Risk Knowledge Graph for Network Entity Cybersecurity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Secure Access Service Edge (SASE) systems face challenges in effectively identifying and mitigating cybersecurity risks across network entities, as they often rely on individual risk event analysis rather than understanding the relationships and collective risks posed by groups of entities, leading to potential risk propagation and missed high-risk entities.

Innovation Solution

A method that constructs a risk knowledge graph to represent network entities as nodes connected by edges representing risk events, using the Louvain method to group these nodes into communities based on their relationships, allowing for targeted response actions to mitigate cybersecurity risks posed by high-risk communities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If individual risk event analysis is used to assess cybersecurity risks, then the system complexity is reduced and ease of operation is improved, but the measurement precision of risk assessment deteriorates and high-risk entities may be missed

Engineering Contradiction:
Improveease of risk assessmentVSAvoidrisk assessment accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent combines multiple individual risk events and their associated network entities into a risk community graph that visualizes relationships and collective risks. This merging approach allows the system to maintain operational simplicity while improving risk assessment accuracy by showing how individual risks interconnect and amplify each other within communities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent adds a relational dimension to traditional individual risk assessment by creating a graph structure that connects network entities through their participation in risk events. This dimensional transformation enables the system to assess risks not just individually but also in terms of their relationships and community contexts, thereby improving measurement precision without significantly increasing operational complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If risk relationships and community structures are analyzed, then the measurement precision of risk identification is improved, but the device complexity and computational requirements increase

Engineering Contradiction:
Improverisk entity identification accuracyVSAvoidsystem structural complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces a risk community graph as an intermediary representation layer between raw risk event data and risk assessment outputs. This graph structure serves as a mediator that organizes complex relationships in a manageable visual format, enabling precise risk identification without directly increasing device complexity. The graph acts as a conceptual framework that simplifies the analysis of intricate risk relationships.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a simplified copy or representation of the complex risk landscape through the risk community graph. Instead of directly analyzing all underlying risk events and relationships, the system generates a condensed graphical model that captures essential risk patterns and community structures, thereby improving identification accuracy while keeping computational requirements manageable.

Inventive Principle:
Principle #26Copying

3Reliability

If comprehensive risk data from multiple sources is collected, then the reliability of risk assessment is improved, but the quantity of information and processing requirements increase

Engineering Contradiction:
Improverisk assessment reliabilityVSAvoiddata volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts and highlights only the most relevant risk relationships and community structures from the comprehensive risk data, rather than processing and displaying all available information. This extraction approach maintains assessment reliability by focusing on critical risk indicators while reducing the effective data volume that requires processing and presentation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments comprehensive risk data into discrete risk events, network entities, and risk communities within the graph structure. This segmentation organizes large volumes of data into manageable units that can be processed and analyzed independently, thereby maintaining reliability through comprehensive data coverage while reducing processing requirements through structured decomposition.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11973791B1Detecting network entities that pose a cybersecurity risk to a private computer network
Publication Date: 2024.04.30 TREND MICRO INC
  • US11973791B1 patent drawing
  • US11973791B1 patent drawing
  • US11973791B1 patent drawing

AI summary

A risk knowledge graph is created from information on risk events involving network entities of a private computer network. Each of the risk events is represented as a node in the risk knowledge graph. The nodes are connected by edges that represent the risk events. The nodes are grouped into communities of related nodes. A response action is performed against a community to mitigate a cybersecurity risk posed by the community.