Statistical Relational Learning for Cybersecurity Graph Maliciousness Prediction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional machine learning methods fail to effectively capture the rich relational structure of data in settings like cybersecurity, limiting the depth and completeness of concepts captured, especially in predicting unknown entity attributes and maliciousness in computing systems.
Innovation Solution
The use of statistical relational learning techniques to generate node graphs that represent computing systems, where nodes are assigned maliciousness factors based on the known maliciousness of other nodes, enabling the prediction of malicious attributes and mitigation of attacks through dynamic security adjustments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional machine learning methods are used to extract patterns from cybersecurity data, then the processing speed and simplicity are maintained, but the ability to capture rich relational structure and predict unknown entity attributes is severely limited
Solution Approach 1:
The patent introduces statistical relational learning as an intermediary approach between traditional machine learning and complex graph analysis. This intermediary method uses probabilistic graphical models to capture relational structures while maintaining computational tractability, thereby improving prediction accuracy without requiring excessively complex models.
Solution Approach 2:
The patent transitions from traditional flat feature vectors to multi-dimensional relational graphs, adding the dimension of entity relationships. By representing cybersecurity data as graphs with nodes (entities) and edges (relationships), the model can capture hierarchical and contextual information that improves maliciousness prediction accuracy.
2Loss of information
If statistical relational learning is applied to predict unknown entity attributes in cybersecurity graphs, then the completeness of captured concepts is improved, but the computational complexity and data processing requirements increase
Solution Approach 1:
The patent segments the cybersecurity graph into multiple subgraphs or communities based on entity types and relationship patterns. This segmentation allows the statistical relational learning to be applied locally to smaller, more manageable subsets of data, reducing overall computational complexity while preserving the completeness of relational structures within each segment.
Solution Approach 2:
The patent applies statistical relational learning selectively to only those parts of the cybersecurity graph where relational information is most valuable for prediction, rather than uniformly processing the entire graph. This partial action approach reduces computational overhead while maintaining the completeness of captured concepts in critical areas.
Data Source
AI summary
Systems and methods for utilizing statistical relational learning techniques in order to predict factors for nodes of a node graph, such as a node graph that represents attacks and incidents to a computing system, are described. In some embodiments, the systems and methods identify certain nodes (of a node graph) as representing malicious attributes of an email or other threat artifact received by a computing system or network and utilize relational learning to predict the maliciousness of attributes represented by other nodes (of the node graph).


