Knowledge Graph Mapping for Cybersecurity Gap Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity frameworks struggle to identify and prioritize gaps in detection and prevention measures due to evolving threat landscapes and complex network environments, making it challenging to effectively mitigate and resolve cyber threats.

Innovation Solution

A knowledge graph schema is used to encode and map prevention and detection measures with a cybersecurity framework, enabling automated identification and prioritization of security gaps by correlating tactics, techniques, and sub-techniques, and predicting malicious actor behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network security frameworks are used to understand and categorize adversary TTPs, then the ability to evaluate defensive capabilities is improved, but the ability to identify gaps in security measures deteriorates

Engineering Contradiction:
Improveevaluation of defensive capabilitiesVSAvoididentification of security gaps
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces an automated analysis system that acts as an intermediary between the network security framework and the evaluation process. This system automatically maps adversary TTPs to security controls, identifies gaps, and generates prioritized recommendations, thereby resolving the contradiction by enabling both precise evaluation and effective gap identification through automation

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If manual investigations of cybersecurity incidents are conducted, then detection capability is improved, but consistency and adequacy of investigations deteriorate when scaled

Engineering Contradiction:
Improvedetection capabilityVSAvoidconsistency and adequacy of investigations
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The system enables self-service automated investigation by automatically analyzing security incidents, mapping them to the network security framework, identifying relevant security controls, and generating gap analysis reports without requiring manual intervention. This maintains high detection capability while ensuring consistent and adequate investigations through standardized automated processes

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent transforms the investigation process from manual to automated by changing key parameters including analysis speed, consistency, and scalability. The automated system processes incidents systematically with uniform application of the security framework, ensuring reliable and consistent results across all investigations regardless of volume

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If the cybersecurity framework is expanded to cover more tactics and techniques, then coverage of threat landscape is improved, but complexity of identifying and prioritizing gaps deteriorates

Engineering Contradiction:
Improvecoverage of threat landscapeVSAvoidcomplexity of gap identification and prioritization
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system dynamically adapts to the expanding cybersecurity framework by automatically adjusting its analysis parameters, mapping relationships, and prioritization algorithms. As new tactics and techniques are added to the framework, the system automatically incorporates them into its gap analysis without requiring manual reconfiguration, thereby maintaining versatility while managing complexity through dynamic automation

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12603914B2Cybersecurity gap identification using knowledge graphs
Publication Date: 2026.04.14 ARCTIC WOLF NETWORKS INC
  • US12603914B2 patent drawing
  • US12603914B2 patent drawing
  • US12603914B2 patent drawing

AI summary

Disclosed are systems for detecting gaps in security measures performed in a network security environment. A system can: receive prevention data from a prevention system that generates and provides prevention measures to a third party system in a network security environment to prevent potential vulnerabilities, receive detection data from a detection system that generates and provides detection measures to the third party system to block the potential vulnerabilities, receive a framework taxonomy that includes relationships between vulnerabilities, tactics, techniques, and sub-techniques, and generate a knowledge graph based on mapping the prevention data, the detection data, and the tactics, techniques, and sub-techniques of the framework taxonomy. The system can also traverse the knowledge graph, iteratively detect gaps in the prevention measures or the detection measures based on traversing the knowledge graph, and return information about the detected gaps.