Statistical Relational Learning for Cybersecurity Graph Maliciousness Prediction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional machine learning methods fail to effectively capture the rich relational structure of data in settings like cybersecurity, limiting the depth and completeness of concepts captured, especially in predicting unknown entity attributes and maliciousness in computing systems.

Innovation Solution

The use of statistical relational learning techniques to generate node graphs that represent computing systems, where nodes are assigned maliciousness factors based on the known maliciousness of other nodes, enabling the prediction of malicious attributes and mitigation of attacks through dynamic security adjustments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional machine learning methods are used to extract patterns from cybersecurity data, then the processing speed and simplicity are maintained, but the ability to capture rich relational structure and predict unknown entity attributes is severely limited

Engineering Contradiction:
Improveprediction accuracy of maliciousnessVSAvoidcomplexity of learning model
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces statistical relational learning as an intermediary approach between traditional machine learning and complex graph analysis. This intermediary method uses probabilistic graphical models to capture relational structures while maintaining computational tractability, thereby improving prediction accuracy without requiring excessively complex models.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transitions from traditional flat feature vectors to multi-dimensional relational graphs, adding the dimension of entity relationships. By representing cybersecurity data as graphs with nodes (entities) and edges (relationships), the model can capture hierarchical and contextual information that improves maliciousness prediction accuracy.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Loss of information

If statistical relational learning is applied to predict unknown entity attributes in cybersecurity graphs, then the completeness of captured concepts is improved, but the computational complexity and data processing requirements increase

Engineering Contradiction:
Improvecompleteness of relational structureVSAvoidcomputational resources
Core Design Contradiction:
Loss of informationVSUse of energy by stationary object

Solution Approach 1:

The patent segments the cybersecurity graph into multiple subgraphs or communities based on entity types and relationship patterns. This segmentation allows the statistical relational learning to be applied locally to smaller, more manageable subsets of data, reducing overall computational complexity while preserving the completeness of relational structures within each segment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies statistical relational learning selectively to only those parts of the cybersecurity graph where relational information is most valuable for prediction, rather than uniformly processing the entire graph. This partial action approach reduces computational overhead while maintaining the completeness of captured concepts in critical areas.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11533324B2Learning maliciousness in cybersecurity graphs
Publication Date: 2022.12.20 MCAFEE LLC
  • US11533324B2 patent drawing
  • US11533324B2 patent drawing
  • US11533324B2 patent drawing

AI summary

Systems and methods for utilizing statistical relational learning techniques in order to predict factors for nodes of a node graph, such as a node graph that represents attacks and incidents to a computing system, are described. In some embodiments, the systems and methods identify certain nodes (of a node graph) as representing malicious attributes of an email or other threat artifact received by a computing system or network and utilize relational learning to predict the maliciousness of attributes represented by other nodes (of the node graph).