Security Appliance Knowledge Graph for Proactive Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting malicious activity in computing environments are reactive, identifying threats only after an attack has occurred, lacking the ability to predict potential attacks beforehand.
Innovation Solution
A security appliance monitors communication between user computers and destination computers, extracts selective information, associates it with security entity attributes, and generates a knowledge graph to detect potential threats by analyzing patterns and anomalies indicative of malicious activity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional malware scanning with signature matching is used, then detection accuracy for known threats is improved, but the ability to detect novel or dormant threats is worsened
Solution Approach 1:
The system performs preliminary actions by monitoring and analyzing communication patterns before malicious activity is activated. It builds knowledge graphs of normal behavior patterns in advance, enabling detection of anomalies when threats become active, thus detecting threats before they can cause harm.
Solution Approach 2:
The system transitions from traditional single-dimension signature matching to multi-dimensional analysis by creating knowledge graphs that incorporate temporal patterns, communication metadata, entity relationships, and behavioral contexts. This dimensional expansion enables detection of threats that lack known signatures.
2Reliability
If comprehensive monitoring of all communication is performed, then detection coverage is improved, but system complexity and processing overhead are worsened
Solution Approach 1:
The system extracts only relevant selective information from communication streams, such as metadata, entity identifiers, and pattern-relevant features, while discarding unnecessary data. This extraction approach maintains comprehensive monitoring coverage while reducing processing complexity and resource requirements.
Solution Approach 2:
The knowledge graph structure serves multiple functions simultaneously: it stores entity relationships, captures temporal patterns, enables anomaly detection, and provides context for investigation. This multi-functionality reduces the need for separate systems for each detection task, thereby reducing overall system complexity.
3Use of energy by moving object
If reactive detection methods are used, then resource consumption is reduced, but the ability to prevent attacks is worsened
Solution Approach 1:
The system performs preliminary monitoring and pattern learning during normal operations without requiring intensive processing only when threats are detected. By continuously building knowledge graphs in the background and using lightweight anomaly detection algorithms, it maintains attack prevention capability while keeping resource consumption manageable.
Data Source
AI summary
System and method for detecting a likely threat from a malicious attack is disclosed. Communication between a user computer and a destination computer is monitored by a security appliance. Selective information from the communication is extracted. Selective information is associated to one or more attributes of a security entity. A knowledge graph is generated for a plurality of security entities based on the associated selective information.


