Risk Knowledge Graph for Network Entity Cybersecurity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Secure Access Service Edge (SASE) systems face challenges in effectively identifying and mitigating cybersecurity risks across network entities, as they often rely on individual risk event analysis rather than understanding the relationships and collective risks posed by groups of entities, leading to potential risk propagation and missed high-risk entities.
Innovation Solution
A method that constructs a risk knowledge graph to represent network entities as nodes connected by edges representing risk events, using the Louvain method to group these nodes into communities based on their relationships, allowing for targeted response actions to mitigate cybersecurity risks posed by high-risk communities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If individual risk event analysis is used to assess cybersecurity risks, then the system complexity is reduced and ease of operation is improved, but the measurement precision of risk assessment deteriorates and high-risk entities may be missed
Solution Approach 1:
The patent combines multiple individual risk events and their associated network entities into a risk community graph that visualizes relationships and collective risks. This merging approach allows the system to maintain operational simplicity while improving risk assessment accuracy by showing how individual risks interconnect and amplify each other within communities.
Solution Approach 2:
The patent adds a relational dimension to traditional individual risk assessment by creating a graph structure that connects network entities through their participation in risk events. This dimensional transformation enables the system to assess risks not just individually but also in terms of their relationships and community contexts, thereby improving measurement precision without significantly increasing operational complexity.
2Measurement precision
If risk relationships and community structures are analyzed, then the measurement precision of risk identification is improved, but the device complexity and computational requirements increase
Solution Approach 1:
The patent introduces a risk community graph as an intermediary representation layer between raw risk event data and risk assessment outputs. This graph structure serves as a mediator that organizes complex relationships in a manageable visual format, enabling precise risk identification without directly increasing device complexity. The graph acts as a conceptual framework that simplifies the analysis of intricate risk relationships.
Solution Approach 2:
The patent creates a simplified copy or representation of the complex risk landscape through the risk community graph. Instead of directly analyzing all underlying risk events and relationships, the system generates a condensed graphical model that captures essential risk patterns and community structures, thereby improving identification accuracy while keeping computational requirements manageable.
3Reliability
If comprehensive risk data from multiple sources is collected, then the reliability of risk assessment is improved, but the quantity of information and processing requirements increase
Solution Approach 1:
The patent extracts and highlights only the most relevant risk relationships and community structures from the comprehensive risk data, rather than processing and displaying all available information. This extraction approach maintains assessment reliability by focusing on critical risk indicators while reducing the effective data volume that requires processing and presentation.
Solution Approach 2:
The patent segments comprehensive risk data into discrete risk events, network entities, and risk communities within the graph structure. This segmentation organizes large volumes of data into manageable units that can be processed and analyzed independently, thereby maintaining reliability through comprehensive data coverage while reducing processing requirements through structured decomposition.
Data Source
AI summary
A risk knowledge graph is created from information on risk events involving network entities of a private computer network. Each of the risk events is represented as a node in the risk knowledge graph. The nodes are connected by edges that represent the risk events. The nodes are grouped into communities of related nodes. A response action is performed against a community to mitigate a cybersecurity risk posed by the community.


