Network Causality Identification for Security Incident Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anti-virus solutions are inadequate for efficiently detecting and managing security incidents in large enterprises, as they often fail to detect malicious activity in a timely manner, leading to undetected threats and overwhelming security teams with numerous alerts.

Innovation Solution

A system and method for causality identification and attribution in a network that continuously monitors processes, differentiates between major, minor, and non-system processes, and generates analytics to identify and validate security incidents in real-time, using a server connected to user devices and a SIEM system to analyze and verify alerts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anti-virus applications are deployed to identify malicious activity, then security incidents can be detected, but security teams are overwhelmed with thousands of alerts daily and response time increases to days or weeks

Engineering Contradiction:
Improvedetection accuracyVSAvoidresponse efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the security monitoring system into multiple specialized components: a causality identification engine that traces process relationships, an alert validation module that filters false positives, and an analytics generator that prioritizes threats. This segmentation allows each component to specialize in specific tasks, improving overall detection accuracy while reducing the burden on security teams by eliminating unnecessary alerts.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary causality identification layer between traditional anti-virus detection and security team response. This intermediary automatically analyzes process relationships, validates alerts, and generates prioritized analytics, serving as a mediator that translates raw security data into actionable intelligence and reduces response time from weeks to minutes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If basic engine solutions search for predetermined virus signatures, then known viruses can be identified, but malicious activity may go undetected and detection effectiveness is insufficient

Engineering Contradiction:
Improvedetection coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by continuously monitoring and building causality chains of process relationships before malicious activity occurs. The system pre-establishes baseline process behaviors and relationships, allowing it to detect deviations and previously unknown threats without requiring complex real-time analysis, thus improving detection coverage while maintaining manageable system complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent adds another dimension to traditional signature-based detection by incorporating temporal and relational dimensions through causality chain analysis. Instead of only searching for static virus signatures, the system analyzes process relationships over time, enabling detection of novel threats through behavioral patterns while keeping the base signature engine intact, thus expanding detection coverage without proportionally increasing complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If multiple anti-virus applications are deployed to cover different threats, then detection capability improves, but the number of alerts increases to thousands daily managing which becomes overwhelming

Engineering Contradiction:
Improvedetection capabilityVSAvoidalert volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges multiple alert streams and detection mechanisms into a unified causality-based analysis framework. By consolidating alerts from various anti-virus applications and correlating them through process relationship analysis, the system reduces redundant and false positive alerts while maintaining comprehensive detection capability, transforming thousands of disparate alerts into a manageable number of validated security incidents.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements feedback mechanisms where the causality identification engine continuously learns from validated security incidents and adjusts its analysis parameters. This feedback loop enables the system to improve alert validation accuracy over time, progressively reducing false positives and alert volume while maintaining or enhancing detection capability through adaptive optimization.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10554672B2Causality identification and attributions determination of processes in a network
Publication Date: 2020.02.04 PALO ALTO NETWORKS INC
  • US10554672B2 patent drawing
  • US10554672B2 patent drawing
  • US10554672B2 patent drawing

AI summary

Processes in a network which cause and are attributable to security incidents are identified. Processes which are initiated on devices in an enterprise network at boot of the devices are identified. The enterprise network is continuously monitored to collect data about processes which were initiated or spawned on devices in the enterprise network after the boot of the devices. Each process is determined to be a major system process, a minor system process, or a non-system process based, at least in part, on the collected data which indicates associations among the processes. Based on matching a security incident alert to a first of the processes, it is determined whether the first process is a non-system process to validate the security incident alert.