Network Entity Discovery and Relationship Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern computer networks are increasingly complex due to trends like BYOD, IoT, cloud infrastructure, and microservices, making it challenging for IT and cybersecurity teams to maintain accurate catalogues of entities and their interactions, leading to inefficiencies in cyber risk assessment and security management.

Innovation Solution

A system that automates entity discovery, attribute resolution, and tracking in computer networks through passive and proactive data collection, using graph technologies and machine learning to map interactions and relationships, and execute automated actions to maintain compliance and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional manual approaches are used to maintain entity catalogues, then human users can play a role in the process, but it becomes infeasible to maintain accurate catalogues in modern complex computer environments

Engineering Contradiction:
Improveaccuracy of entity catalogueVSAvoidfeasibility of manual maintenance
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system enables automatic self-discovery of entities and relationships through automated data collection from multiple sources, eliminating the need for manual catalogue maintenance while ensuring continuous accuracy in dynamic environments

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual processes are replaced with automated computational systems that use graph technologies and machine learning to discover, track, and maintain entity relationships without human intervention

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If automated data collection is implemented to track all entities, then real-time accurate insights are provided, but the complexity of the system increases

Engineering Contradiction:
Improveaccuracy of entity trackingVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the complex task of entity tracking into modular components: data collection from multiple sources, graph-based relationship mapping, machine learning for pattern recognition, and automated remediation actions, making the overall system manageable and scalable

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Graph technologies serve as an intermediary layer that structures and represents complex entity relationships in a manageable format, enabling efficient querying and analysis without overwhelming system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If comprehensive entity monitoring is implemented, then cyber risk assessment is improved, but the burden on limited IT and security resources increases

Engineering Contradiction:
Improvecyber risk assessment capabilityVSAvoidIT resource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system continuously monitors entity relationships and provides real-time feedback on security risks, enabling proactive threat detection and automated remediation that reduces the need for constant human monitoring while improving security posture

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Automated remediation actions are executed by the system itself based on detected risks, reducing the burden on IT and security teams while maintaining comprehensive monitoring coverage

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12120134B2System for automatically discovering, enriching and remediating entities interacting in a computer network
Publication Date: 2024.10.15 RAPID7 INC
  • US12120134B2 patent drawing
  • US12120134B2 patent drawing
  • US12120134B2 patent drawing

AI summary

An entity tracking system and method for a computer network employs proactive data collection and enrichment driven by configurable rules and workflows responsive to the discovery of new entities, changes to existing entities, and specifics about the entities' attributes. The data collection is used in conjunction with graph technologies to map interactions and relationships between various entities interacting in the computer environment and deduce interactions and relationships between the entities. Machine learning techniques further identify, group or categorize entities and identify patterns which are indicative of anomalies that might be due to nefarious actions or compromised security.