Knowledge Graph for Cyber Threat Inference

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing amount of information in cyberspace, including deep web and dark web data, poses challenges in identifying and analyzing relationships relevant to crimes and threats due to the lack of standardized data formats, making it difficult to infer circumstances related to crimes.

Innovation Solution

A knowledge-based graph is created using a taxonomy graph for classification and an entity graph for relationships, which updates and infers relevance by processing data from various sources, including normal and special web browsers, to analyze and identify connections between information objects.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If data from deep web and dark web are collected and analyzed, then the completeness of crime-related information is improved, but the complexity of data processing and analysis increases

Engineering Contradiction:
Improvecompleteness of crime-related informationVSAvoidcomplexity of data processing
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent segments the complex data processing task into multiple components: data collection from various sources (normal web, deep web, dark web), data storage in standardized format, graph construction from stored data, and graph analysis for crime inference. This segmentation allows each component to be handled independently, reducing overall processing complexity while maintaining information completeness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary standardized data format as a mediator between raw collected data and the graph analysis system. Collected data from diverse sources is first converted to a standardized format before being used to construct the graph, which simplifies subsequent analysis operations and reduces processing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If a knowledge-based graph is constructed to analyze relationships, then the accuracy of crime circumstance inference is improved, but the time required for data processing increases

Engineering Contradiction:
Improveaccuracy of crime circumstance inferenceVSAvoidtime required for data processing
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-construction a knowledge-based graph from collected data and storing it in a standardized format. This pre-processed graph structure is then reused for multiple analysis queries, avoiding repeated full-data processing and reducing the time required for subsequent crime circumstance inference while maintaining accuracy.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If standardized data format is implemented for all web data, then the ease of data integration is improved, but the complexity of data standardization process increases

Engineering Contradiction:
Improveease of data integrationVSAvoidcomplexity of data standardization process
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a universal standardized data format that can accommodate data from multiple sources (normal web, deep web, dark web) with different structures and formats. This single standardized format serves multiple functions: storing diverse data types, enabling graph construction, and supporting analysis operations, thereby simplifying data integration despite the complexity of the standardization process.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12124512B2Method, apparatus, and computer program for providing cyber security by using a knowledge graph
Publication Date: 2024.10.22 S2W INC
  • US12124512B2 patent drawing
  • US12124512B2 patent drawing
  • US12124512B2 patent drawing

AI summary

The present invention relates to a method for processing a knowledge graph in a data processing apparatus, comprising the steps of: (a) creating a knowledge graph including a taxonomy graph for a classification system of information objects and an entity graph for a relationship between specific information object instances; (b) updating the knowledge graph by reflecting the information objects extracted from a database in the knowledge graph; and (c) inferring the relevance of a random information object by using the updated knowledge graph.