Network Asset Correlator for Cybersecurity Entity Resolution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing entity resolution mechanisms are not optimized for complex network environments, and current network asset correlation techniques rely on manual rules and lack machine learning, leading to inefficient identification and provisioning of computing assets for security actions.

Innovation Solution

The implementation of a network asset correlation server that uses computing entity resolution to probabilistically correlate newly scanned nodes with existing assets, optimizing resource allocation by generating a network asset correlator that identifies disparate correlations and determines appropriate security actions based on entity resolution thresholds.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing record linkage mechanisms are used for computing entities, then basic entity matching is possible, but accuracy and efficiency are insufficient for complex network environments

Engineering Contradiction:
Improveentity identification accuracyVSAvoidasset correlation efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent transforms the entity resolution problem from deterministic matching to probabilistic parameter-based correlation. It introduces correlation probabilities as parameters to represent the likelihood that two computing entities are the same, allowing the system to handle uncertainty in complex network environments where entities may have varying attributes across different data sources.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces traditional mechanical record linkage mechanisms with a machine learning-based network asset correlator. This correlator uses trained models to probabilistically determine entity correlations, substituting rule-based mechanical matching with intelligent automated decision-making that adapts to complex network patterns.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If manual rules are used for network asset correlation, then implementation is simple, but resource allocation is inefficient and computational complexity increases

Engineering Contradiction:
Improveresource allocation efficiencyVSAvoidcorrelation system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements self-service through automated machine learning models that independently perform asset correlation and security action determination. The network asset correlator automatically trains on historical data and makes decisions without manual rule configuration, while the system self-optimizes resource allocation based on learned patterns of entity correlations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-training the network asset correlator model on historical entity data before deployment. The machine learning model is trained in advance to recognize correlation patterns, so when new assets need to be correlated, the system can quickly make accurate determinations without manual rule creation or complex real-time analysis.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11539736B1Network asset correlator for cybersecurity operations
Publication Date: 2022.12.27 RAPID7 INC
  • US11539736B1 patent drawing
  • US11539736B1 patent drawing
  • US11539736B1 patent drawing

AI summary

Disclosed herein are methods, systems, and processes for utilizing computing entity resolution for network asset correlation. A scanned dataset that includes newly scanned node information that identifies newly scanned nodes on a network is received from a security server. The newly scanned node information is extracted from the scanned dataset and indicates that the newly scanned nodes cannot be identified as being part of existing computing devices in the network. The newly scanned node information is processed with a network asset correlator and the processing results in a set of asset correlation results for the newly scanned nodes. An existing computing device is identified based on a highest disparate correlation probability in the set of asset correlation results and the security server is instructed to perform a security action on the identified existing computing device.