption increases

Engineering Contradiction:
Improveattack detection speedVSAvoidcomputational energy consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system implements periodic pattern matching that is triggered by specific events such as graph updates or threshold conditions rather than continuously. This event-driven approach maintains fast attack detection capability while reducing computational energy consumption by performing pattern matching only when necessary, rather than at constant intervals.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10162970B2Automated intelligence graph construction and countermeasure deployment
Publication Date: 2018.12.25 ACCENTURE GLOBAL SOLUTIONS LTD
  • US10162970B2 patent drawing
  • US10162970B2 patent drawing
  • US10162970B2 patent drawing

AI summary

Techniques for providing information security threat assessment and amelioration are disclosed. The techniques may include obtaining fundamental data, obtaining document data, preparing fundamental instance nodes from the fundamental data, preparing document nodes from the document data, preparing edges between at least some of the nodes, storing the nodes and the edges in a manner that reflects a graph structure, and causing to be displayed at least a portion of a graph defined by at least one node and at least one edge.