Network Causality Identification for Security Incident Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current anti-virus solutions are inadequate for efficiently detecting and managing security incidents in large enterprises, as they often fail to detect malicious activity in a timely manner, leading to undetected threats and overwhelming security teams with numerous alerts.
Innovation Solution
A system and method for causality identification and attribution in a network that continuously monitors processes, differentiates between major, minor, and non-system processes, and generates analytics to identify and validate security incidents in real-time, using a server connected to user devices and a SIEM system to analyze and verify alerts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional anti-virus applications are deployed to identify malicious activity, then security incidents can be detected, but security teams are overwhelmed with thousands of alerts daily and response time increases to days or weeks
Solution Approach 1:
The patent segments the security monitoring system into multiple specialized components: a causality identification engine that traces process relationships, an alert validation module that filters false positives, and an analytics generator that prioritizes threats. This segmentation allows each component to specialize in specific tasks, improving overall detection accuracy while reducing the burden on security teams by eliminating unnecessary alerts.
Solution Approach 2:
The patent introduces an intermediary causality identification layer between traditional anti-virus detection and security team response. This intermediary automatically analyzes process relationships, validates alerts, and generates prioritized analytics, serving as a mediator that translates raw security data into actionable intelligence and reduces response time from weeks to minutes.
2Reliability
If basic engine solutions search for predetermined virus signatures, then known viruses can be identified, but malicious activity may go undetected and detection effectiveness is insufficient
Solution Approach 1:
The patent implements preliminary action by continuously monitoring and building causality chains of process relationships before malicious activity occurs. The system pre-establishes baseline process behaviors and relationships, allowing it to detect deviations and previously unknown threats without requiring complex real-time analysis, thus improving detection coverage while maintaining manageable system complexity.
Solution Approach 2:
The patent adds another dimension to traditional signature-based detection by incorporating temporal and relational dimensions through causality chain analysis. Instead of only searching for static virus signatures, the system analyzes process relationships over time, enabling detection of novel threats through behavioral patterns while keeping the base signature engine intact, thus expanding detection coverage without proportionally increasing complexity.
3Reliability
If multiple anti-virus applications are deployed to cover different threats, then detection capability improves, but the number of alerts increases to thousands daily managing which becomes overwhelming
Solution Approach 1:
The patent merges multiple alert streams and detection mechanisms into a unified causality-based analysis framework. By consolidating alerts from various anti-virus applications and correlating them through process relationship analysis, the system reduces redundant and false positive alerts while maintaining comprehensive detection capability, transforming thousands of disparate alerts into a manageable number of validated security incidents.
Solution Approach 2:
The patent implements feedback mechanisms where the causality identification engine continuously learns from validated security incidents and adjusts its analysis parameters. This feedback loop enables the system to improve alert validation accuracy over time, progressively reducing false positives and alert volume while maintaining or enhancing detection capability through adaptive optimization.
Data Source
AI summary
Processes in a network which cause and are attributable to security incidents are identified. Processes which are initiated on devices in an enterprise network at boot of the devices are identified. The enterprise network is continuously monitored to collect data about processes which were initiated or spawned on devices in the enterprise network after the boot of the devices. Each process is determined to be a major system process, a minor system process, or a non-system process based, at least in part, on the collected data which indicates associations among the processes. Based on matching a security incident alert to a first of the processes, it is determined whether the first process is a non-system process to validate the security incident alert.


